ISO 27001:2022 Clause 6.2 Information Security Objectives and Planning Explained

In this guide you will learn how to implement ISO 27001 Clause 6.2 Information Security Objectives and Planning and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

Information security needs to have objectives that set out what the information security management system hopes to achieve. This is the ‘why’ you have an information security management system.

Purpose & Definition

The purpose of ISO 27001 Clause 6.2 is to make sure that you know what you want your information security management system (ISMS) to achieve and how you will go about doing it.

The purpose here is to have an effective information security management system (ISMS) that meets the needs of the organisation.

ISO 27001 defines ISO 27001 clause 6.2 as:

The organisation shall establish information security objectives at relevant functions and levels. The information security objectives shall:

a) be consistent with the information security policy;

b) be measurable (if practicable);

c) take into account applicable information security requirements, and risk assessment and risk treatment results;

d) be monitored

e) be communicated

f) be updated as appropriate.

g) be available as documented information

The organisation shall retain documented information on the information security objectives. When planning how to achieve its information security objectives, the organisation shall determine;

h) what will be done;

i) what resources will be required;

j) who will be responsible;

k) when it will be completed; and

l) how the results will be evaluated.

ISO 27001:2022 Clause 6.2 Information Security Objectives and Planning to Achieve Them
Stuart Barker - High Table - ISO27001 Director

Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.

FREE ISO 27001 Clause 6.2 Training Video

What is Information Security Objectives and Planning?

ISO 27001 Clause 6.2 is a security control that mandates organisations to establish measurable information security objectives at relevant functions. It satisfies the Primary Implementation Requirement of aligning security targets with overarching risk strategy, delivering the Business Benefit of a verifiable, results-driven security management system.

ISO 27001 Clause 6.2 is an ISO 27001 control that requires you to establish information security objectives.

Those objectives should be established at relevant functions and levels in the organisation.

This ISO 27001 clause is all about information security objectives and planning to meet those objectives.

ISO 27001 Toolkit Business Edition

Implementation Guide

The implementation of ISO 27001 Clause 6.2 Objectives is based on three core pillars.

  • Pillar 1 is ensuring strategic alignment.
  • Pillar 2 is establishing the operational framework.
  • Pillar 3 is driving performance and assurance.

To implement ISO 27001 Clause 6.2 effectively, you must move beyond simple documentation and focus on creating a living framework where security goals drive operational behaviour. This involves aligning technical controls, such as Identity and Access Management (IAM) and Asset Registers, with the strategic intent of the Information Security Management System (ISMS).

Implementing ISO 27001 Clause 6.2 ensures that your organisation’s security objectives are actionable, measurable, and aligned with your broader business strategy. Follow these ten steps to establish a high-performance framework for planning and achieving your information security goals, ensuring full alignment with the 2022 standard requirements.

How to implement ISO 27001 Clause 6.2

1. Analyse Business Context and Stakeholder Requirements

  • Provision a thorough review of internal and external issues identified in Clause 4.1.
  • Formalise the requirements of interested parties to ensure objectives meet legal, regulatory, and contractual obligations.
  • Result: A strategic foundation that ensures security goals support the wider business mission.

2. Map Objectives to the Risk Treatment Plan

  • Review the outputs of your Clause 6.1 Risk Assessment to identify high-priority vulnerabilities.
  • Provision specific objectives that directly mitigate risks documented in your Risk Treatment Plan (RTP).
  • Result: Direct alignment between identified security threats and your strategic improvement goals.

3. Establish SMART Information Security Objectives

  • Identify core security requirements based on your Risk Assessment and Information Security Policy.
  • Provision objectives that are Specific, Measurable, Achievable, Relevant, and Time-bound (SMART).
  • Formalise these goals to address the pillars of Confidentiality, Integrity, and Availability (CIA).
  • Result: A documented set of objectives providing a clear baseline for ISMS performance.

4. Formalise the Information Security Objectives Register

  • Document all objectives in a centralised register to meet the “documented information” requirement.
  • Include metadata for each entry, such as the baseline date, target date, and current status.
  • Result: A “single source of truth” for auditors to verify compliance with Clause 6.2.

5. Provision Resources and Technical Tooling

  • Determine the financial, human, and technical resources required to meet each objective.
  • Allocate necessary tooling, such as the ISO 27001 Toolkit, to support the implementation and tracking phase.
  • Result: Operational feasibility and the technical capacity to deliver on security promises.

6. Assign Responsibilities and IAM Role Definitions

  • Assign specific ownership to roles within the organisation, ensuring accountability via clear Job Descriptions.
  • Provision appropriate permissions within your Identity and Access Management (IAM) systems to enable owners to execute tasks.
  • Result: Clear accountability and the technical authority required for objective delivery.

7. Integrate Measurement and Monitoring Metrics

  • Define Key Performance Indicators (KPIs) for every objective, such as MFA adoption rates or patching lead times.
  • Utilise your Asset Register to identify technical touchpoints where automated monitoring can provide real-time data.
  • Result: An evidence-based system that proves the effectiveness of security controls over time.

8. Formalise Communication and Awareness Programmes

  • Communicate objectives to all relevant internal and external interested parties via a formal communication plan.
  • Incorporate objectives into staff induction and ongoing security awareness training to ensure organisational alignment.
  • Use Rules of Engagement (ROE) documents to update technical teams on their specific security responsibilities.
  • Result: A security-conscious culture where every employee understands their contribution to the goals.

9. Audit and Review via Management Review Process

  • Audit the progress of objectives at least annually or following significant organisational changes.
  • Include progress reports in the formal Management Review (Clause 9.3) to ensure senior leadership oversight.
  • Result: Executive visibility and validation of the ISMS performance against the strategic plan.

10. Revoke and Update for Continual Improvement

  • Revoke or update objectives that are no longer relevant to the current risk landscape or business direction.
  • Provision new objectives based on the results of internal audits and emerging threat intelligence.
  • Result: A dynamic ISMS that adapts to new threats while maintaining compliance with Clause 6.2 requirements.
ISO 27001 Templates

ISO 27001 Templates

ISO 27001 templates are a great way to fast track your implementation and leverage industry best practice.

These individual templates help meet the specific requirements of ISO 27001 clause 6.2

ISO 27001 Information Security Policy Template
ISO 27001 Management Review Team Meeting Agenda Template
ISO 27001 Risk Register Template

ISO 27001 Clause 6.2 FAQ

What is ISO 27001 Clause 6.2.1?

ISO 27001 Clause 6.2.1 mandates that an organisation establishes documented information security objectives at relevant functions and levels. Bottom line: these objectives must be consistent with the security policy, be measurable, account for risk assessment results, and be effectively communicated and updated to maintain ISMS compliance.

How do you create measurable security objectives?

Measurable objectives are created by applying the SMART framework (Specific, Measurable, Achievable, Relevant, and Time-bound). Lead auditors look for specific KPIs; for example, achieving 100% encryption on all portable assets or ensuring 99.99% uptime for critical infrastructure, rather than vague statements like “improve security.”

What planning is required for Clause 6.2.2?

To comply with Clause 6.2.2, you must document five specific planning elements: what will be done, what resources are required, who is responsible, when it will be completed, and how the results will be evaluated. This ensures that objectives move from theoretical goals to operational realities within the ISMS.

Who is responsible for setting security objectives?

Top management holds ultimate responsibility for ensuring security objectives are established and aligned with the organisation’s strategic direction. While the CISO or Information Security Manager typically drafts the technical details, 100% of these objectives must be approved and signed off by senior leadership to pass a Stage 2 audit.

The following list identifies the critical 2022 controls that act as the delivery mechanism for your information security objectives:

Outside of ISO 27001 Annex A, ISO 27001 Clause 6.2 is also connected with these core management requirements:

Further Reading

Stuart Barker

I am the ISO 27001 Ninja.

I help tech companies, start-ups, and small businesses implement information security management systems without the corporate bloat or massive consultant fees.

If you want to pass your audit the first time, book a call.

Shopping Basket
Scroll to Top