ISO 27001 guide · Clause 8
8.1 — Operational planning and control
Clause 8.1 requires you to run ISMS processes under defined criteria, keep evidence they ran as planned, and control changes and externally provided services.
By Sentrix · Published 2026-07-16
The requirement that keeps day-to-day operations aligned with what clause 6 decided, instead of quietly drifting from it.
Mandatory requirement · Documented information required: yes
In plain language
8.1 requires you to run the processes needed to meet your ISMS requirements and the risk treatment actions from clause 6 under defined criteria, keep enough evidence to show they ran as planned, control changes to those processes on purpose rather than by accident, and make sure any externally provided process, product, or service relevant to the ISMS is kept under control too.
Why this requirement exists
A risk treatment plan is only as good as its execution. This requirement exists because operational reality drifts from documented intent constantly—a process gets tweaked to save time, a vendor changes how they deliver a service, an emergency fix skips the usual review—and without deliberate control, those small drifts accumulate into a gap between what the ISMS says happens and what actually happens.
Scenario: a company outsources its backup infrastructure to a third party after certification, without ever assessing whether that provider meets the same security expectations as the in-house process it replaced. The service works fine technically, but nobody controlled the change, and nobody verified the vendor against the ISMS’s requirements. That gap surfaces exactly when an auditor asks who reviewed the switch.
What the standard expects
The standard expects the organization to plan, implement, and control the processes needed to meet requirements and to implement the actions determined in clause 6, by establishing criteria for the processes and implementing control of the processes in accordance with those criteria. Documented information must be available to the extent necessary to have confidence the processes were carried out as planned. The organization must control planned changes and review the consequences of unintended changes, taking action to mitigate adverse effects as necessary, and must ensure that externally provided processes, products, or services relevant to the ISMS are controlled.
In practice
- Define clear criteria for security-relevant processes (patching cadence, access review frequency, backup testing) so "running as planned" is verifiable, not subjective.
- Route changes to ISMS-relevant processes through a change control step, however lightweight, rather than letting them happen ad hoc.
- Assess new or changed external providers (cloud services, managed service providers, outsourced processes) against the same security expectations the ISMS already sets internally.
Evidence the auditor will ask for
- Documented criteria for key operational processes and evidence they are actually met.
- Change records showing planned changes were reviewed, and unintended changes were assessed for consequences.
- Evidence that externally provided processes or services relevant to the ISMS were assessed and are monitored.
Common pitfalls
- New vendors or outsourced services adopted after certification with no assessment against ISMS expectations.
- Emergency changes that bypass review entirely, with no after-the-fact assessment of their consequences.
Related requirements
- 8.2 Risk assessment (operational)—a significant unplanned change is one of the triggers for re-running risk assessment.
- 6.3 Planning of changes—sets the planning discipline that 8.1 requires you to actually apply operationally.
- Parent clause: Clause 8 Operation.
Sources
Frequently asked questions
- Does every process need documented criteria?
- Focus on processes that materially affect information security—patching, access management, backups, vendor onboarding—rather than every operational task in the organization. For those, clear criteria (patching cadence, access review frequency, backup testing) make "running as planned" verifiable rather than subjective, and evidence that they are met is what the auditor will ask for.
- What happens with an emergency change?
- The standard requires you to control planned changes and review the consequences of unintended changes, taking action to mitigate adverse effects as necessary. An emergency fix that bypasses review entirely, with no after-the-fact assessment of its consequences, is one of the most common pitfalls; a change control step, however lightweight, is usually enough.
- How should a new vendor be handled after certification?
- Assess it against the same security expectations the ISMS already sets internally before handing it an ISMS-relevant process, then monitor it. The auditor will ask for evidence that externally provided processes or services were assessed and are monitored; a vendor adopted without that assessment surfaces exactly when someone asks who reviewed the switch.
Related pages
ISO 27001 guide · Clause 8
Clause 8 — Operation
Clause 8 turns the plans from clause 6 into practice: processes run under defined criteria, changes are controlled, risk assessment and treatment are repeated.
ISO 27001 guide · Clause 8
8.2 — Information security risk assessment
Clause 8.2 requires you to repeat the risk assessment at planned intervals or when a significant change occurs, using the 6.1.2 criteria, and keep the results.
ISO 27001 guide · Clause 6
6.3 — Planning of changes
ISO 27001:2022 added sub-clause 6.3: changes to the ISMS must be carried out in a planned manner. What that means in practice, and what auditors look for.
Let's talk about your compliance program.
Last updated: 2026-09-17
