Clause 6

Planning

The risk-based core: address risks and opportunities, run risk assessment and treatment, set objectives, and plan changes.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILClause 6 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Mandatory documents in this clause

  • Risk assessment process (6.1.2)
  • Statement of Applicability (6.1.3)
  • Risk treatment plan (6.1.3)
  • Information security objectives (6.2)
6.1.1

Actions to address risks and opportunities (general)

What it requires: Considering your context and interested parties, determine the risks and opportunities to be addressed so the ISMS can achieve its outcomes, prevent undesired effects, and improve. Plan actions and how to integrate and evaluate them.

How to meet it: Document how risks/opportunities feed your planning, then integrate the actions into normal work.

6.1.2

Information security risk assessment

What it requires: Define and apply a risk assessment process with risk acceptance and assessment criteria, that is repeatable and consistent, identifies risks to confidentiality/integrity/availability and their owners, and analyses, evaluates and prioritises them. Retain documented information about the process.

How to meet it: Adopt a consistent methodology and record it; maintain a risk register with owners and scores.

6.1.3

Information security risk treatment

What it requires: Define a risk treatment process: select treatment options, determine the necessary controls, compare them against Annex A to confirm none are missed, produce a Statement of Applicability (controls applied, justification, implementation status, and exclusion justifications), formulate a risk treatment plan, and obtain risk owners’ approval and acceptance of residual risk.

How to meet it: Build the SoA and risk treatment plan from your risk register; have risk owners sign off the residual risk.

6.2

Information security objectives and planning

What it requires: Set measurable information security objectives at relevant functions and levels, consistent with the policy, monitored, communicated, updated, and documented. Plan what will be done, the resources, who is responsible, when, and how results are evaluated.

How to meet it: A handful of measurable objectives with owners, targets, and review dates.

6.3

Planning of changes

What it requires: When changes to the ISMS are needed, carry them out in a planned manner.

How to meet it: Run ISMS changes through change control rather than ad hoc.

ISO 27001 policy templates

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map
Looking for the Annex A controls? See all 93 controls. To run these requirements with automation, read how AI manages compliance.