ISO 27001 guide · Clause 6
6.1.1 — General
ISO 27001:2022 sub-clause 6.1.1 sets the general provisions for how risks and opportunities are addressed: the frame that 6.1.2 and 6.1.3 operate inside.
By Sentrix · Published 2026-07-16
The frame that 6.1.2 and 6.1.3 operate inside: risk and opportunity planning has to be deliberate, consistent with your context, and integrated into the rest of the ISMS.
In plain language
When you plan your ISMS, you must account for the risks and opportunities identified from your context (clause 4) and leadership commitments (clause 5), and make sure that planning connects cleanly to the risk assessment and treatment work that follows.
Why this requirement exists
Without this general framing, organizations tend to treat risk assessment as an isolated exercise disconnected from the rest of the ISMS — a spreadsheet built once, filed away, and never reconciled with the context or objectives that were supposed to drive it.
Scenario: a company defines its ISMS scope (clause 4.3) around its cloud product, then runs a risk assessment that also covers an unrelated legacy internal tool nobody flagged as in scope. The assessment is technically thorough, but it does not map to the ISMS boundary — an auditor will ask why, and the mismatch undermines confidence in the whole risk file.
What the standard expects
When planning for the ISMS, the standard expects you to consider the issues and requirements identified under clause 4 and to plan actions that address relevant risks and opportunities, how those actions will be integrated into ISMS processes, and how their effectiveness will be evaluated. In practice, this is the requirement that keeps 6.1.2 and 6.1.3 anchored to the rest of the system rather than floating free of it.
In practice
- Make sure your risk assessment scope (6.1.2) matches your ISMS scope (4.3) exactly — same systems, same sites, same services.
- Reference the interested parties and issues from clause 4 explicitly when you set risk criteria, rather than starting from a generic checklist.
- Decide upfront how you will measure whether your risk treatment actions actually worked — this feeds directly into clause 9.
Evidence the auditor will ask for
- A documented link between the ISMS scope (4.3) and the risk assessment scope (6.1.2).
- Evidence that risk criteria account for the interested parties and issues identified in clause 4.
Common pitfalls
- Running risk assessment as a standalone project with no traceable link to clause 4 or clause 5.
- A risk assessment scope that silently drifts from the declared ISMS scope over time.
Related requirements
- 6.1.2 Risk assessment — the identification and analysis work this general provision frames.
- 6.1.3 Risk treatment — what happens once risks have been assessed.
- 4.3 ISMS scope — the boundary your risk assessment scope has to match exactly.
- Parent clause: 6.1 Actions to address risks and opportunities
Sources
Frequently asked questions
- Does 6.1.1 require its own separate document?
- No. It is a framing requirement usually satisfied within your risk methodology and ISMS scope documents, by showing they are consistent with clauses 4 and 5. The auditor will look for a documented link between the ISMS scope (4.3) and the risk assessment scope (6.1.2), and for risk criteria that account for the interested parties and issues identified in clause 4.
- What happens if the risk assessment scope differs from the ISMS scope?
- The auditor will ask why, and the mismatch undermines confidence in the whole risk file — even if the assessment is technically thorough. Your risk assessment scope (6.1.2) must match your ISMS scope (4.3) exactly: same systems, same sites, same services. A risk assessment scope that silently drifts from the declared ISMS scope over time is a common pitfall.
- What does the standard ask for when planning the ISMS?
- To consider the issues and requirements identified under clause 4 and to plan actions that address relevant risks and opportunities, how those actions will be integrated into ISMS processes, and how their effectiveness will be evaluated. Deciding upfront how you will measure whether your risk treatment actions actually worked feeds directly into clause 9.
Related pages
ISO 27001 guide · Clause 6
6.1 — Actions to address risks and opportunities
ISO 27001:2022 sub-clause 6.1 requires assessing and treating information security risks and opportunities: how 6.1.1, 6.1.2 and 6.1.3 fit together.
ISO 27001 guide · Clause 6
6.1.2 — Information security risk assessment
ISO 27001:2022 sub-clause 6.1.2 requires a consistent, repeatable risk assessment process: what it expects, and the evidence auditors will ask to see.
ISO 27001 guide · Clause 6
6.1.3 — Information security risk treatment
ISO 27001:2022 sub-clause 6.1.3 requires a risk treatment process, a risk treatment plan and the Statement of Applicability, plus the supporting evidence.
ISO 27001 guide · Clause 4
4.3 — Determining the scope of the ISMS
ISO 27001:2022 sub-clause 4.3 requires determining the boundaries and applicability of the ISMS to establish its scope, plus the evidence auditors request.
Let's talk about your compliance program.
Last updated: 2026-09-17
