Chapter 10
10Security Objectives and the Statement of Applicability
“What is not measured is not managed, and what is not written is not reviewed.”
After risks, Clause 6 of the standard requires two things that turn the system from intentions into commitments: measurable security objectives, and the Statement of Applicability (SoA) that links every control to a justified decision. With these, leader and auditor alike can ask: what did we promise? And did we deliver?
SMART Objectives, Not Slogans
“Improve security” is not an objective. A good objective follows the SMART criteria: Specific, Measurable, Achievable, Relevant and Time-bound.


Text in this figure
S · Specific · M · Measurable · A · Achievable · R · Relevant · T · Time-bound · Example: enable MFA on 100% of cloud and email accounts · within 60 days, measured weekly from the admin console, supporting the goal of zero account takeovers · Figure 12
| Weak objective | SMART objective |
|---|---|
| Enable two-factor authentication | Enable two-factor authentication on 100% of cloud and social accounts by the end of Q1. |
| Staff awareness | Cut the phishing simulation click rate from 18% to under 5% within six months. |
| Fix vulnerabilities | Remediate every critical vulnerability within 7 days and every high one within 30 days. |
The Statement of Applicability (SoA)
A document listing the 93 controls in Annex A, stating for each one whether it is applied or excluded, why, and its implementation status. Exclusion is acceptable when justified; a freelancer without an office may exclude some physical controls, but cannot exclude access control.
- Link it to risks: Every applied control maps to a risk in the register.
- List additional controls: If you apply a control from outside the annex, such as ISO 42001 controls, list it.
- Keep it alive: Update it with every risk review; it is the first document an auditor asks for.
Planning for Change
The 2022 edition added an explicit clause on planning for changes (6.3): any change to the system, such as adding a new team, adopting a cloud platform or introducing an AI tool, is planned in a controlled way that considers its security impact before implementation, not after.
A SMART objective turns security from an opinion into an agreed number.
Lessons Learned
- 1Security objectives follow the SMART criteria.
- 2The Statement of Applicability justifies every applied or excluded control.
- 3Every applied control maps to a documented risk.
- 4Changes to the system are planned before implementation.
Tip: use ← → to move between sections.

