ISO 27001 guide · Clause 6
6.1 — Actions to address risks and opportunities
ISO 27001:2022 sub-clause 6.1 requires assessing and treating information security risks and opportunities: how 6.1.1, 6.1.2 and 6.1.3 fit together.
By Sentrix · Published 2026-07-16
The requirement that turns your ISMS from a document exercise into a risk-driven system: identify what could go wrong, decide what to do about it, and prove both were done consistently.
In plain language
Sub-clause 6.1 requires you to identify the risks and opportunities relevant to your ISMS, then split that work into two disciplines: assessing risks (6.1.2) and treating them (6.1.3), on top of the general provisions that frame both (6.1.1).
How these requirements fit together
The three sub-clauses form a straight line. 6.1.1 sets the general expectation that risks and opportunities are addressed in a planned way, consistent with the context defined in clause 4 and the commitments made in clause 5. 6.1.2 then does the identification and analysis work: what could happen, how likely, how severe. 6.1.3 picks up those results and decides what to do about them — reduce, accept, avoid, or transfer each risk — and that decision-making produces the Statement of Applicability, the document that ties your risk work to the 93 Annex A controls. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust.
Support
Need hands-on support building your risk assessment and treatment process? See the ISO 27001 compliance service or go back to clause 6 · Planning.
Sources
Frequently asked questions
- How do the three sub-clauses of 6.1 fit together?
- They form a straight line. 6.1.1 sets the general expectation that risks and opportunities are addressed in a planned way, consistent with the context defined in clause 4 and the commitments made in clause 5. 6.1.2 then does the identification and analysis work: what could happen, how likely, how severe. 6.1.3 picks up those results and decides what to do about them.
- What are the options for treating a risk?
- For each assessed risk, 6.1.3 asks you to choose: reduce it (apply controls), accept it (knowingly, within your criteria), avoid it (remove the source of the risk) or transfer it (insurance, a supplier, a partner). That decision-making produces the Statement of Applicability, the document that ties your risk work to the 93 Annex A controls.
- Can we go straight to the Statement of Applicability?
- No. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust. Every control inclusion or exclusion must trace back to a risk that was identified, analyzed and evaluated with a defined method; without that traceability, the SoA is just a list of ticked boxes.
Related pages
ISO 27001 guide · Clause 6
6.1.1 — General
ISO 27001:2022 sub-clause 6.1.1 sets the general provisions for how risks and opportunities are addressed: the frame that 6.1.2 and 6.1.3 operate inside.
ISO 27001 guide · Clause 6
6.1.2 — Information security risk assessment
ISO 27001:2022 sub-clause 6.1.2 requires a consistent, repeatable risk assessment process: what it expects, and the evidence auditors will ask to see.
ISO 27001 guide · Clause 6
6.1.3 — Information security risk treatment
ISO 27001:2022 sub-clause 6.1.3 requires a risk treatment process, a risk treatment plan and the Statement of Applicability, plus the supporting evidence.
Let's talk about your compliance program.
Last updated: 2026-09-17
