Security Operations Objectives - How to Achieve Them and Apply Treatments
Introduction
Clause 6.2.2 of ISO 18788:2015 builds on the foundation of Clause 6.2 (Security Operations Objectives) and requires organizations to not only define objectives but also to establish plans for how these objectives will be achieved and treated. This clause ensures that objectives are actionable, measurable, and linked to risk treatment measures, providing assurance to clients, regulators, and communities that security operations are managed systematically and ethically.
The focus here is on bridging the gap between policy and practice—transforming strategic objectives into operational results through concrete actions, treatments, and monitoring mechanisms.
Security Operations Objectives in Context
As outlined in Clause 6.2, Security Operations Objectives must:
- Be consistent with the Security Policy (Clause 5.2).
- Align with the risk and opportunities process (Clause 6.1).
- Be measurable where practicable.
- Be communicated and understood throughout the organization.
- Be monitored, evaluated, and continually improved.
Clause 6.2.2 takes this further by requiring organizations to define how these objectives will be achieved and treated.
Planning to Achieve Security Operations Objectives
ISO 18788 requires organizations to create structured plans that detail:
- What will be done
- Define clear initiatives, projects, or controls to achieve each objective.
- Example: If the objective is “Reduce incident response time by 20%â€, the plan may include:
- Implementing new digital reporting tools.
- Training supervisors in rapid decision-making.
- Establishing a 24/7 operations control centre.
- What resources will be required
- Financial budgets, personnel, technology, and logistical support.
- Example: Allocating funds for surveillance upgrades or hiring additional compliance officers.
- Who will be responsible
- Clear ownership through assignment of accountable individuals or departments.
- Example: Operations Department accountable; IT Department providing technology support.
- When it will be completed
- Time-bound objectives and milestones with realistic deadlines.
- Example: All guard force retraining completed by Q4.
- How results will be evaluated
- Key Performance Indicators (KPIs) and measurable metrics.
- Example: Tracking average response time before and after the new processes are implemented.
Linking Objectives with Risk Treatment
Clause 6.2.2 integrates directly with Clause 6.1 (Risks and Opportunities) and requires that achieving objectives must involve risk treatment actions.
- Risk Identification - Each objective must be linked to risks identified in the Strategic, Tactical, or Operational Risk Registers.
- Risk Treatment Options (aligned with ISO 31000:2018):
- Avoid - Cease operations in high-risk areas.
- Mitigate - Apply controls to reduce likelihood or impact.
- Transfer - Outsource or insure against risk.
- Accept - Tolerate residual risks within defined risk appetite.
- Implementation of Controls - Security controls (training, procedures, technology, governance) must be mapped to objectives.
- Monitoring Residual Risk - Post-treatment monitoring ensures risks remain within tolerable levels.
Example:
- Objective: Ensure compliance with human rights obligations.
- Risk: Allegations of unlawful detention by security staff.
- Treatment:
- Mandatory human rights training for all guards.
- Clear rules of engagement.
- Independent grievance mechanisms.
- Evaluation: Tracking incidents, complaints, and disciplinary actions.
Achieving and Sustaining Security Operations Objectives
To ensure objectives are successfully achieved:
- Integration with Daily Operations - Objectives must be embedded in operational procedures, not treated as parallel activities.
- Performance Management - Use dashboards, scorecards, and KPI monitoring to track progress.
- Management Reviews - Regular reviews by top management to assess effectiveness, allocate resources, and make adjustments.
- Audit and Assurance - Internal audits and external certification audits verify that objectives and treatments are properly applied.
- Continual Improvement - Lessons learned from incidents, near misses, and audits feed back into updated objectives and treatment plans.
Example of an Objective and Treatment Flow
- Strategic Objective: Enhance client trust through international certification.
- SOMS Objective: Achieve and maintain ISO 18788 certification.
- Departmental Objective: Conduct quarterly compliance audits across all regions.
- Operational Objective: Ensure 100% incident reports are submitted within 24 hours.
- Linked Risk: Inconsistent incident reporting across provinces.
- Treatment:
- Implement standardized digital reporting tool.
- Train all supervisors in its use.
- Audit incident reports monthly.
- Evaluation: Measure compliance rate, corrective actions, and residual risk rating.
This demonstrates the golden thread of alignment, supported by treatments that are concrete, measurable, and linked to risk management.
Conclusion
Clause 6.2.2 of ISO 18788 ensures that Security Operations Objectives are not abstract intentions but concrete, measurable commitments backed by resources, responsibilities, timelines, and treatments. By linking objectives to risk treatment, organizations create a transparent and auditable process that aligns strategy with daily operations.
Ultimately, this clause ensures that security companies and departments move from policy to practice, delivering on their commitments to professionalism, human rights, compliance, and continual improvement.