ISO/IEC 27004
E472704
ISO/IEC 27004 is an international standard that provides guidelines for measuring and evaluating the effectiveness of an information security management system (ISMS) within the ISO/IEC 27000 family.
All labels observed (1)
| Label | Occurrences |
|---|---|
| ISO/IEC 27004 canonical | 2 |
How this entity was disambiguated
This entity first appeared as the object of triple T4835189 — resolving that mention is where its identity was fixed. The disambiguator weighed these candidate entities and picked the highlighted one (or “None”, minting a new entity). This is how homonymy is resolved: the same surface form can point to different entities.
Target entity: ISO/IEC 27004 Context triple: [ISO/IEC 27005, relatedTo, ISO/IEC 27004]
-
A.
ISO/IEC 27005
ISO/IEC 27005 is an international standard that provides guidelines for information security risk management within an organization’s overall information security management system.
-
B.
ISO/IEC 27002
ISO/IEC 27002 is an international standard that provides best-practice guidelines and controls for information security management.
-
C.
ISO/IEC 27000 family
The ISO/IEC 27000 family is an international set of standards that provides best-practice frameworks and requirements for establishing, implementing, maintaining, and continually improving information security management systems.
-
D.
ISO 27001
ISO 27001 is an internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
-
E.
ISO/IEC 19770
ISO/IEC 19770 is an international standard series that defines best practices and requirements for effective IT asset management, including software asset management processes and data formats.
- F. None of above. chosen
- G. Unsure - the case is ambiguous/there is not enough information to decide.
Target entity: ISO/IEC 27004 Target entity description: ISO/IEC 27004 is an international standard that provides guidelines for measuring and evaluating the effectiveness of an information security management system (ISMS) within the ISO/IEC 27000 family.
-
A.
ISO/IEC 27005
ISO/IEC 27005 is an international standard that provides guidelines for information security risk management within an organization’s overall information security management system.
-
B.
ISO/IEC 27002
ISO/IEC 27002 is an international standard that provides best-practice guidelines and controls for information security management.
-
C.
ISO/IEC 27000 family
The ISO/IEC 27000 family is an international set of standards that provides best-practice frameworks and requirements for establishing, implementing, maintaining, and continually improving information security management systems.
-
D.
ISO 27001
ISO 27001 is an internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
-
E.
ISO/IEC 19770
ISO/IEC 19770 is an international standard series that defines best practices and requirements for effective IT asset management, including software asset management processes and data formats.
- F. None of above. chosen
Statements (38)
| Predicate | Object |
|---|---|
| instanceOf |
information security standard
ⓘ
international standard ⓘ |
| aimsTo |
enable organizations to assess ISMS performance
ⓘ
support continual improvement of ISMS ⓘ |
| alignedWith | Plan-Do-Check-Act cycle ⓘ |
| appliesTo | information security management system ⓘ |
| belongsToSeries | ISO/IEC 27000-series standards NERFINISHED ⓘ |
| contributesTo |
evidence-based information security management
ⓘ
risk-based decision making in information security ⓘ |
| defines |
criteria for evaluating ISMS effectiveness
ⓘ
processes for information security measurement ⓘ requirements for information security metrics ⓘ |
| field |
information security
ⓘ
information security management ⓘ |
| focusesOn |
effectiveness of an information security management system
ⓘ
evaluation of information security performance ⓘ measurement of information security ⓘ |
| hasScope |
measurement of ISMS outcomes
ⓘ
measurement of ISMS processes ⓘ measurement of information security controls ⓘ |
| partOf | ISO/IEC 27000 family NERFINISHED ⓘ |
| provides |
guidelines for analysis of ISMS performance
ⓘ
guidelines for evaluation of ISMS effectiveness ⓘ guidelines for improvement of ISMS ⓘ guidelines for information security measurement ⓘ guidelines for monitoring ISMS performance ⓘ |
| publishedBy |
International Electrotechnical Commission
NERFINISHED
ⓘ
International Organization for Standardization ⓘ |
| relatedTo | ISO/IEC 27001 NERFINISHED ⓘ |
| supportsImplementationOf | ISO/IEC 27001 NERFINISHED ⓘ |
| targetAudience |
ISMS auditors
ⓘ
governance and compliance professionals ⓘ information security managers ⓘ risk managers ⓘ |
| usedBy | organizations implementing ISO/IEC 27001 ⓘ |
| usedFor |
designing information security metrics
ⓘ
implementing information security measurement processes ⓘ reporting on information security performance ⓘ |
How these facts were elicited
The pipeline generated the facts above by prompting gpt-5.1 with this entity's name + description and the instruction below.
You are a knowledge base construction expert. Given a subject entity and a description of it, return factual statements that you know for the subject as a JSON list of dictionaries(triples), where keys must be "subject", "predicate" and "object". The number of facts may be very high, between 25 to 50 or more, for very popular subjects. For less popular subjects, the number of facts can be very low, like 5 or 10. # Requirements - If you don't know the subject at all, return an empty list. - If the subject is not a named entity, return an empty list. - Include at least one triple where predicate is "instanceOf". - Do not get too wordy. - Separate several objects into multiple triples with one object.
Subject: ISO/IEC 27004 Description of subject: ISO/IEC 27004 is an international standard that provides guidelines for measuring and evaluating the effectiveness of an information security management system (ISMS) within the ISO/IEC 27000 family.
Referenced by (2)
Full triples — surface form annotated when it differs from this entity's canonical label.