Add a dedicated module to define, measure, and report on information security objectives as required by ISO 27001:2022 Clause 6.2. Today, most ISMS teams track this in Excel, which makes management reviews, internal audits, and trend analysis painful.
The register should let users:
Create objectives grouped by domain (Governance, Awareness & Training, Incident Management, Compliance, Supplier Management, Vulnerability Management, etc.), each linked to the relevant policy, Annex A control(s), and risk(s).
Define one or more KPIs per objective, with: data source, measurement frequency (monthly / quarterly / annually), numerator, denominator, target threshold (norm %), and reporting evidence.
Auto-compute the compliance status (Compliant / Non-Compliant) from the KPI value vs. the defined threshold, per reporting period.
Capture ownership (responsible team or individual) and review cycle.
For any Non-Compliant result, trigger a non-conformity workflow: root cause, corrective/preventive action plan, due date, follow-up, and closure evidence.
Maintain historical results to show trend over time, and feed the Management Review (Clause 9.3) and Internal Audit (Clause 9.2) modules automatically.
Export an audit-ready report (Excel / PDF) with version control and approval history matching 6clicks' existing document standards.
Business value: replaces spreadsheet-based registers, produces auditor-ready evidence for Clauses 6.2, 9.1, 9.2, and 9.3 in one click, and reduces management review prep time significantly for MSPs and internal ISMS teams managing multiple ISO 27001 certifications.