“When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.”ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, clauza 6.3 «Planning of changes» — clauză nouă în ediția din 2022
An objective that cannot be measured is an intention on letterhead.
Clause 6.2 asks for objectives that can be checked: consistent with the policy, measurable if practicable, taking account of applicable requirements and of the results of risk assessment and treatment, monitored, communicated, updated and available as documented information. Their planning answers five questions on top of that: what will be done, with what resources, who is responsible, when it will be completed and how the results will be evaluated. "Raise the level of security" does not survive that filter. Clause 6.3 is new in the 2022 edition and is a single sentence, but it is auditable: a change to the system — a new site, a new cloud provider, a reorganization — carried out in a rush becomes a finding. Clause 7 supplies the rest: resources (7.1), competence determined, ensured and evidenced with the effectiveness of actions evaluated (7.2), awareness of the policy, of one's own contribution and of the consequences of not conforming (7.3), planned communication (7.4) and control of documented information (7.5).
Why it matters Most minor nonconformities at a first audit sit in clause 7: competence and awareness evidence that was never retained.