Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
12 / 34

Chapter 10

10Security Objectives and the Statement of Applicability

2 min read12 of 34Read it in the book · page 63

“What is not measured is not managed, and what is not written is not reviewed.”

After risks, Clause 6 of the standard requires two things that turn the system from intentions into commitments: measurable security objectives, and the Statement of Applicability (SoA) that links every control to a justified decision. With these, leader and auditor alike can ask: what did we promise? And did we deliver?

SMART Objectives, Not Slogans

“Improve security” is not an objective. A good objective follows the SMART criteria: Specific, Measurable, Achievable, Relevant and Time-bound.

SMART objective criteriaSMART objective criteria
SMART objective criteria
Text in this figure

S · Specific · M · Measurable · A · Achievable · R · Relevant · T · Time-bound · Example: enable MFA on 100% of cloud and email accounts · within 60 days, measured weekly from the admin console, supporting the goal of zero account takeovers · Figure 12

Weak objectiveSMART objective
Enable two-factor authenticationEnable two-factor authentication on 100% of cloud and social accounts by the end of Q1.
Staff awarenessCut the phishing simulation click rate from 18% to under 5% within six months.
Fix vulnerabilitiesRemediate every critical vulnerability within 7 days and every high one within 30 days.

The Statement of Applicability (SoA)

A document listing the 93 controls in Annex A, stating for each one whether it is applied or excluded, why, and its implementation status. Exclusion is acceptable when justified; a freelancer without an office may exclude some physical controls, but cannot exclude access control.

  • Link it to risks: Every applied control maps to a risk in the register.
  • List additional controls: If you apply a control from outside the annex, such as ISO 42001 controls, list it.
  • Keep it alive: Update it with every risk review; it is the first document an auditor asks for.

Planning for Change

The 2022 edition added an explicit clause on planning for changes (6.3): any change to the system, such as adding a new team, adopting a cloud platform or introducing an AI tool, is planned in a controlled way that considers its security impact before implementation, not after.

A SMART objective turns security from an opinion into an agreed number.

Lessons Learned

  1. 1Security objectives follow the SMART criteria.
  2. 2The Statement of Applicability justifies every applied or excluded control.
  3. 3Every applied control maps to a documented risk.
  4. 4Changes to the system are planned before implementation.

Tip: use ← → to move between sections.