ISO 27001 Requirements: Clause 6
Read about the requirements for ISO 27001 Clause 6, which covers the identification of risks and opportunities, as well as the establishment by the senior leadership of information security objectives for the ISMS and the development of a plan to implement them.

ISO 27001 Clause 6 includes the following sub-clauses:
ISO 27001 Clause 6.1 outlines the risks and responsibilities, building upon the context of the organisation and needs of interested parties provided in clauses 4.1 and 4.2, covering how to carry out an information security risk assessment.
ISO 27001 Clause 6.2 details the three ISMS security objectives, confidentiality, integrity and availability, and how to identify them and then plan to address them.
{{snapshot}}
Operational checklist in brief
- ISO 27001 Clause 6 includes the following sub-clauses: ISO 27001 Clause 6.1 ISO 27001 Clause 6.1 outlines the risks and responsibilities, building upon the context of the organisation and needs of interested parties provided in clauses 4.1 and 4.2, covering how to carry out an information security risk assessment.
- ISO 27001 Clause 6.2 ISO 27001 Clause 6.2 details the three ISMS security objectives, confidentiality, integrity and availability, and how to identify them and then plan to address them.
- ISO 27001 Clause 6 includes the following sub-clauses: ISO 27001 Clause 6.1 ISO 27001 Clause 6.1 outlines the risks
- building upon the context of the organisation
{{/snapshot}}
{{snapshot}}
Operational checklist in brief
- ISO 27001 Clause 6 includes the following sub-clauses: ISO 27001 Clause 6.1 ISO 27001 Clause 6.1 outlines the risks and responsibilities, building upon the context of the organisation and needs of interested parties provided in clauses 4.1 and 4.2, covering how to carry out an information security risk assessment.
- ISO 27001 Clause 6.2 ISO 27001 Clause 6.2 details the three ISMS security objectives, confidentiality, integrity and availability, and how to identify them and then plan to address them.
- {{snapshot}} Operational checklist in brief {{/snapshot}}
{{/snapshot}}
| Point | What it requires |
|---|---|
| Point 1 | ISO 27001 Clause 6 includes the following sub-clauses: |
| Point 2 | ISO 27001 Clause 6.1 outlines the risks and responsibilities, building upon the context of the organisation and needs of interested parties provided in clauses 4.1 and 4.2, covering how to carry out an information security risk assessment. |
| Point 3 | ISO 27001 Clause 6.2 details the three ISMS security objectives, confidentiality, integrity and availability, and how to identify them and then plan to address them. |
{{snapshot}}
In Hicomply's experience
In our experience, ISO 27001 Requirements: Clause 6 works best when it is maintained as living evidence inside the ISMS, not recreated before each audit. Keep ownership, approvals, and version history clear, then use automation to reuse the same evidence across ISO 27001 and related frameworks. See how that works in a platform tour.
{{/snapshot}}
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.




