ISO 27001 guide · Clause 8
Clause 8 — Operation
Clause 8 turns the plans from clause 6 into practice: processes run under defined criteria, changes are controlled, risk assessment and treatment are repeated.
By Sentrix · Published 2026-07-16
Requirement 8 · “Do” phase of the PDCA cycle
In plain language
The shortest of the seven certifiable clauses, and the one that turns everything else into practice. Clause 8 is where the plans from clause 6 stop being documents and start being executed: processes run under defined criteria, changes are controlled instead of improvised, external providers relevant to the ISMS are kept in check, and—critically—risk assessment and treatment happen again, on a recurring basis, not just once at certification. An auditor reading clause 8 evidence is really asking one question: is the plan from clause 6 still the plan you are actually running?
What clause 8 covers
Clause 8 is the shortest of the seven certifiable clauses—just three flat requirements, no sub-clauses. 8.1 covers running the ISMS day to day: executing processes under defined criteria, controlling both planned changes and the fallout of unplanned ones, and keeping outsourced processes relevant to the ISMS in check. 8.2 and 8.3 are the operational twins of clauses 6.1.2 and 6.1.3—the same risk assessment and treatment discipline, but repeated at planned intervals or whenever something significant changes, rather than performed once and filed away.
Why it is central
Certifications commonly fail here not because clause 6’s original risk assessment was wrong, but because it was never repeated. A risk register that is a year and a half stale at the surveillance audit—with no evidence it was revisited at planned intervals or after a significant change—is a clause 8 finding, even if the original assessment was excellent.
The documents that come out of clause 8
- Evidence that operational processes are running to their defined criteria (8.1)
- Records of controlled changes and reviewed consequences of unintended changes (8.1)
- The results of each recurring risk assessment (8.2)
- The results of each recurring risk treatment cycle (8.3)
Going further
Need hands-on support running your operational risk cycle? See our ISO 27001 certification support service or contact us. The ISO 27001 framework page summarises the standard as a whole.
Sources
Frequently asked questions
- How is 8.2 different from 6.1.2?
- 6.1.2 establishes your risk assessment methodology and criteria as part of planning. 8.2 is the operational requirement to actually run that methodology again—at planned intervals or after significant changes—using the same criteria clause 6.1.2 set, and to retain the results of each assessment as evidence.
- Why does clause 8 have no sub-clauses?
- It is one of the shorter clauses in the standard: its three requirements are direct and operational enough that the standard does not break them into further numbered sub-points, unlike clauses 6, 7, and 9. 8.1 covers day-to-day operation, 8.2 the recurring risk assessment, and 8.3 the execution of the treatment plan.
- Does 8.1 cover suppliers?
- Yes. It explicitly requires controlling externally provided processes, products, or services relevant to the ISMS, which is the anchor point for supplier and third-party risk oversight within the standard. A vendor adopted after certification with no assessment against ISMS expectations is a common pitfall.
Related pages
ISO 27001 guide · Clause 8
8.1 — Operational planning and control
Clause 8.1 requires you to run ISMS processes under defined criteria, keep evidence they ran as planned, and control changes and externally provided services.
ISO 27001 guide · Clause 8
8.2 — Information security risk assessment
Clause 8.2 requires you to repeat the risk assessment at planned intervals or when a significant change occurs, using the 6.1.2 criteria, and keep the results.
ISO 27001 guide · Clause 8
8.3 — Information security risk treatment
Clause 8.3 requires you to actually carry out the risk treatment plan produced under 6.1.3 and to retain evidence that the treatment genuinely happened.
Let's talk about your compliance program.
Last updated: 2026-09-17
