How to write ISO 27001 Objectives [+ Template]

How To Write ISO 27001 Objectives

ISO 27001 Objectives

In this ultimate guide to ISO 27001 Objectives, you will learn:

  • What ISO 27001 Objectives are
  • How to write them
  • How to audit them
  • Examples of Objectives that pass audits
  • How to pass the audit

I am Stuart Barker, the ISO 27001 Ninja and author of the Ultimate ISO 27001 Toolkit.

Using over 30 years of industry experience across hundreds of audits, I’m giving you the exact templates, walkthroughs, and practical examples you need to achieve ISO 27001 certification.

What are ISO 27001 Objectives?

ISO 27001 Objectives are statements of what you want the information security management system to achieve.

Objectives should be:

  • Specific
  • Measurable
  • Achievable
  • Realistic
  • Timely

For each information security objective you record

  • What will be done
  • What resources will be required
  • Who will be responsible
  • When will it be completed
  • How the results are evaluated

The objectives should be measurable and clear so that you can track your progress over time.

ISO 27001 Toolkit Business Edition

Key Points

You need to understand your organisation and its context before setting goals.

The goals should be focussed on the needs of the business and improving security.

The goals do not have to be overly complex.

ISO 27001 objectives training video

In this free ISO 27001 training video we look specifically at implementing ISO 27001 Objectives.

How to write ISO 27001 objectives

Writing objectives for the information security management system is a straightforward process. These are the steps to follow:

Identify your stakeholders

Stakeholders are people that have a vested interest in the operation of the management system and you will identify who those people are. 

They fall into 2 broad categories being:

  • People that are required to provide resources 
  • People with a vested interest in objectives being met 

Define stakeholder requirements

Once you have identified who the stakeholders are you should ask them what their requirements are for the information security management system. This is more formally covered in the needs and expectations of interested parties and at the end of this step you will be ready to translate those needs and requirements into objectives.

Document the objectives

Taking the requirements you will define the objectives. There are several elements of an objective that you are required to record. They are:

  • Information Security Objective 
  • What will be done 
  • What resources will be required 
  • Who will be responsible 
  • When will it be completed 
  • How the results are evaluated

Agree the objectives

Once the objectives have been documented they must be agreed and approved. To do this you will either:

  • Follow your internal approval method
  • Have them signed off at the management review team meeting and the decision documented in the minutes

Manage the objectives

Objectives are not approved and then forgotten. They are part of the operation of the management system and should be managed. 

You will evidence that you are

  • reviewing the performance of the objectives on a regular basis
  • reviewing the appropriateness of the objectives at least annually
  • addressing any deviation of the management system from it’s objectives through the continual improvement process

The framework for setting ISO 27001 objectives

You will document your framework for setting objectives. The following is a great framework that you can consider adopting.

Objectives are reviewed at least annually or when significant change occurs to the organisation.

Objectives are approved and signed off by the Management Review Team.

Objectives are published in the Information Security Policy which is communicated to and accepted by all staff.

The objectives are based on a clear understanding of the business requirements and as a minimum are based on

  • the Organisation Overview that records the business objectives.
  • the Context of Organisation that records interested parties, internal issues, and external issues.
  • Feedback from Interested Parties capture as part of the Management Review process
  • Output from Risk Assessment and Risk Treatments

Objectives are measured and progress against objectives is tracked at the Management Review Team Meeting.

The objectives are recorded in the Information Security Objectives document that sets out what will be done, what resources are required, who will be responsible, when it will be completed. The Information Security Management system will be measured upon its ability to meet these overall objectives and to achieve these objectives.

Examples

The following are common best practice ISO 27001 objectives:

ObjectiveISO 27001:2022 Control ReferenceWhat will be doneResources RequiredResponsibilityTimeline / DeadlineEvaluation Method
1. Meet Legal & Regulatory Obligations5.31 (Legal, statutory, regulatory and contractual requirements)Implementation of Legal Register; Adherence to Standard; Achieve Accredited Certification.Experienced ISO 27001 implementation resource.Assigned Owner (Recorded in Roles Doc).Legal Register Sign Off: [Date]; Certification Audit: [Date].Legal Register Signed Off; Audits Booked/Completed; Certificate Issued.
2. Manage Third-Party Supplier Risk5.19 (Information security in supplier relationships)Implement Third Party Policy & Register; Review contracts for security assurances.Supplier Management resources.Assigned Owner (Recorded in Roles Doc).Policy Implementation: [Date]; Initial Review: [Date]; Ongoing: Monthly.Register complete; Contracts active with security clauses; Valid ISO certificates or assurances on file.
3. Ensure Confidentiality, Integrity & Availability (CIA)Clause 6.1 (Actions to address risks) & Clause 8.2 (Risk assessment)Risk Management implementation; Annex A Controls via SoA; Monitor control measurement.Information Security Management resources.Assigned Owner (Recorded in Roles Doc).SoA Implementation: [Date]; Effectiveness Review: Monthly.Measures reported to Management Review; Internal Audit checks; External verification.
4. Resource Provisioning & Continual ImprovementClause 7.1 (Resources) & Clause 10.1 (Continual improvement)Assign Roles/Responsibilities; Implement Risk Register; Implement CIP & Incident Log.Information Security Management resources.Assigned Owner (Recorded in Roles Doc).Roles Assigned: [Date]; Risk/CIP Policy: [Date]; Reviews: Annual.Documentation up to date; Corrective actions evidenced; Meeting minutes recorded.
5. Culture, Training & Awareness6.3 (Information security awareness, education and training)Execute Communication Plan; Implement Training Tool; Establish Management Review Team.Training Tool; Awareness Management resources.Assigned Owner (Recorded in Roles Doc).Comms Plan: [Date]; Training Tool: [Date]; Basic Training: Annually.Meeting Minutes; Evidence of Communication; Training completion records.

Applicability of ISO 27001 Objectives across different business models.

Business TypeApplicability of Clause 6.2Tailored Objective Example
Small BusinessesHigh Priority: Focuses on meeting basic legal obligations and client contracts to ensure business survival without over-engineering the management system.“Achieve 100% staff completion of information security awareness training to reduce phishing risks and meet GDPR compliance requirements.”
Tech StartupsCritical: Essential for demonstrating product maturity to investors and enterprise clients. Objectives often align with product uptime and secure development lifecycles.“Ensure the confidentiality, integrity, and availability of the SaaS platform by maintaining 99.9% uptime and resolving critical vulnerabilities within 48 hours.”
AI CompaniesVital: Centres on the integrity of training data and the ethical application of algorithms. Objectives must address unique risks like model inversion or data poisoning.“Protect the integrity of AI models by implementing strict access controls on training datasets and conducting quarterly algorithmic bias reviews.”

ISO 27001 Objectives Process Flow

ISO 27001 Objectives Process Flow

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top