The document discusses the increasing importance of ISO 27001 certification for organizations seeking to improve their information security governance and risk management processes. It emphasizes the cyclical PDCA approach as fundamental to the ISO 27001:2013 standard and outlines the necessity for effective measurement of ISMS processes to ensure alignment with business strategies and improvements in risk management. A series of suggested measurement points and metrics are provided to help organizations evaluate their ISMS effectiveness and compliance with security obligations.