Effectiveness Measurement has not been effectively implemented.
The organization has only 1 KPIs related to ISMS that is %NDA signed 100%. This is not sufficient to ensure that the security controls selected to manage the Risks have been effectively implemented.
There was no method on how the organization could collect the information to review the effectiveness of security controls in implementation