GuideScope & Governance

Setting Meaningful Information Security Objectives

How to define security objectives that satisfy Clause 6.2 and actually drive improvement — not just tick a box.

Updated 4 Mar 2026

The Requirement

Clause 6.2 requires you to establish information security objectives at relevant functions and levels. They must be:

Consistent with the information security policy
Measurable (if practicable)
Consider applicable requirements and risk assessment results
Be monitored, communicated, and updated as appropriate

Bad Objectives vs Good Objectives

Bad

"Improve security" — not measurable
"Achieve zero incidents" — unrealistic
"Comply with ISO 27001" — circular
"Implement all controls" — not strategic

Good

"Reduce mean time to patch critical vulnerabilities from 14 days to 7 days by Q3"
"Achieve 95% completion rate for security awareness training by end of year"
"Complete risk treatment actions for all High-rated risks within 90 days of identification"
"Conduct quarterly access reviews for all critical systems with documented evidence"
"Reduce phishing click rate from 15% to under 5% through simulation programme"

How to Choose Objectives

1. Start With Your Risks

Look at your top risks. Objectives should address the most significant ones.

2. Align With Business Goals

Security objectives should support business direction, not work against it.

3. Make Them Achievable

Stretch goals are fine. Impossible goals create apathy.

4. Define Measurement

For each objective: what metric, what target, how measured, how often reviewed?

Tracking & Reporting

Review progress in management reviews
Update objectives annually or when context changes significantly
Document achieved and missed objectives with explanations
Use objectives performance to drive resource requests

What Auditors Check

Are objectives documented?
Are they measurable and monitored?
Do they link to policy and risk assessment?
Is there evidence of progress tracking?
Are they reviewed in management reviews?

Related Modules

Objectives
Standard Controls
Documents

Related Controls / Clauses

6.2
5.2
9.1
9.3

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.