Sentrix

ISO 27001 guide · Plan

Clause 6 — Planning

ISO 27001:2022 clause 6 covers risk assessment and treatment, the Statement of Applicability (SoA) and measurable security objectives, explained in plain terms.

By Sentrix · Published 2026-07-16

The heart of the ISMS: this is where you turn your risks into a defensible action plan. Clause 6 is often considered the most decisive clause of the standard. It requires you to assess your information security risks, decide how to treat them, produce the Statement of Applicability (SoA) — the centerpiece of any ISO 27001 file — and set measurable security objectives. The 2022 version added a requirement on planning changes (6.3). Done well, this clause gives your entire system a backbone; done poorly, it derails the audit.

What clause 6 covers

Clause 6 answers three connected questions. First: what risks threaten the confidentiality, integrity, and availability of your information, and which ones come first (6.1.1 and 6.1.2)? Next: what do you decide to do about those risks, which measures do you retain and why — that is the role of risk treatment and the SoA (6.1.3)? Finally: what concrete security objectives do you set, and how do you plan changes to your ISMS (6.2 and 6.3)? It is the passage from “why” to “what to do.”

Why it is central

The SoA (produced under 6.1.3) is the document an auditor opens first: it connects your risks to the 93 Annex A controls, justifying every inclusion or exclusion. It is the bridge between the clauses (the ISMS) and Annex A (the measures). Without a solid clause 6, the rest of the system rests on nothing. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust.

The documents that come out of clause 6

  • The risk assessment process (6.1.2)
  • The risk treatment process (6.1.3)
  • The Statement of Applicability — SoA (6.1.3)
  • The information security objectives (6.2)

Support

Need hands-on support structuring your risk management and Statement of Applicability? See the ISO 27001 compliance service or go back to the 7-clause guide.

Sources

Frequently asked questions

What is the difference between 6.1.2 and 6.1.3?
6.1.2 (assessment) identifies and evaluates risks: what could happen and how severe it would be, against defined criteria and with a repeatable method. 6.1.3 (treatment) decides what to do about it: reduce, accept, avoid, or transfer, then selects the necessary controls — that is where the Statement of Applicability and the risk treatment plan come in.
What is the Statement of Applicability (SoA)?
It is the document that lists the 93 Annex A controls and, for each one, states whether it is retained or not, the justification for that choice, and its implementation status. It is required by clause 6.1.3 and is the centerpiece of the audit: it connects your risks to the measures you retained and bridges the clauses and Annex A.
What did the 2022 version add to clause 6?
Sub-clause 6.3, Planning of changes, which requires ISMS changes — a new system, a restructured team, a new supplier, a revised risk treatment — to be carried out in a planned way rather than improvised. It has no direct 2013 equivalent and targets unplanned changes, which is exactly where ISMS gaps quietly appear.

Let's talk about your compliance program.

Last updated: 2026-09-17