(a)ISMS EFFECTIVENESS EVALUATION When complying with IS.AR.235(a), the competent authority should have a process in place to monitor, measure, evaluate and review the effectiveness of its ISMS that defines:
(1)who monitors, measures, analyses and evaluates the results and takes accountable decisions;
(2)when the above steps should be performed;
(3)which methods for monitoring, measurement, analysis and evaluation are applied to ensure comparable and reproducible results. The calendar basis of the assessments should be commensurate with the maximum level of risk established under IS.AR.205. The process to monitor, measure, evaluate and review the effectiveness of its ISMS referred to under AMC1 IS.AR.235(a) should include as a minimum:
(1)the gathering and retention of metrics of the activities, and additional information that could be useful for monitoring purposes;
(2)the analysis of the metrics in order to identify trends and deviations from predefined performance targets.
(b)ISMS MATURITY ASSESSMENT The competent authority should assess the maturity of its ISMS using a suitable maturity model in order to identify areas for improvement to the ISMS. To do so, the competent authority should:
(1)define or adopt a maturity model which represents a set of important and relevant processes and capabilities that are expected to be implemented and maintained;
(2)for each assessed process or capability, ensure that the model defines criteria against which specific aspects, characteristics and effectiveness should be assessed and evaluated when determining a maturity level;
(3)define for each assessed process or capability its desired target maturity level.
(c)For each assessed information security process or capability contained in the maturity model, the competent authority should:
(1)evaluate and justify the current maturity level;
(2)identify any area for improvement it should make to reach the targeted maturity level;
(3)collect and record the evidence regarding strengths and weaknesses of the implemented ISMS and its evaluated maturity.