The Requirement
Clause 6.2 requires you to establish information security objectives at relevant functions and levels. They must be:
•Consistent with the information security policy
•Measurable (if practicable)
•Consider applicable requirements and risk assessment results
•Be monitored, communicated, and updated as appropriate
Bad Objectives vs Good Objectives
Bad
•"Improve security" — not measurable
•"Achieve zero incidents" — unrealistic
•"Comply with ISO 27001" — circular
•"Implement all controls" — not strategic
Good
•"Reduce mean time to patch critical vulnerabilities from 14 days to 7 days by Q3"
•"Achieve 95% completion rate for security awareness training by end of year"
•"Complete risk treatment actions for all High-rated risks within 90 days of identification"
•"Conduct quarterly access reviews for all critical systems with documented evidence"
•"Reduce phishing click rate from 15% to under 5% through simulation programme"
How to Choose Objectives
1. Start With Your Risks
Look at your top risks. Objectives should address the most significant ones.
2. Align With Business Goals
Security objectives should support business direction, not work against it.
3. Make Them Achievable
Stretch goals are fine. Impossible goals create apathy.
4. Define Measurement
For each objective: what metric, what target, how measured, how often reviewed?
Tracking & Reporting
•Review progress in management reviews
•Update objectives annually or when context changes significantly
•Document achieved and missed objectives with explanations
•Use objectives performance to drive resource requests
What Auditors Check
•Are objectives documented?
•Are they measurable and monitored?
•Do they link to policy and risk assessment?
•Is there evidence of progress tracking?
•Are they reviewed in management reviews?