Security objectives & KPIs
Set measurable information security objectives and track them to target, the ISO 27001 Clause 6.2 requirement, with a metric, a baseline, a target, and a live status on each.
| Objective | Target | Current | Owner | Status |
|---|---|---|---|---|
| MFA coverage | 100% | 96% | IT team | On track |
| Mean time to patch | < 14d | 11d | Security | On track |
| Phishing click rate | < 3% | 4.1% | Awareness | At risk |
| Access reviews on time | 100% | 100% | GRC | Met |
ISO 27001 Clause 6.2 requires information security objectives that are measurable, monitored, and updated, not vague intentions. Keel gives you a register for exactly that: each objective with a metric, a baseline, a target, and a current value, an owner, a target date, and a status you can move as the work progresses.
Objectives that aren’t measurable, or aren’t tracked
Clause 6.2 is where a lot of programs get a finding: objectives are written once as aspirations, with no metric, no target, and no evidence anyone tracked them. An auditor asks “what are your security objectives, and how are you doing against them?” and there’s no living answer.
What security objectives & kpis does
Measurable by construction
Every objective carries a metric and a numeric baseline, target, and current value, so “measurable”, the word Clause 6.2 hinges on, is built in rather than bolted on.
Monitored over time
Move each objective through not started, on track, at risk, achieved, or missed, and update its current value as you go. The register is the running record that the objectives are actually monitored.
An owner and a target date
Assign who owns each objective and when it’s due. Keel flags objectives with no owner, so accountability is explicit.
Program health at a glance
See how many objectives are achieved, on track, or at risk in one view, the summary a management review (Clause 9.3) needs and an auditor expects.
Feeds your management review
Objectives and their status are exactly the kind of input Clause 9.3 management reviews consume, so the goals you set here flow straight into the leadership review of the ISMS.
Why it matters
- Meet ISO 27001 Clause 6.2 with genuinely measurable objectives
- Track baseline → target → current on every objective, monitored over time
- Assign an owner and due date, and catch objectives with neither
- Show program progress an auditor and your leadership can read at a glance
Get audit-ready, and prove it
Security objectives & KPIs is one module of a full GRC platform: controls crosswalked across every framework, so you collect evidence once and comply everywhere. Start free, no credit card, no sales call.
Start freeFrequently asked questions
What does ISO 27001 Clause 6.2 require?
That you set information security objectives at relevant functions and levels, and that they are measurable (where practicable), monitored, communicated, and updated. Keel’s objectives register captures the measurable and monitored parts directly.
What makes an objective “measurable”?
A metric plus a numeric target you can compare against. Each objective in Keel has a metric and a baseline / target / current value, so progress is a number, not an opinion.
How is this different from the risk register?
Risks are things that could go wrong; objectives are the measurable goals you’re steering the program toward. They’re complementary (objectives often come out of treating risks), and Clause 6.2 asks specifically for the objectives.
Do objectives connect to the management review?
Yes. The status of your objectives is a standard input to the Clause 9.3 management review, so what you track here informs the leadership review of the ISMS.
Related features: Management reviews · Readiness reports · Risk register
Works with: ISO/IEC 27001