The problem which I have now is to define a measurable ISMS objective. One approach will be to focus on security incidents and define something like this
To achieve 0% of security incidents which high, or medium business impact.
But I?m not sure if such objective will be accepted by the auditors during the certification audits.
Does anyone have any idea about this? May be some samples to share.
The problem which I have now is to define a measurable ISMS objective. One approach will be to focus on security incidents and define something like this
To achieve 0% of security incidents which high, or medium business impact.
But I?m not sure if such objective will be accepted by the auditors during the certification audits.
Does anyone have any idea about this? May be some samples to share.
Thanks in advanced.
[ reply ]