ISO/IEC 27003:2017 ISO27003-6.2: Information Security Objectives and Planning to Achieve Them
Guidance on setting measurable information security objectives at relevant functions and levels, and planning actions, resources, responsibilities, and timeframes.