ISO 27001 Requirements: Clause 8
Learn about the requirements for ISO 27001 Clause 8, which covers operational planning and control, as well as risk assessment and risk treatment, as laid out in clause 6.1.3.

Clause 8 consists of the following sub-clauses:
{{snapshot}}
Clause 8 in brief
- Clause 8 consists of sub-clauses 8.1, 8.2, and 8.3.
- Clause 8.1 covers operational planning and control.
- Clause 8.2 concerns risk assessment as an ongoing part of the ISMS process.
- Clause 8.3 reiterates information security risk treatment and documented results.
{{/snapshot}}
| Sub-clause | Focus stated in the article |
|---|---|
| 8.1 | Operational planning and control, implementing actions determined in clause 6. |
| 8.2 | Risk assessment as an ongoing part of the ISMS process. |
| 8.3 | Information security risk treatment and documented risk treatment process results. |
Clause 8.1 covers operational planning and control, implementing actions previously determined in clause 6. If organisations have already attained clauses 6.1, 6.2 and 7.5, then clause 8.1 should be automatically covered.
Clause 8.2 concerns risk assessment, which should be an ongoing part of the ISMS process. Like its predecessor, this clause should already be complete if a previous clause, this time 6.1.2, has already been attained.
Clause 8.3 reiterates the information security risk treatment covered by clause 6.1.3, as well as stating the need for documenting all risk treatment process results.
{{snapshot}}
What Hicomply recommends
Hicomply recommends managing Clause 8 as a connected operating cycle: plan the work, assess risk, treat risk, and preserve the results as evidence. Connect these activities to the wider ISO 27001 programme through the ISO 27001 hub so each sub-clause supports the next.
{{/snapshot}}
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.


.avif)




















