Home | News | Understanding the Objective setting for ISO 27001?

News

Understanding the Objective setting for ISO 27001?

Understanding The Objective Setting For Iso 27001?

Understanding the Objective setting for ISO 27001?

Setting information security objectives is an important part of ISO 27001 because it turns broad security commitments into specific results that an organisation can work towards, monitor and review.

An Information Security Management System, commonly called an ISMS, should not exist simply to produce policies or satisfy an auditor. It should help the organisation improve how it protects information, manages risk and supports business priorities. Information security objectives provide a practical connection between those goals and everyday activity.

ISO/IEC 27001:2022 Clause 6.2 requires organisations to establish information security objectives at relevant functions and levels. Those objectives need to align with the information security policy, consider applicable security requirements and take account of risk assessment and risk treatment results. Organisations must monitor, communicate and update objectives as appropriate and retain documented information about them. ISO guidance also confirms that objectives should be measurable where practicable.

For a business, that means moving away from statements such as “improve security” and towards objectives that clearly describe what the organisation wants to achieve, who owns the work and how management will know whether it succeeded.

UK Cyber Compliance supports organisations through this process with an automated and AI-driven platform. UK Cyber Compliance (a part of UK Cyber Security Group) provides these services and has a platform to make certification much easier and cheaper. The platform brings risk assessment, controls, policies, progress monitoring and audit-ready documentation together within structured ISO 27001 workflows.

Why information security objectives matter

Objectives give direction to the ISMS.

An organisation might have an information security policy that commits to protecting customer information, meeting legal requirements and continually improving security. Those statements establish important principles, but management still needs to decide what practical improvements it wants to achieve.

Objectives answer that question.

For example, an organisation might decide that it wants to:

Reduce the number of overdue critical access reviews

Improve staff security awareness

Increase multi-factor authentication coverage

Reduce unresolved high-risk vulnerabilities

Improve the speed of security incident reporting

Increase successful backup recovery testing

Complete supplier security reviews within an agreed period

Reduce unnecessary administrator access

Improve completion of security actions

Strengthen evidence supporting key controls

These objectives transform security commitments into activities that people can own and monitor.

A good objective also helps management prioritise resources. Instead of asking whether the organisation should “do more cyber security”, senior leaders can examine specific goals, current performance and outstanding work.

What is ISO 27001 Certification?

ISO 27001 certification provides independent assurance that an organisation operates an Information Security Management System that meets ISO/IEC 27001 requirements.

ISO describes ISO/IEC 27001 as the world’s best-known standard for information security management systems. It enables organisations to establish an ISMS and apply a risk management process that reflects their own objectives, processes and organisational structure.

An ISMS connects:

Leadership

Business context

Interested parties

Information security risk

Risk treatment

Security objectives

Policies

People

Suppliers

Technology

Physical security

Performance monitoring

Internal audit

Management review

Corrective action

Continual improvement

Objectives sit within this wider management system.

Certification does not simply confirm that an organisation owns particular security tools. It demonstrates that the business manages information security systematically and can provide evidence showing that its processes operate.

ISO itself develops standards rather than issuing ISO 27001 certificates. Independent certification bodies perform certification activity.

what is iso 27001

ISO 27001 is the commonly used name for ISO/IEC 27001:2022, the international requirements standard for information security management systems.

The standard helps organisations manage risks affecting confidentiality, integrity and availability.

Confidentiality concerns whether information reaches only authorised people and systems.

Integrity concerns whether information remains accurate, complete and trustworthy.

Availability concerns whether authorised users can access information and services when they need them.

Information security objectives should support these principles where they matter to the organisation.

A business that relies heavily on an online service may establish objectives relating to availability and recovery.

A company processing confidential customer information may focus on access, data handling and security awareness.

A software provider may establish objectives around vulnerability remediation, secure development and privileged access.

ISO 27001 gives organisations flexibility because security priorities should reflect business context and risk rather than a generic set of goals.

Start with the information security policy

Clause 6.2 expects information security objectives to remain consistent with the organisation’s information security policy.

That makes the policy a sensible starting point.

Review the commitments management has already made.

If the policy commits the organisation to protecting customer information, objectives might focus on access management, encryption, awareness or data handling.

If it commits to continually improving security, objectives could focus on reducing unresolved audit findings or increasing control effectiveness.

If the organisation commits to meeting contractual security requirements, an objective might focus on completing customer security obligations within agreed periods.

Objectives should reinforce policy commitments rather than operate as unrelated projects.

Turn broad commitments into practical goals

Consider a policy statement such as:

“We protect confidential information against unauthorised access.”

That commitment needs practical support.

A related objective might become:

“Complete quarterly access reviews for all critical cloud services and address identified inappropriate access promptly.”

Another could state:

“Ensure that privileged access receives management approval and periodic review.”

These statements give teams something clear to work towards.

Use the risk assessment to identify objectives

Risk assessment provides another valuable source of objectives.

ISO 27001 requires objectives to take account of applicable information security requirements and results from risk assessment and risk treatment.

Look at the organisation’s highest risks.

Suppose the risk register identifies phishing and account compromise as major concerns.

Relevant objectives could include:

Increasing multi-factor authentication coverage

Improving staff phishing recognition

Reducing successful simulated phishing events

Reviewing privileged accounts

Improving suspicious message reporting

If supplier failure represents a high risk, objectives could focus on supplier assessment and continuity.

If ransomware presents significant exposure, objectives might focus on vulnerability remediation, backup testing, recovery exercises or staff awareness.

This approach ensures that objectives support the problems the organisation genuinely needs to manage.

Do not create objectives simply because they sound impressive

An objective should have a business reason.

Statements copied from another company’s ISMS may have little relevance to your organisation.

For example, a small consultancy that uses established cloud applications may gain little value from an objective focused heavily on internal software development.

Likewise, a software provider would probably overlook an important area if it had no objectives connected with development or application security.

Ask:

Which risks matter most?

Which control weaknesses need improvement?

Which customer requirements matter?

Which business services depend heavily on information?

Where have incidents occurred?

What did internal audit identify?

Which actions repeatedly become overdue?

Where would measurable improvement create meaningful value?

Answers to these questions will usually produce more useful objectives than copying generic wording.

Make objectives measurable where practicable

ISO guidance makes an important distinction: Clause 6.2 requires objectives to be measurable if practicable.

That wording matters.

It does not mean every objective needs a percentage or numerical target.

ISO committee guidance explains that qualitative results can also demonstrate achievement when appropriate evidence supports them.

For example:

“Complete a recovery exercise for the customer platform.”

The organisation can answer yes or no and retain evidence showing whether the exercise happened.

Another objective might say:

“Review all critical suppliers during the current review period.”

Again, the organisation can measure completion.

Numerical targets can still provide useful clarity.

Examples include:

“Achieve 100 per cent completion of annual information security awareness training.”

“Reduce overdue high-risk vulnerability actions to fewer than five.”

“Complete access reviews for all critical cloud systems every quarter.”

“Reduce unapproved administrator accounts to zero.”

“Test recovery of every critical information service during the year.”

The chosen measurement should support good decision-making rather than exist simply for the auditor.

SMART objectives can help, but ISO does not demand the acronym

Many organisations use SMART when writing objectives.

The approach encourages objectives that remain specific, measurable, achievable, relevant and time-bound.

It can provide a useful drafting framework, but ISO 27001 does not require organisations to label objectives as SMART.

The standard focuses on the substance.

An effective objective tells people what success means and supports monitoring.

For example:

Weak objective:

“Improve staff security awareness.”

Stronger objective:

“Ensure all employees complete annual information security awareness activity and review any outstanding completion every month.”

The stronger version gives management a clear result and review process.

Connect objectives to business priorities

Information security should support the organisation rather than compete with it.

ISO management system standards aim to help organisations use repeatable processes to achieve goals while reviewing and improving performance.

If the business plans to expand a cloud service, information security objectives may focus on maintaining resilience and access control as usage increases.

If the company wants to enter a supply chain with strict security requirements, an objective might focus on addressing assurance gaps.

If customers increasingly ask questions about supplier security, management may establish an objective to review critical suppliers.

The strongest objectives answer two questions:

What security improvement do we want?

Why does the business care?

This connection also makes senior management engagement easier.

Leaders are more likely to support a security objective when they understand how it protects customers, service delivery or business commitments.

Decide who owns each objective

Every meaningful objective needs ownership.

The owner should have enough authority and knowledge to drive the required activity.

Possible owners include:

Information Security Manager

IT Manager

Operations Director

Human Resources Manager

Service Delivery Manager

Development Lead

Supplier Manager

Compliance Manager

Department Head

Avoid assigning every objective automatically to the same security employee.

An awareness objective may need support from human resources.

A supplier objective may belong with procurement or operations.

A vulnerability objective may require IT ownership.

A secure development objective may belong with the development team.

Security works better when responsibility sits with the people who control the relevant process.

Define what needs to happen

ISO 27001 requires organisations to plan how they will achieve their information security objectives.

That means defining the activities required rather than merely publishing a target.

Suppose the objective involves completing access reviews.

The plan may involve:

Identifying critical services

Confirming account owners

Generating access reports

Sending reviews to managers

Recording decisions

Removing inappropriate access

Retaining evidence

Reporting completion

The organisation now has a repeatable process behind the objective.

For an awareness objective, the work might involve selecting relevant material, assigning it to employees, tracking completion and following up missed activity.

Planning converts the objective into real work.

Identify the resources required

Objectives need resources.

Those resources might involve:

Employee time

Management attention

Technical expertise

Security tools

External support

Training material

Internal audit effort

Reporting capability

Automation

An organisation should set realistic objectives that reflect available resources.

An ambitious goal has little value when nobody has the time or authority to deliver it.

Resource planning also helps senior management understand what an objective requires before approving it.

Decide when the objective should be completed

Objectives need a suitable timeframe.

Some work follows an annual cycle.

Other objectives might need quarterly or monthly monitoring.

A serious risk may justify a much shorter period.

For example:

Complete an access review every quarter

Finish annual awareness activity during a defined period

Review critical suppliers once each year

Resolve identified audit actions within agreed deadlines

Test recovery arrangements during the current certification period

Avoid setting arbitrary dates simply because they appear precise.

The timeframe should reflect risk and business need.

Decide how you will evaluate the result

An objective requires a clear evaluation method.

Ask what evidence will demonstrate success.

Useful evidence could include:

Access review records

Training completion records

Vulnerability reports

Supplier review records

Backup recovery reports

Incident reports

Audit findings

System reports

Management dashboards

Control test results

Action records

The evidence should support the objective directly.

For example, a policy stating that staff need training does not prove completion. Training records provide much stronger evidence.

Likewise, a backup dashboard does not necessarily demonstrate successful recovery. A completed recovery test provides better evidence for an objective focused on recoverability.

Monitor objectives instead of waiting for audit day

ISO 27001 requires organisations to monitor information security objectives.

Do not create objectives during certification preparation and ignore them until the next external audit.

Review performance regularly.

A simple management dashboard might show:

Objective

Owner

Target

Current position

Evidence

Status

Next action

Review date

Management can then see which goals remain on track and which require attention.

UK Cyber Compliance currently provides real-time progress tracking, risk analysis, control coverage and audit reporting through its compliance platform.

Centralising this information can reduce the difficulty of tracking objectives across separate files.

Communicate objectives to the people who matter

ISO 27001 also requires organisations to communicate information security objectives.

That does not mean every employee needs detailed knowledge of every ISMS metric.

Communicate objectives according to relevance.

The IT team may need to understand vulnerability remediation targets.

Human resources may need awareness completion information.

Department managers may need access review responsibilities.

Senior management needs visibility of significant objectives and progress.

Employees should understand the goals that affect their own responsibilities.

Clear communication helps objectives become part of normal operations rather than compliance paperwork.

Update objectives when circumstances change

An objective that mattered last year may no longer represent the organisation’s biggest priority.

ISO 27001 expects objectives to receive updates where appropriate.

Review them after:

Significant security incidents

Major audit findings

New services

Important customer requirements

Changes to critical suppliers

Major technology changes

Business restructuring

New risks

Control failures

Changes in legal obligations

Suppose the organisation suffers repeated phishing attempts against finance employees.

Management may decide to add or strengthen an objective around account protection and targeted awareness.

A major cloud migration may create new objectives around configuration review, resilience or administrator access.

The objective process should respond to real business change.

Use internal audit to test whether objectives work

Internal audit can examine whether the organisation has established and managed objectives effectively.

An internal auditor may ask:

Do objectives align with the information security policy?

Have risk assessment results influenced them?

Does each objective have an owner?

Can the organisation measure or otherwise evaluate achievement?

Does evidence support reported progress?

Have relevant employees received communication?

Does management review progress?

Have overdue objectives triggered action?

Have objectives changed after significant events?

This testing helps identify weak management practices before the certification audit.

Management review should examine performance

Information security objectives provide valuable input to management review.

Senior leaders can examine whether the organisation achieved planned results and whether security activity supports business priorities.

Discussion may cover:

Completed objectives

Missed targets

Reasons for delay

Resources

Risk changes

Audit findings

Incidents

Control performance

Required improvements

Future objectives

Management should do more than receive a dashboard.

Leaders should make decisions when performance falls short.

That could involve allocating resources, changing the objective, increasing oversight or choosing another control.

Examples of strong information security objectives

The right objectives depend on the organisation, but the following examples show how useful goals can work.

Access management

“Complete access reviews for every critical business service each quarter and remove access that no longer has a valid business justification.”

Evidence could include completed reviews, approvals and account removal records.

Vulnerability management

“Review high-risk vulnerability findings within the agreed remediation period and report overdue actions to management.”

Evidence might include scanning reports, remediation tickets and management escalation.

Security awareness

“Maintain annual security awareness participation across all employees and follow up any outstanding activity.”

Evidence can include learning records and completion reports.

Supplier assurance

“Complete security assessments for all critical suppliers during the annual review cycle.”

Evidence might include supplier questionnaires, assurance reports and review records.

Incident response

“Complete at least one information security incident response exercise during the current review period and document improvement actions.”

Evidence may include the exercise plan, attendance, findings and completed actions.

Backup recovery

“Test restoration of information supporting critical services according to the agreed recovery schedule.”

Evidence could include test reports and corrective actions.

These examples provide a starting point, not mandatory ISO requirements.

Your objectives should reflect your own risks and priorities.

Avoid vague objectives

One common weakness involves objectives such as:

“Improve cyber security.”

“Reduce risk.”

“Protect data better.”

“Increase awareness.”

These statements express sensible intentions but do not provide enough direction.

Ask what improvement actually means.

Instead of “reduce risk”, identify a particular risk or control weakness.

Instead of “increase awareness”, identify the activity or outcome you want.

Specific objectives make accountability much easier.

Avoid objectives that the organisation cannot influence

Some goals sit largely outside the organisation’s control.

For example:

“Prevent all cyber attacks.”

No organisation can guarantee that attackers will never target it.

A more useful objective might focus on the company’s own controls:

“Maintain multi-factor authentication across all supported externally accessible business services.”

Another poor goal might be:

“Have zero phishing emails reach employees.”

Security systems may reduce malicious messages, but expecting perfect prevention may create an unrealistic target.

A stronger objective could focus on detection, reporting or account protection.

Do not create too many objectives

More objectives do not necessarily mean a stronger ISMS.

An organisation that tracks fifty weak goals may understand its performance less clearly than one that monitors eight meaningful objectives.

Choose goals that support:

Important risks

Business priorities

Policy commitments

Control weaknesses

Audit findings

Customer requirements

Management concerns

A focused objective set makes monitoring more manageable and helps leadership understand progress.

Current cyber risk shows why measurable improvement matters

The UK Government’s Cyber Security Breaches Survey 2025 to 2026 reported that 43 per cent of businesses identified a cyber breach or attack during the previous 12 months. Phishing affected 38 per cent of businesses.

The same research found that 72 per cent of businesses considered cyber security a high priority for senior management, while 31 per cent had board-level responsibility for cyber security.

These findings show why organisations benefit from turning management concern into specific actions and measurable security goals.

An objective linked to account protection, incident response, awareness or vulnerability management gives leadership a practical way to monitor improvement.

Who needs iso 27001 certification

ISO 27001 certification can benefit organisations that manage valuable information or need to demonstrate structured security governance.

Technology providers, managed service providers, software companies, professional firms, healthcare suppliers, manufacturers, financial organisations, charities and public sector suppliers may all find the framework useful.

Customer requirements often provide a strong reason.

A client may want assurance that its supplier manages information security risk systematically.

Contracts, corporate governance, supply-chain requirements and expansion into security-conscious markets can also influence the decision.

ISO notes that certification can provide credibility by demonstrating that an organisation meets relevant expectations, while some sectors may also face contractual or legal certification requirements.

Objectives become valuable evidence because they demonstrate that the organisation does not merely maintain security controls. It also sets goals, tracks progress and improves.

ISO 27001 Certification Levels

ISO 27001 does not use achievement bands such as bronze, silver or gold.

An organisation either achieves certification for its declared ISMS scope or it does not.

Businesses do move through practical stages during implementation.

These commonly include:

Understanding business context

Identifying interested parties

Defining the ISMS scope

Establishing the information security policy

Setting information security objectives

Completing risk assessment

Treating unacceptable risks

Selecting controls

Preparing the Statement of Applicability

Operating the ISMS

Gathering evidence

Completing internal audit

Holding management review

Undergoing the external certification assessment

After certification, organisations continue to operate and improve the ISMS.

Objectives remain part of that ongoing work.

How the Certification Works

The organisation starts by defining its business context, relevant interested parties and ISMS scope.

It establishes information security policy and leadership responsibilities.

The business then identifies and evaluates information security risks.

Risk treatment determines which controls and actions the organisation needs.

At the planning stage, the organisation also establishes information security objectives that align with policy, relevant requirements and risk results.

The business implements the necessary processes and controls and gathers evidence.

It monitors objectives and other measures to understand whether the ISMS performs effectively.

Internal audit then examines conformity and operation.

Management review gives senior leaders an opportunity to evaluate performance, risks, objectives, findings and improvement needs.

An independent certification body carries out the external certification assessment.

The organisation needs to demonstrate that the ISMS works in practice and that management uses it to support informed decisions.

Objective setting and Annex A controls are different

Information security objectives should not be confused with Annex A controls.

An objective describes something the organisation intends to achieve.

A control helps manage risk.

For example:

Objective:

“Reduce overdue access reviews.”

Relevant controls may support identity management, access rights and privileged access.

Another example:

Objective:

“Improve recovery confidence for critical business information.”

Relevant controls may include backup and ICT readiness measures.

The objective describes the desired result.

The controls help the business achieve or maintain that result.

This distinction prevents organisations from treating the Annex A control list as though it were an objective list.

Connect objectives with your Statement of Applicability

The Statement of Applicability records the controls the organisation has determined are necessary and explains its decisions.

Objectives can help management improve performance across some of those controls.

Suppose vulnerability management remains applicable within the SoA and internal audit identifies repeated overdue remediation.

Management may create an objective designed to reduce that backlog.

If supplier controls remain important and several assessments have become overdue, supplier assurance could become an objective.

This creates useful links between:

Risk

Controls

Performance

Objectives

Actions

Evidence

Management review

Those relationships make the ISMS easier to understand and defend during an audit.

Keep documented evidence

ISO 27001 requires organisations to maintain documented information about their information security objectives.

Useful records may include:

Objective descriptions

Owners

Approval records

Targets

Planned actions

Resources

Progress reports

Evidence

Review dates

Management decisions

Completed results

Corrective action where goals were missed

Do not produce documents solely for the sake of having evidence.

The records should help the organisation manage performance.

What happens when an objective is missed?

Missing an objective does not automatically mean certification fails.

What matters is how the organisation responds.

Ask:

Why did we miss it?

Was the objective realistic?

Were sufficient resources available?

Did ownership remain clear?

Did business priorities change?

Did an unexpected event affect progress?

Does the underlying risk remain acceptable?

Do we need corrective action?

Should the objective continue?

Management should document important decisions.

A missed target can provide valuable information if the organisation uses it to improve.

Pretending every objective always succeeds creates less confidence than demonstrating honest management and effective action.

Which UK-based firms offer ISO 27001 consultancy services?

UK organisations can obtain ISO 27001 assistance from information security consultancies, compliance specialists, managed security providers and platform-led services.

UK Cyber Compliance provides ISO 27001 support through an automated and AI-driven platform. Its current platform includes structured guidance, intelligent risk assessment, policy generation, real-time progress tracking and audit-ready documentation.

A capable provider should help an organisation understand how objectives connect with:

Business context

Information security policy

Risk assessment

Risk treatment

Controls

The Statement of Applicability

Monitoring

Internal audit

Management review

Audit evidence

Good support should leave the organisation able to understand and manage its own ISMS.

Management should still decide which objectives matter and approve the resources needed to achieve them.

How UK Cyber Compliance supports objective management

Managing objectives through individual documents and spreadsheets can make progress difficult to see.

UK Cyber Compliance provides a central compliance environment where businesses can connect ISO 27001 work with risk information, controls, documentation and real-time progress monitoring.

The platform currently provides structured workflows, risk assessment functionality, control coverage, audit reports and live progress information.

This can help businesses see whether security work remains on track and identify gaps earlier.

Automation also reduces repetitive administration, but human judgement remains essential.

Senior leaders choose priorities.

Risk owners understand business exposure.

Control owners manage security processes.

Objective owners track progress.

Technology helps organise and report that information.

A practical ISO 27001 objective checklist

Before approving an information security objective, ask:

Does it support our information security policy?

Does it relate to a meaningful business or security requirement?

Have we considered our risk assessment and treatment results?

Can we measure or otherwise evaluate achievement?

Does someone clearly own it?

Have we defined what needs to happen?

Do we know which resources the work requires?

Have we set an appropriate completion period?

Do we know how we will evaluate the result?

Have we communicated the objective to relevant people?

Will we monitor progress?

Do we know what evidence we will retain?

Will management review important results?

Do we know what happens if we miss the objective?

Does the goal still reflect current business priorities?

A clear answer to these questions gives the organisation a strong foundation.

Turning security intentions into measurable progress

Information security objectives turn ISO 27001 from a collection of security commitments into an active management system.

Start with your business priorities and information security policy.

Review the risk assessment and treatment plan.

Identify areas where improvement will create meaningful value.

Set clear objectives at the functions and management levels that need them.

Make each objective measurable where practicable and decide how the organisation will evaluate success.

Assign ownership.

Identify resources.

Set appropriate completion periods.

Monitor progress.

Communicate relevant objectives.

Keep evidence.

Update goals when risks, systems or business priorities change.

UK Cyber Compliance supports this work through an automated and AI-driven platform that brings risk, controls, documentation, progress tracking and audit readiness together.

Well-designed information security objectives give leaders a clear way to see whether the ISMS is improving. They also help employees understand what needs to change, give auditors better evidence of active management and ensure that ISO 27001 supports genuine business security rather than becoming a paperwork exercise.

UK Cyber Compliance is here to help

For more information, please do get in touch.

Please check out our Free Cyber Insurance

Other blog posts, Your ISO 27001 Questions AnsweredGet ISO 27001 Certified ,

If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks.