Information Security Objectives (ISO 27001)
Guidance on how to establish and measure information security objectives
Written By Micah
Clause 6.2 of ISO 27001:2022 requires that management establish information security objectives. These objectives will be communicated throughout the organization and will be periodically monitored. The objectives are to be:
Consistent with the Information Security Policy
Measurable
Take into account information security requirements determined from the risk assessment and risk treatments
Documented
Communicated throughout the organization and periodically updated, as needed by the ISMS Team
Follow these steps to define and monitor your information security objectives.
1) We recommend that you start by defining 3-5 information security objectives. When selecting your objectives:
Consider the Confidentiality, Availability, and Integrity of Client/Customer data
Consider any areas your leadership is already curious about or concerned about
Consider what your customer may be most concerned about - with respect to IT Security or information privacy
2) After selecting your objectives, post them internally on a site easily accessible by all staff.
3) Documented a plan for achieving each information security objective that includes what will be done, the resources required, who will be responsible, when it will be completed, and how the results will be evaluated. This document can be internal to the ISMS core team.
3) Set a time 6 months in the future (and well before your next surveillance audit) to formally monitor how the organization is doing against the objectives. If new objectives are added, update all documentation.
Reach out to your Customer Success Manager if you have any questions.