ISO 27001

Security objectives & KPIs

Set measurable information security objectives and track them to target, the ISO 27001 Clause 6.2 requirement, with a metric, a baseline, a target, and a live status on each.

Start free See pricing
app.keelgrc.com/objectives
Compliance
Security objectives & KPIs
8
Objectives
6
On track
2
At risk
82%
Avg progress
ObjectiveTargetCurrentOwnerStatus
MFA coverage100%96%IT teamOn track
Mean time to patch< 14d11dSecurityOn track
Phishing click rate< 3%4.1%AwarenessAt risk
Access reviews on time100%100%GRCMet

ISO 27001 Clause 6.2 requires information security objectives that are measurable, monitored, and updated, not vague intentions. Keel gives you a register for exactly that: each objective with a metric, a baseline, a target, and a current value, an owner, a target date, and a status you can move as the work progresses.

Objectives that aren’t measurable, or aren’t tracked

Clause 6.2 is where a lot of programs get a finding: objectives are written once as aspirations, with no metric, no target, and no evidence anyone tracked them. An auditor asks “what are your security objectives, and how are you doing against them?” and there’s no living answer.

What security objectives & kpis does

Measurable by construction

Every objective carries a metric and a numeric baseline, target, and current value, so “measurable”, the word Clause 6.2 hinges on, is built in rather than bolted on.

Monitored over time

Move each objective through not started, on track, at risk, achieved, or missed, and update its current value as you go. The register is the running record that the objectives are actually monitored.

An owner and a target date

Assign who owns each objective and when it’s due. Keel flags objectives with no owner, so accountability is explicit.

Program health at a glance

See how many objectives are achieved, on track, or at risk in one view, the summary a management review (Clause 9.3) needs and an auditor expects.

Feeds your management review

Objectives and their status are exactly the kind of input Clause 9.3 management reviews consume, so the goals you set here flow straight into the leadership review of the ISMS.

Why it matters

  • Meet ISO 27001 Clause 6.2 with genuinely measurable objectives
  • Track baseline → target → current on every objective, monitored over time
  • Assign an owner and due date, and catch objectives with neither
  • Show program progress an auditor and your leadership can read at a glance

Get audit-ready, and prove it

Security objectives & KPIs is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.

Start free

Frequently asked questions

What does ISO 27001 Clause 6.2 require?

That you set information security objectives at relevant functions and levels, and that they are measurable (where practicable), monitored, communicated, and updated. Keel’s objectives register captures the measurable and monitored parts directly.

What makes an objective “measurable”?

A metric plus a numeric target you can compare against. Each objective in Keel has a metric and a baseline / target / current value, so progress is a number, not an opinion.

How is this different from the risk register?

Risks are things that could go wrong; objectives are the measurable goals you’re steering the program toward. They’re complementary (objectives often come out of treating risks), and Clause 6.2 asks specifically for the objectives.

Do objectives connect to the management review?

Yes. The status of your objectives is a standard input to the Clause 9.3 management review, so what you track here informs the leadership review of the ISMS.

Related features: Management reviews · Readiness reports · Risk register

Works with: ISO/IEC 27001