Operation for ISO 27001 Information Security

ISO 27001 Clause 8

This clause is the operational core of the ISMS - planning and controlling the information security activities, conducting risk assessments and implementing risk treatment.

ISO 27001 Clause 8 - Operation

Clause 8 is where the planning done under Clause 6 meets the day-to-day running of the management system. It covers how the operational processes are controlled, how risk assessments are kept current as circumstances change, and how the risk treatment plan is implemented.

Sub-clauses of ISO 27001 Clause 8

Clause 8.1 - Operational Planning and Control requires the organisation to plan, implement and control the processes needed to meet ISMS requirements and to implement the actions identified under Clause 6.1.

Clause 8.2 - Information Security Risk Assessment requires the organisation to perform information security risk assessments at planned intervals or when significant changes are proposed or occur.

Clause 8.3 - Information Security Risk Treatment requires the organisation to implement the information security risk treatment plan and to retain documented information about the results.

payment logos