Security Operations Objectives - How to Achieve Them and Apply Treatments
Introduction
Clause 6.2.2 of ISO 18788:2015 builds on the foundation of Clause 6.2 (Security Operations Objectives) and requires organizations to not only define objectives but also to establish plans for how these objectives will be achieved and treated. This clause ensures that objectives are actionable, measurable, and linked to risk treatment measures, providing assurance to clients, regulators, and communities that security operations are managed systematically and ethically.
The focus here is on bridging the gap between policy and practice—transforming strategic objectives into operational results through concrete actions, treatments, and monitoring mechanisms.
Security Operations Objectives in Context
As outlined in Clause 6.2, Security Operations Objectives must:
- Be consistent with the Security Policy (Clause 5.2).
- Align with the risk and opportunities process (Clause 6.1).
- Be measurable where practicable.
- Be communicated and understood throughout the organization.
- Be monitored, evaluated, and continually improved.
Clause 6.2.2 takes this further by requiring organizations to define how these objectives will be achieved and treated.
Planning to Achieve Security Operations Objectives
ISO 18788 requires organizations to create structured plans that detail:
- What will be done
- Define clear initiatives, projects, or controls to achieve each objective.
- Example: If the objective is “Reduce incident response time by 20%â€, the plan may include:
- Implementing new digital reporting tools.
- Training supervisors in rapid decision-making.
- Establishing a 24/7 operations control centre.
- What resources will be required
- Financial budgets, personnel, technology, and logistical support.
- Example: Allocating funds for surveillance upgrades or hiring additional compliance officers.
- Who will be responsible
- Clear ownership through assignment of accountable individuals or departments. #BBD0E0 »