Clause 8

Operation

Run the plan: control your processes, and actually perform risk assessment and treatment.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILClause 8 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Mandatory documents in this clause

  • Operational planning evidence (8.1)
  • Risk assessment results (8.2)
  • Risk treatment results (8.3)
8.1

Operational planning and control

What it requires: Plan, implement and control the processes needed to meet requirements and the Clause 6 actions, establish process criteria, control changes, and control externally provided processes. Keep enough documented information to have confidence processes ran as planned.

How to meet it: Document key operational procedures and keep records that they were followed.

8.2

Information security risk assessment

What it requires: Perform risk assessments at planned intervals or when significant changes occur, and retain the results.

How to meet it: Schedule risk assessments (at least annually and on major change) and store the results.

8.3

Information security risk treatment

What it requires: Implement the risk treatment plan and retain the results.

How to meet it: Track treatment actions to completion and keep evidence of implementation.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Looking for the Annex A controls? See all 93 controls. To run these requirements with automation, read how AI manages compliance.