Operation
Run the plan: control your processes, and actually perform risk assessment and treatment.
Mandatory documents in this clause
- ✓Operational planning evidence (8.1)
- ✓Risk assessment results (8.2)
- ✓Risk treatment results (8.3)
Operational planning and control
What it requires: Plan, implement and control the processes needed to meet requirements and the Clause 6 actions, establish process criteria, control changes, and control externally provided processes. Keep enough documented information to have confidence processes ran as planned.
How to meet it: Document key operational procedures and keep records that they were followed.
Information security risk assessment
What it requires: Perform risk assessments at planned intervals or when significant changes occur, and retain the results.
How to meet it: Schedule risk assessments (at least annually and on major change) and store the results.
Information security risk treatment
What it requires: Implement the risk treatment plan and retain the results.
How to meet it: Track treatment actions to completion and keep evidence of implementation.
ISO 27001 policy templates
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.