2.5 Information Security Objectives & Planning (Clauses 6.2 & 7.1)

Key Takeaways

  • Clause 6.2 mandates establishing information security objectives at relevant functions and levels, ensuring alignment with the Information Security Policy.
  • Information security objectives must be SMART: Specific, Measurable, Achievable, Relevant, and Time-bound, with defined key performance metrics.
  • ISO 27001 Clause 6.2 requires explicit planning to achieve objectives: defining what will be done, what resources are required, who is responsible, completion dates, and evaluation methods.
  • The Risk Treatment Plan (RTP) operationalizes selected controls and risk mitigation tasks, integrating directly with security objectives and budget cycles.
  • Clause 7.1 requires organizations to determine and provide the necessary resources (financial, personnel, technology, infrastructure) to establish, implement, maintain, and continually improve the ISMS.
Last updated: July 2026

2.5 Information Security Objectives & Planning (Clauses 6.2 & 7.1)

Setting strategic security direction requires translating high-level Information Security Policy commitments into actionable, measurable targets. ISO/IEC 27001:2022 Clause 6.2 outlines mandatory requirements for establishing information security objectives and planning how to achieve them. Complementing Clause 6.2, Clause 7.1 mandates that top management determine and allocate the necessary resources to establish, implement, maintain, and continually improve the ISMS.


1. Establishing Information Security Objectives (Clause 6.2)

Information security objectives are measurable targets established at relevant functions and levels within the organization. They bridge executive policy and operational control execution.

Mandatory Clause 6.2 Requirements

Clause 6.2 specifies that information security objectives must:

  1. Align with Security Policy: Be consistent with the high-level information security policy established under Clause 5.2.
  2. Be Measurable: Expressed quantitatively or qualitatively so that achievement can be objectively verified.
  3. Incorporate Security Requirements: Take into account applicable legal, regulatory, contractual, and risk assessment results.
  4. Be Monitored & Communicated: Tracked on an ongoing basis and communicated to relevant internal and external stakeholders.
  5. Be Updated & Retained: Updated as organizational context evolves, and retained as documented information.

2. Applying the SMART Framework to Security Objectives

Lead Implementers must ensure security objectives avoid vague statements like 'Improve corporate security.' Objectives must follow the SMART framework.

SMART CriteriaObjective CharacteristicNon-Compliant Vague ObjectiveCompliant SMART Objective
SpecificPrecise target operational area'Enhance employee security awareness.''Achieve 100% completion of phishing response training for all active staff.'
MeasurableQuantifiable metric or KPI'Reduce malware infections.''Maintain zero uncontained workstation malware infections per quarter.'
AchievableRealistic given resources'Eliminate 100% of all software bugs.''Remediate 100% of Critical vulnerabilities within 14 days of release.'
RelevantDirectly mitigates high risks'Purchase new firewall hardware.''Deploy MFA across 100% of remote access VPN endpoints to mitigate risk R-04.'
Time-boundExplicit target completion date'Patch critical servers soon.''Achieve full MFA deployment across all systems by October 31, 2026.'

3. Planning to Achieve Objectives (The 5 Mandatory Questions)

Setting an objective without an operational action plan violates Clause 6.2. When planning how to achieve its security objectives, ISO/IEC 27001 explicitly requires the organization to document five core elements:

+-----------------------------------------------------------------------------+
|                     CLAUSE 6.2 ACTION PLANNING FRAMEWORK                    |
+-----------------------------------------------------------------------------+
| 1. WHAT will be done?          ---> [Defined Action / Project Deliverable] |
| 2. WHAT RESOURCES required?    ---> [Budget, Tools, Staffing Allocated]   |
| 3. WHO will be responsible?    ---> [Assigned Lead / Function Owner]      |
| 4. WHEN will it be completed?  ---> [Target Milestone Deadline]           |
| 5. HOW evaluated?              ---> [Metrics / Audit KPI Verification]    |
+-----------------------------------------------------------------------------+

Practical Action Plan Example

  • Objective: Reduce high-risk third-party vendor security exposure by Q3 2026.
    • 1. What will be done: Implement automated vendor risk scoring platform and execute updated security assessments for all Tier-1 vendors.
    • 2. Resources required: $35,000 SaaS platform subscription budget + 120 hours of Vendor Risk Analyst labor.
    • 3. Who is responsible: Head of Procurement & Vendor Risk Lead.
    • 4. Completion date: September 30, 2026.
    • 5. Evaluation method: Monthly KPI reporting showing 100% of Tier-1 vendors evaluated with executed SLAs.

4. Developing & Operationalizing the Risk Treatment Plan (RTP)

The Risk Treatment Plan (RTP) is the master operational document that connects risk assessment findings, selected Annex A controls, SMART security objectives, and project execution timelines.

+-----------------------------------------------------------------------------+
|                     RISK TREATMENT PLAN INTEGRATION                         |
+-----------------------------------------------------------------------------+
| [Risk Register Findings]  --> [Selected Annex A Controls (SoA)]             |
|                                          |                                  |
| [Clause 7.1 Resource Budget] <-- [SMART Objectives & Action Plan (6.2)]     |
+-----------------------------------------------------------------------------+

Key Components of an Effective RTP

  1. Risk Identifier & Inherent Score: Link to specific risk entries in the Risk Register.
  2. Selected Control Reference: Corresponding Annex A or custom control (e.g., A.8.8 Management of Technical Vulnerabilities).
  3. Specific Implementation Tasks: Action items required to deploy the control.
  4. Assigned Action Owner: Designated individual accountable for task execution.
  5. Required Resources & Budget: Direct link to Clause 7.1 resource allocations.
  6. Target Milestone Dates & Current Status: Project tracking fields updated bi-weekly.

5. Resource Allocation & Leadership Commitment (Clause 7.1)

Under Clause 7.1, the organization must determine and provide the resources needed for the establishment, implementation, maintenance, and continually improve the ISMS. Resources fall into three essential categories:

Resource Categories under Clause 7.1

  1. Financial Resources: Dedicated capital expenditure (CapEx) for security software, hardware upgrades, external consultancy, and certification audit fees; operational expenditure (OpEx) for continuous monitoring subscriptions.
  2. Human Resources & Expertise: Assigning qualified personnel with adequate time, competence (Clause 7.2), and authority to manage ISMS roles.
  3. Infrastructure & Technology: Providing secure physical workspaces, network bandwidth, SIEM logging tools, vulnerability scanners, and backup storage.

6. Metrics & Continuous Performance Monitoring

Objectives must be monitored continuously to fulfill Clause 6.2 d). Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) are established for each objective. Performance results feed directly into Management Review (Clause 9.3) and drive Continual Improvement (Clause 10.2).


7. PECB Exam Mastery Notes

  • The 5 Mandatory Questions: Be prepared to identify the exact 5 questions mandated by Clause 6.2 when planning how to achieve security objectives: what will be done, what resources are required, who will be responsible, when it will be completed, and how results will be evaluated.
  • Evaluating SMART Objectives: Exam questions present candidates with multiple candidate objective statements and ask which one satisfies Clause 6.2. The correct choice is always the one that is Specific, Measurable, Achievable, Relevant to risk, and Time-bound (e.g., deploying MFA across remote endpoints by October 31, 2026).
  • Clause 7.1 Resources: Remember that top management cannot delegate resource provision—Clause 7.1 explicitly places the duty of providing financial, human, and technical resources on top management.
Test Your Knowledge

Under ISO/IEC 27001:2022 Clause 6.2, which set of elements must an organization explicitly document when planning how to achieve its information security objectives?

A
B
C
D
Test Your Knowledge

Which of the following represents a fully compliant SMART security objective that satisfies ISO/IEC 27001 Clause 6.2 requirements?

A
B
C
D
Test Your Knowledge

What is the primary function of Clause 7.1 (Resources) within the ISMS planning and implementation framework?

A
B
C
D