Information Security Objectives and Planning of Changes
In ISO/IEC 27001:2022, Information Security Objectives (Clause 6.2) and Planning of Changes (Clause 6.3) are part of Clause 6, Planning. They turn the information security policy and the risk assessment into measurable action, and they keep the ISMS stable as it evolves. Clause 6.2 requires the or… In ISO/IEC 27001:2022, Information Security Objectives (Clause 6.2) and Planning of Changes (Clause 6.3) are part of Clause 6, Planning. They turn the information security policy and the risk assessment into measurable action, and they keep the ISMS stable as it evolves. Clause 6.2 requires the organization to set information security objectives at relevant functions and levels. Objectives must be consistent with the information security policy, measurable where practicable, and based on applicable security requirements and the results of risk assessment and risk treatment. They must also be monitored, communicated, updated as appropriate, and kept as documented information. The 2022 revision added the explicit requirement for monitoring. To plan how objectives will be achieved, the organization must determine what will be done, what resources are needed, who is responsible, when it will be completed, and how results will be evaluated. Examples include reducing critical vulnerabilities older than 30 days to zero, or reaching 95 percent completion of security awareness training. A Lead Auditor checks that objectives exist and are SMART. The auditor confirms they trace back to the policy and the risk treatment plan, and that owners and deadlines are assigned. The auditor also looks for evidence of progress tracking feeding into performance evaluation (Clause 9.1) and management review (Clause 9.3). Vague aspirations, or objectives without measurement, are common nonconformities. Clause 6.3, new in the 2022 edition, states that when the organization determines a need for changes to the ISMS, those changes shall be carried out in a planned manner. Such changes may involve scope, processes, controls, technology, or organizational structure. Planned change avoids unintended weakening of security. Good practice is to consider the purpose and potential consequences of the change, the continued integrity of the ISMS, resource availability, and the allocation of responsibilities. Auditors seek evidence such as change records, impact assessments, and approvals. They also check links to operational control of planned changes (Clause 8.1) and Annex A control 8.32, Change Management.
Information Security Objectives and Planning of Changes (ISO/IEC 27001 Clauses 6.2 and 6.3): A Complete Guide for Lead Auditor Candidates
Introduction
Clause 6 of ISO/IEC 27001:2022 (Planning) covers three things. Clause 6.1 deals with actions to address risks and opportunities. Clause 6.2 covers information security objectives and planning to achieve them. Clause 6.3 covers planning of changes, which is new in the 2022 edition.
This guide focuses on 6.2 and 6.3. These two clauses turn the information security policy and the risk treatment work into measurable direction and controlled evolution. For a Lead Auditor candidate they are favourite exam topics because they test three abilities: knowing the exact wording of a requirement, linking clauses together, and judging what counts as acceptable audit evidence.
1. Why It Is Important
Objectives turn intent into results. A policy states what management wants. Objectives state what will actually be achieved, by when and how it will be measured. Without objectives, an ISMS has no way to show that it is effective or improving.
Objectives link strategy to operations. Clause 5.1 requires top management to ensure that the policy and objectives are established and compatible with the strategic direction of the organization. Clause 5.2 requires the policy to provide a framework for setting objectives. Clause 6.2 is where that framework becomes concrete.
Objectives feed performance evaluation.
- Clause 9.1 requires monitoring and measurement.
- Clause 9.3 requires management review to consider feedback on information security performance, including the fulfilment of objectives.
Uncontrolled change is a major source of risk. Reorganisations, new outsourcing arrangements, cloud migrations, mergers, scope changes and new legal requirements can all weaken the ISMS if they are made ad hoc. Clause 6.3 ensures the ISMS keeps its integrity while it evolves.
Auditors use these clauses to test management system maturity. An organization can have perfect Annex A controls and still fail certification if it cannot show measurable objectives, plans to achieve them, and controlled changes to the ISMS.
2. What It Is: Clause 6.2 Information Security Objectives and Planning to Achieve Them
The organization shall establish information security objectives at relevant functions and levels. The objectives shall:
- a) be consistent with the information security policy;
- b) be measurable (if practicable);
- c) take into account applicable information security requirements, and the results from risk assessment and risk treatment;
- d) be monitored;
- e) be communicated;
- f) be updated as appropriate;
- g) be available as documented information.
When planning how to achieve its objectives, the organization shall determine:
- what will be done;
- what resources will be required;
- who will be responsible;
- when it will be completed;
- how the results will be evaluated.
Points of nuance
- Relevant functions and levels means objectives may exist at several layers. Examples are a corporate objective, an IT operations objective and an HR objective. Not every department needs one, only the relevant ones.
- Measurable (if practicable) allows some qualitative objectives. An auditor should still expect most objectives to be measurable and should question vague statements such as 'improve security'.
- Monitored and updated as appropriate were made explicit in the 2022 edition. An auditor should look for evidence of tracking, such as dashboards, KPIs or progress reports, and for revisions when the context or risks change.
- Objectives are not the same as controls. Annex A control 5.1 (policies) and the Statement of Applicability are related but distinct. An objective describes a target outcome, for example: 'Reduce critical patch deployment time to under 14 days for 95% of servers by Q4'.
- Objective: Achieve 98% completion of annual security awareness training by all staff by 31 December.
- Link: The policy commitment to competence and awareness, and a risk assessment result showing phishing as a high risk.
- What: Deploy an e-learning module and run a phishing simulation.
- Resources: An LMS licence and 0.2 FTE from the security team.
- Who: The CISO, with HR support.
- When: Quarterly milestones, with completion by year end.
- How evaluated: LMS completion reports and phishing click rate trends, reviewed monthly and reported to management review.
The requirement is short: when the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.
Although brief, auditors normally expect planned changes to consider the following. These points come from the Annex SL intent and good practice:
- the purpose of the change and its potential consequences;
- the integrity of the ISMS during and after the change;
- the availability of resources;
- the allocation or reallocation of responsibilities and authorities;
- updates to the risk assessment, the SoA, documented information and communication.
- outputs of management review (clause 9.3 explicitly includes decisions on any needs for changes to the ISMS);
- internal audit findings and corrective actions (clause 10.2);
- changes in external or internal issues or interested party needs (clauses 4.1 and 4.2, which clause 9.3 also requires to be reviewed);
- scope changes, new sites, acquisitions, outsourcing or restructuring;
- new regulations, or major technology shifts such as moving to the cloud.
This is a common exam trap.
- Clause 6.3 covers planning of changes to the ISMS itself: its scope, structure, processes, roles and policy framework.
- Clause 8.1 (operational planning and control) requires the organization to control planned changes and review the consequences of unintended changes to operations, taking action to mitigate adverse effects.
- Annex A 8.32 (change management) addresses changes to information processing facilities and information systems, for example IT change control and a CAB.
- Clause 6.1.3 and 8.3 require risk treatment plans to be updated when changes occur.
- Top management approves the information security policy (5.2), which provides a framework for objectives.
- The organization completes risk assessment and risk treatment (6.1.2, 6.1.3) and identifies applicable requirements, including legal, contractual and interested party requirements (4.2).
- Objectives are set at relevant levels. They are consistent with the policy, informed by risk results and measurable where practicable.
- Action plans define What, Resources, Who, When and How evaluated. Resources link to 7.1.
- Objectives are communicated (7.3 awareness, 7.4 communication). Staff should know how they contribute (7.3).
- Progress is monitored and measured (9.1), and evidence is retained as documented information.
- Management review (9.3) evaluates fulfilment of objectives and decides on changes and improvements.
- Any ISMS change is planned (6.3), implemented under control (8.1) and reflected in updated risk assessments, the SoA and documents.
- Objectives are updated as appropriate and the cycle repeats, supporting continual improvement (10.1).
Documents to request
- the objectives register or plan;
- KPI dashboards;
- management review minutes;
- the risk assessment report and risk treatment plan;
- the policy;
- project plans or change records for ISMS changes, such as a scope extension or restructuring.
- Top management: are objectives aligned with business strategy, and are resources provided?
- Process owners: what are your objectives, and how are you progressing?
- Staff: are you aware of the objectives relevant to you?
- Pick an objective and trace it back to the policy and risk assessment.
- Trace it forward to the action plan, monitoring data and management review.
- Pick a recent ISMS change and verify it was planned, its consequences considered, responsibilities assigned and documents updated.
- Objectives exist but are not measurable, with no justification that measurement is impracticable.
- Objectives are not linked to risk assessment results or applicable requirements.
- There is no plan stating who, when, resources or how results will be evaluated.
- Objectives were set years ago and never monitored or updated.
- Staff are unaware of objectives, showing a communication failure.
- The scope was extended to a new site without planning, so the risk assessment and SoA were not updated (6.3).
- No documented information on objectives is retained.
- A major nonconformity is a total absence of objectives, or a systemic failure, because the ISMS cannot demonstrate its intended outcomes.
- A minor nonconformity is an isolated lapse, such as one objective lacking a responsible person or a target date.
- An opportunity for improvement covers cases where requirements are met but could be stronger. An example is objectives that are measurable but not trended over time.
- Memorise the seven characteristics (a to g): consistent with policy, measurable if practicable, take into account requirements and risk results, monitored, communicated, updated, available as documented information. Many multiple-choice distractors add items that are not required, for example 'approved by the certification body' or 'must be financial'.
- Memorise the five planning elements: What, Resources, Who, When, How evaluated. A question describing a plan missing one of these is pointing you to a clause 6.2 nonconformity.
- Watch the words 'if practicable'. An objective that is not measurable is not automatically a nonconformity. The auditor should ask whether measurement was practicable.
- Separate objectives from controls and from the policy. If a scenario shows only a policy statement and no targets, the finding is against 6.2, not 5.2.
- Identify the correct clause for change scenarios:
- a change to the ISMS structure or scope points to 6.3;
- an operational change, or an unintended change not reviewed, points to 8.1;
- an IT system change without testing or approval points to Annex A 8.32.
- Link objectives to management review. If minutes show no discussion of objective fulfilment, the finding is against 9.3. If objectives are not tracked at all, the finding is against 6.2 d) and 9.1.
- Use the correct documentation language. Objectives must be available as documented information, and the organization must retain documented information on them. 'Retain' implies records.
- In scenario or essay questions, write findings in full audit format. State the requirement (clause 6.2 c), the evidence (objective records sampled, interview with the CISO on a given date) and the nonconformity statement. The statement should be factual, objective and verifiable, with no recommendations or solutions.
- Think about evidence sources. When asked how to verify a requirement, mention a combination of document review, interviews and observation, plus sampling and traceability.
- Justify your grading. Explain whether the issue is systemic or isolated and whether it affects the ability of the ISMS to achieve its intended results.
- Remember the 2022 changes. 'Monitored' was added as an explicit characteristic in 6.2, and clause 6.3 Planning of changes is entirely new. Exam writers like testing new content.
- Avoid consultancy. As an auditor you may not tell the auditee which objectives to set. You verify conformity and effectiveness.
- Read stems carefully for top management involvement. Clause 5.1 b) makes top management accountable for ensuring objectives are established. A scenario where the IT team alone sets objectives that conflict with business strategy may point to 5.1 as well as 6.2.
- 6.2: Objectives at relevant functions and levels, with seven characteristics and five planning elements. Documented information must be retained.
- 6.3: ISMS changes must be carried out in a planned manner.
- Inputs: policy (5.2), risk results (6.1), requirements (4.2).
- Outputs and links: resources (7.1), awareness (7.3), monitoring (9.1), management review (9.3), operational change control (8.1), continual improvement (10.1).
- Auditor focus: measurability, traceability, monitoring evidence, communication, and controlled change with updated risk assessments and SoA.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!