Compliance Framework Alignment
ISO/IEC 27001:2022 — Clause 6.2 (Information security objectives and planning to achieve them) ISO/IEC 27001:2022 — Clause 5.2 (Policy) ISO/IEC 27001:2022 — Clause 6.1 (Actions to address risks and opportunities) ISO/IEC 27001:2022 — Clause 9.1 (Monitoring, measurement, analysis and evaluation) SOC 2 — CC3.1 / CC4.1 This register operationalises ISO/IEC 27001:2022 Clause 6.2 — it establishes information security objectives at relevant functions and levels that are consistent with the Information Security Policy (Clause 5.2), measurable where practicable, and driven by the results of risk assessment and treatment (Clause 6.1). It also captures the planning that Clause 6.2 requires (what will be done, resources, responsibility, deadline and how results are evaluated) and provides the objective-setting and monitoring evidence SOC 2 CC3.1 and CC4.1 expect. It is a supporting record, not a substitute for legal or audit advice.
ACME TECHNOLOGIES PVT LTD INFORMATION SECURITY OBJECTIVES REGISTER
Effective / Issue Date [Effective Date]
Objectives Period FY 2026-27
Register Owner Chief Information Security Officer
Linked Policy POL-ISMS-001 v2.0
Linked Risk Assessment RA-2026-01 / RTP-2026-01
Review Cadence Quarterly
Record Retention 3 years 1. Purpose and Scope
This register records the information security objectives of Acme Technologies Pvt Ltd and the plans to achieve them, in fulfilment of ISO/IEC 27001:2022 Clause 6.2. It establishes objectives at the relevant functions and levels of the organisation — for example IT operations, security operations, engineering, human resources and procurement — as well as at the organisation-wide level. Each objective is set for the period FY 2026-27 , is owned by a single accountable person, and is tracked from its baseline to its target. The register is the primary evidence that Acme Technologies Pvt Ltd sets, plans, monitors and evaluates measurable security objectives, and that those objectives flow from top management's Information Security Policy and from the results of risk assessment and treatment.
2. Consistency with the Information Security Policy
Per Clause 6.2(a), every objective in this register shall be consistent with POL-ISMS-001 v2.0 and shall support at least one commitment expressed in it. Objectives are the concrete, time-bound expression of the direction top management sets in the Policy: where the Policy commits the organisation to protect the confidentiality, integrity and availability of information and to satisfy applicable requirements, each objective states a specific, measurable outcome that advances one of those commitments. Any objective that cannot be traced back to a Policy commitment shall be rejected at review or the Policy shall be updated to reflect it.
3. Derivation from Risk Assessment and Treatment
Per Clause 6.2(c), each objective shall take into account applicable information security requirements and the results of risk assessment and risk treatment. Objectives in this register are cross-referenced to RA-2026-01 / RTP-2026-01 : an objective typically targets the reduction of a specific assessed risk, the implementation of a selected Annex A control, the closure of a risk-treatment action, or the satisfaction of a legal, regulatory or contractual requirement. This linkage ensures the organisation invests effort where risk is greatest rather than pursuing arbitrary targets, and provides a defensible rationale for why each objective was chosen.
4. SMART and Measurable Objectives
Per Clause 6.2(b), objectives shall be measurable wherever practicable. Each objective in this register is expressed in SMART form — Specific, Measurable, Achievable, Relevant and Time-bound. Every row therefore states a defined metric or key performance indicator (KPI), a documented baseline (the starting value against which progress is judged), and a numeric or otherwise verifiable target. Where a truly quantitative measure is not practicable, the objective shall instead specify a verifiable qualitative milestone (for example, ‘risk treatment plan approved and 100% of high risks assigned an owner’) so that achievement can still be objectively determined.
5. Objectives at Relevant Functions and Levels
Per Clause 6.2, objectives shall be established at the relevant functions and levels. This register assigns objectives across the organisation so that responsibility for information security is distributed rather than concentrated: strategic, organisation-wide objectives are owned by top management and the ISMS owner, while functional objectives are owned by the leaders of IT operations, security operations, engineering, human resources, procurement and any other function within the ISMS scope. Assigning an objective to a named function ensures it is embedded in that function's normal planning and performance management.
6. Owner, Metric/KPI, Baseline, Target and Deadline
Per the planning requirements of Clause 6.2 (what will be done, who is responsible, and when it will be completed), each objective record shall name: a single accountable owner; the specific action or programme of work that will achieve it; the metric or KPI by which it is measured; the baseline value at the start of the period; the target value to be reached; and a firm deadline expressed as a date, not a quarter alone. A single named owner — for example ‘Head of IT Operations’ rather than ‘the security team’ — is mandatory, because accountability without a name does not drive action.
7. Resources Required
Per Clause 6.2, the plan for each objective shall determine what resources will be required. Each record shall identify the budget, headcount, tooling, external services and internal effort needed, so that top management can allocate resources when approving the register. An objective for which no resources have been identified or committed is not achievable and shall not be approved. Where an objective depends on a resource that has not yet been secured, that dependency shall be recorded as a risk to delivery.
8. Monitoring, Measurement and Evaluation
Per Clause 6.2(d) and Clause 9.1, each objective shall be monitored, and the plan shall state how the results will be evaluated. Every record specifies its monitoring method — the data source, the measurement technique, and the frequency at which the metric is captured (for example, monthly extraction from the vulnerability scanner, quarterly access-review completion rates, or per-incident MTTR from the ticketing system). Results shall be measured against the target on the defined cadence so that a shortfall is detected early enough to act, and the method shall be consistent enough to produce comparable results over time.
9. Status Tracking and Progress
Each objective moves through a controlled status lifecycle: Not Started → On Track → At Risk → Achieved, or Not Achieved (carried forward or superseded). An objective is ‘On Track’ while its measured value is trending toward the target on schedule, ‘At Risk’ when the trend or timeline indicates the target may be missed, and ‘Achieved’ only once the target value is met and evidenced. An objective that is Not Achieved by its deadline shall be reviewed with Chief Information Security Officer to decide whether it is carried forward with a revised plan, re-scoped, or closed with a documented rationale.
10. Communication and Updating of Objectives
Per Clause 6.2(e) and 6.2(f), objectives shall be communicated to relevant interested parties and updated as appropriate. Approved objectives shall be communicated to the owners and teams responsible for delivering them and to any function whose cooperation is required. Objectives shall be updated when the risk landscape changes materially, when the Information Security Policy is revised, when an objective is achieved, or when circumstances make a target no longer relevant. Every change to an objective — its target, deadline, owner or status — shall be version-controlled with the date, the person making the change, and the reason.
11. Review Cadence and Management Review
This register shall be reviewed on a quarterly basis by Chief Information Security Officer to check progress against every target, refresh baselines, and re-assess whether each objective remains relevant. Progress against the information security objectives is a standing agenda item at the management review under Clause 9.3, where top management considers whether objectives are being met and whether new objectives are required. The review date, reviewer and any actions arising shall be recorded in the register's revision history.
12. Documented Information, Retention and Access
Per Clause 6.2(g), the information security objectives shall be available as documented information. This register, together with its supporting measurement records, constitutes that documented information and shall be retained for at least 3 years, or longer where required by contract, certification scheme or law, so that the history of objectives, targets and outcomes can be evidenced to an auditor. Access shall be restricted to authorised ISMS, audit and management personnel, and any personal data appearing in an owner or measurement field shall be handled in line with Acme Technologies Pvt Ltd 's data-protection obligations.
WORKED OBJECTIVES REGISTER The table below is a worked example showing how each information security objective is recorded against the Clause 6.2 fields. Replace the sample rows with Acme Technologies Pvt Ltd 's own objectives for FY 2026-27 .
Ref Function / Level Objective (SMART) Metric / KPI Baseline Target Monitoring Method Owner Deadline Status OBJ-00 IT Operations Reduce the mean time to remediate critical vulnerabilities on internet-facing systems from 21 days to 7 days by 31 March 2027. Mean time to remediate (MTTR) for critical CVEs, in days 21 days (H2 2026 average) ≤ 7 days [Monitoring method — data source & frequency] Head of IT Operations [Deadline] Not Started OBJ-01 Security Operations Reduce mean time to remediate critical vulnerabilities on internet-facing systems MTTR for critical CVEs (days) 21 days ≤ 7 days Weekly export from the vulnerability scanner; SLA report Head of Security Operations 31 Mar 2027 On Track OBJ-02 IT Operations Complete quarterly user access reviews for all in-scope systems on time % access reviews completed by due date 78% 100% Quarterly access-review tracker; sign-off log Head of IT Operations Each quarter-end On Track OBJ-03 Organisation-wide Raise security awareness and reduce phishing-simulation click rate Phishing-simulation click rate (%) 18% ≤ 5% Bi-monthly phishing campaign platform report ISMS Owner / CISO 31 Dec 2026 At Risk OBJ-04 Engineering / Development Embed secure code review to reduce security defects reaching production High/critical security defects in production per quarter 9 ≤ 2 SAST/DAST findings; defect tracker; release records Head of Engineering 31 Mar 2027 Not Started OBJ-05 Procurement / Vendor Management Assess critical suppliers before onboarding and annually thereafter % critical suppliers with a completed security assessment 60% 100% Vendor risk register; DPA and assessment log Procurement Lead 30 Sep 2026 On Track OBJ-06 Human Resources Ensure timely revocation of access on employee exit % leavers de-provisioned within 24 hours 85% 100% HRMS exit records reconciled against IAM logs Head of HR 31 Dec 2026 On Track
Planning note (Clause 6.2 h–l): for each objective above, the register also records — in the linked action plan — what will be done, the resources required, the person responsible, when it will be completed, and how the results will be evaluated. Every objective is traceable to POL-ISMS-001 v2.0 and to RA-2026-01 / RTP-2026-01 .
This Information Security Objectives Register has been approved by top management of Acme Technologies Pvt Ltd and is effective from [Effective Date]. It shall be reviewed quarterly and updated as objectives are achieved, added or superseded.
Prepared by (Register Owner)
Chief Information Security Officer
______________________
Approved by (Top Management)
Managing Director
______________________