Sentrix

ISO 27001 guide · Clause 6

6.1 — Actions to address risks and opportunities

ISO 27001:2022 sub-clause 6.1 requires assessing and treating information security risks and opportunities: how 6.1.1, 6.1.2 and 6.1.3 fit together.

By Sentrix · Published 2026-07-16

The requirement that turns your ISMS from a document exercise into a risk-driven system: identify what could go wrong, decide what to do about it, and prove both were done consistently.

In plain language

Sub-clause 6.1 requires you to identify the risks and opportunities relevant to your ISMS, then split that work into two disciplines: assessing risks (6.1.2) and treating them (6.1.3), on top of the general provisions that frame both (6.1.1).

How these requirements fit together

The three sub-clauses form a straight line. 6.1.1 sets the general expectation that risks and opportunities are addressed in a planned way, consistent with the context defined in clause 4 and the commitments made in clause 5. 6.1.2 then does the identification and analysis work: what could happen, how likely, how severe. 6.1.3 picks up those results and decides what to do about them — reduce, accept, avoid, or transfer each risk — and that decision-making produces the Statement of Applicability, the document that ties your risk work to the 93 Annex A controls. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust.

Support

Need hands-on support building your risk assessment and treatment process? See the ISO 27001 compliance service or go back to clause 6 · Planning.

Sources

Frequently asked questions

How do the three sub-clauses of 6.1 fit together?
They form a straight line. 6.1.1 sets the general expectation that risks and opportunities are addressed in a planned way, consistent with the context defined in clause 4 and the commitments made in clause 5. 6.1.2 then does the identification and analysis work: what could happen, how likely, how severe. 6.1.3 picks up those results and decides what to do about them.
What are the options for treating a risk?
For each assessed risk, 6.1.3 asks you to choose: reduce it (apply controls), accept it (knowingly, within your criteria), avoid it (remove the source of the risk) or transfer it (insurance, a supplier, a partner). That decision-making produces the Statement of Applicability, the document that ties your risk work to the 93 Annex A controls.
Can we go straight to the Statement of Applicability?
No. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust. Every control inclusion or exclusion must trace back to a risk that was identified, analyzed and evaluated with a defined method; without that traceability, the SoA is just a list of ticked boxes.

Let's talk about your compliance program.

Last updated: 2026-09-17