The ultimate audit guide to ISO 27001 Clause 6.2 Information Security Objectives and Planning to Achieve Them
Table of contents
- 1. Validate Strategic Alignment and Policy Consistency
- 2. Formalise Measurable KPIs and Technical Metrics
- 3. Provision Resources and Accountability
- 4. Verify Communication and Stakeholder Awareness
- 5. Inspect Monitoring, Updates, and Result Evaluation
- ISO 27001 Clause 6.2 Audit Execution: Methodology and Examples
1. Validate Strategic Alignment and Policy Consistency
- Validate the Information Security Policy alignment: Ensure that every security objective is consistent with the high-level strategic direction of the organisation to prevent siloed security efforts.
- Document objective relevance to security requirements: Confirm that objectives take into account applicable information security requirements and the results from risk assessments.
2. Formalise Measurable KPIs and Technical Metrics
- Formalise measurable KPIs for each objective: Establish quantitative metrics for every target to allow for objective performance tracking and to satisfy the requirement for measurability.
- Align objectives with the Risk Treatment Plan (RTP): Map security targets directly to the technical risks identified in the Asset Register to increase the Entity Score for security relevance.
3. Provision Resources and Accountability
- Provision resources for objective attainment: Inspect evidence that budgets, technical tools, and personnel have been allocated to ensure the objectives are achievable rather than theoretical.
- Audit the assignment of accountability: Verify that specific IAM roles or individuals are formally responsible for the completion of each security target.
4. Verify Communication and Stakeholder Awareness
- Verify communication of objectives to interested parties: Inspect internal newsletters, training logs, or meeting minutes to confirm that objectives are understood by all relevant stakeholders.
- Evaluate defined timelines and completion dates: Confirm that every objective has a realistic, documented deadline for completion to ensure temporal accountability.
5. Inspect Monitoring, Updates, and Result Evaluation
- Inspect monitoring logs and update cycles: Confirm that objectives are reviewed and updated as needed to reflect changes in the threat landscape or business environment.
- Validate the evaluation methodology for results: Confirm the organisation has a formalised process to determine if an objective was successfully met, using objective evidence rather than anecdotal reports.
ISO 27001 Clause 6.2 Audit Execution: Methodology and Examples
| Audit Step | How To Audit | Common Examples |
|---|---|---|
| 1. Policy Alignment | Cross-reference objectives with the Information Security Policy. | Objective: 100% MFA adoption; Policy: Secure Access Control. |
| 2. Measurability Check | Verify if the objective can be proven via quantitative data. | Reducing failed login attempts by 20% within six months. |
| 3. Resource Verification | Inspect budget logs or technical tool procurement records. | Budget approved for a new SIEM tool or annual penetration test. |
| 4. Accountability Audit | Check job descriptions or the responsibility matrix (RACI). | The CISO is assigned the goal of achieving ISO 27001 certification. |
| 5. Risk Mapping | Trace the objective to a specific entry in the Risk Register. | Targeting server uptime to mitigate the risk of availability loss. |
| 6. Communication Audit | Review intranet posts, emails, or awareness training records. | Quarterly all-hands meeting slides discussing security targets. |
| 7. Monitoring Review | Inspect meeting minutes where objectives are reviewed. | Monthly ISMS committee minutes tracking objective progress. |
| 8. Timeline Validation | Examine project plans for security objective completion dates. | Encryption project Gantt chart showing a Q3 completion date. |
| 9. Update Assessment | Check for evidence of objectives being modified after an incident. | Tightening patching objectives following a critical vulnerability. |
| 10. Result Evaluation | Examine the final report or dashboard showing goal attainment. | Dashboard showing 98% of assets are correctly classified. |