Security Operations Objectives - Building the Golden Thread of Alignment

Introduction

Clause 6.2 of ISO 18788:2015 requires organizations to establish Security Operations Objectives (SOOs) that are consistent with the Security Policy, measurable where possible, and aligned with the outcomes of the risk and opportunities analysis. These objectives are the heart of the Security Operations Management System (SOMS), ensuring that strategy is translated into operational results.

Importantly, Security Operations Objectives are not standalone—they must cascade from the organization's strategic objectives, flow through departmental objectives, and connect to operational activities. This creates a golden thread that links governance, risk, compliance, and performance across all levels of the company.

The Cascading Structure of Objectives

  1. Strategic Objectives (Board and Executive Level)
    • Derived from the company's mission, vision, and long-term strategy.
    • Examples: Enhance client trust through compliance with international standards, Expand into new markets ethically and sustainably.
  2. Security Operations Objectives (Organizational SOMS Level)
    • Translate strategic objectives into security-specific outcomes.
    • Examples: Ensure 100% compliance with human rights obligations in security deployments, Reduce incident response times by 20%, Achieve ISO 18788 certification across all regions.
  3. Departmental Objectives (Divisional and Functional Level)
    • Break down organizational security objectives into departmental targets.
    • Examples:
      • HR Department: Ensure vetting and background checks are completed for 100% of recruits.
      • Operations Department: Conduct quarterly scenario-based drills in all provinces.
      • Compliance Department: Complete bi-annual audits of subcontractor compliance.
  4. Operational Objectives (Frontline and Tactical Level)
    • Define actionable, measurable tasks at site, unit, and supervisor level.
    • Examples: All guards to complete refresher training on rules of engagement by Q3, Incident reports submitted within 24 hours of occurrence, Daily equipment inspections recorded and verified.

The Golden Thread: Linking Objectives Across Levels

The golden thread ensures that each objective is traceable back to the company's strategic intent:

  • Strategic Objective → Security Operations Objective → Departmental Objective → Operational Objective.
  • Example Flow:
    • Strategic: Protect company reputation by ensuring compliance with international standards.
    • SOMS: Achieve ISO 18788 certification and maintain ongoing compliance.
    • Departmental (Compliance): Audit all departments quarterly for ISO 18788 conformity.
    • Operational (Site Level): All incident reports completed within required compliance timeframe.

This golden thread provides traceability, accountability, and assurance that every operational activity contributes to the achievement of corporate strategy.

Linking Objectives to Risks and Opportunities

Clause 6.2 must be applied in conjunction with Clause 6.1 (Risks and Opportunities). Each objective must be informed by, and connected to, the organization's risk registers:

  • Strategic Risk Register - Identifies risks at the organizational level (e.g., reputational damage from non-compliance). Objectives mitigate these risks (e.g., “Achieve ISO 18788 certification within 18 months”).
  • Tactical/Departmental Risk Registers - Identify risks within divisions (e.g., insufficient training capacity). Objectives respond directly (e.g., “Expand e-learning program to cover all provinces”).
  • Operational Risk Registers - Identify risks at the frontline (e.g., equipment failure, late incident reporting). Objectives address these (e.g., “Daily operational readiness checks with supervisor sign-off”).

By linking objectives to risks and opportunities, organizations ensure that objectives are risk-driven, opportunity-focused, and measurable.

Achieving Security Operations Objectives

To ensure objectives are met, ISO 18788 requires organizations to:

  1. Make Objectives Measurable - Use Key Performance Indicators (KPIs) linked to SOMS.
  2. Integrate Objectives into Planning - Embed objectives into departmental work plans and operational procedures.
  3. Assign Accountability - Use a RACI matrix to define roles for each objective.
  4. Communicate Objectives - Ensure all staff, from executives to guards, understand their role in achieving objectives.
  5. Monitor and Evaluate - Use audits, management reviews, and dashboards to track progress.
  6. Link to Continual Improvement - Review objectives in light of risk evaluations, incidents, and lessons learned, and adjust accordingly.

Benefits of Clause 6.2 Compliance

  • Alignment - Ensures that every action at operational level is tied to strategic priorities.
  • Risk Integration - Embeds risk-based thinking into the achievement of objectives.
  • Transparency - Creates a documented chain of accountability from Board to frontline.
  • Performance Measurement - Enables progress to be tracked using KPIs.
  • Assurance to Stakeholders - Demonstrates to clients, regulators, and communities that the company is systematic and accountable.

Conclusion

Clause 6.2 of ISO 18788 is about creating alignment and coherence. Security Operations Objectives are not created in isolation but are part of a cascading framework that begins with strategic intent, filters through departments, and is executed at the operational level. This golden thread ensures that every guard, supervisor, and manager contributes directly to the company's mission and compliance commitments.

When integrated with the risk and opportunity process and linked to risk registers, these objectives become more than performance targets—they become drivers of resilience, compliance, and continual improvement in security operations.