Measurement of Security Controls under ISO 18788

Introduction

Monitoring provides the “observation” of controls, but measurement puts a value on how well they perform. Clause 9.1 of ISO 18788:2015 requires organizations to establish a methodology for measuring performance, ensuring that controls are not only present but effective, efficient, and aligned with objectives.

Measurement allows security companies to move from qualitative assurance (“yes/no checks”) to quantitative insights that guide decisions on budgeting, resourcing, and continuous improvement.

Why Measurement Matters

  1. Objectivity - Translates subjective opinions into numerical performance data.
  2. Comparability - Allows benchmarking across sites, departments, or time periods.
  3. Decision Support - Provides evidence for where to invest or divest in controls.
  4. Compliance and Assurance - Demonstrates measurable conformity with ISO 18788 and contractual KPIs.
  5. Continuous Improvement - Identifies trends and tracks the impact of corrective actions.

Approaches to Measuring Security Controls

1. Key Performance Indicators (KPIs)

KPIs are quantitative metrics that measure whether a control is performing as intended.

  • Examples:
    • % of patrols completed per shift.
    • % of CCTV cameras operational at any given time.
    • Average response time to alarms.

2. Key Risk Indicators (KRIs)

KRIs measure exposure to risks that controls are supposed to mitigate.

  • Examples:
    • Number of unauthorized entries detected per quarter.
    • Frequency of grievances linked to misconduct.
    • Number of weapons-related incidents.

3. Internal Control Effectiveness (ICE) Ratings

Using structured methodologies like ICE, controls can be measured against:

  • Design Effectiveness: Is the control designed to meet its objective?
  • Operational Effectiveness: Does it work consistently in practice?
  • Residual Risk Impact: How much risk remains after applying the control?
    Controls can be scored (e.g., 1-5 scale) and aggregated to measure combined assurance.

4. Cost vs. Performance Ratios

Measurement must also consider the efficiency of controls:

  • Example: If a high-tech locking system costs ZAR 1 million but prevents only low-value losses, its performance value may be low compared to its cost.
  • This supports return on security investment (ROSI) analysis.

The Measurement Process

  1. Define Measurement Criteria
    • Based on control objectives from the Control Catalogue.
    • Examples: availability, reliability, timeliness, compliance.
  2. Collect Data
    • Through monitoring (logs, audits, system reports, ICE assessments).
  3. Assign Values
    • Quantify performance using metrics, KPIs, KRIs, or scoring models.
  4. Analyse and Compare
    • Compare across time periods, sites, or against defined targets.
  5. Report and Improve
    • Feed results into tactical reviews and strategic management meetings.
    • Adjust resources, training, or technology where performance is weak.

Example - Perimeter Security Controls

  • Control: Perimeter CCTV cameras.
  • Objective: Detect unauthorized access attempts.
  • Monitoring Result: 98% uptime recorded.
  • Measurement:
    • KPI: “% of downtime per month” = 2%.
    • ICE Score: 4/5 (Effective, minor weaknesses).
    • ROSI: Savings from prevented thefts vs. cost of camera maintenance = 3:1.

This provides quantitative assurance to management that the control is both effective and cost justified.

Documentation and Audit Evidence

Auditors will expect:

  • Measurement Frameworks (defined KPIs, KRIs, ICE methodology).
  • Measurement Records (data logs, calculation sheets, trend analyses).
  • Performance Reports (monthly/quarterly dashboards).
  • Corrective Action Logs tied to measurement results.
  • Management Reviews showing decisions made based on measurements.

Most reliable evidence: Automated dashboards, system reports, validated data logs.
Moderate: Supervisor measurement sheets, Excel-based scoring.
Least reliable: Verbal assessments without quantification.

Conclusion

Measurement of security controls under ISO 18788 Clause 9.1 turns monitoring into actionable intelligence. By putting numerical values on performance through KPIs, KRIs, ICE ratings, and cost-performance analysis, organizations gain a clear view of control effectiveness and efficiency.

This enables not only compliance with ISO 18788 but also strategic decision-making about where to invest resources for the greatest security and operational impact.