6.1.1 — General
The frame that 6.1.2 and 6.1.3 operate inside: risk and opportunity planning has to be deliberate, consistent with your context, and integrated into the rest of the ISMS.
In plain language
In plain language: when you plan your ISMS, you must account for the risks and opportunities identified from your context (clause 4) and leadership commitments (clause 5), and make sure that planning connects cleanly to the risk assessment and treatment work that follows.
Position in the standard
Why this requirement exists
Without this general framing, organizations tend to treat risk assessment as an isolated exercise disconnected from the rest of the ISMS — a spreadsheet built once, filed away, and never reconciled with the context or objectives that were supposed to drive it.
Scenario: a company defines its ISMS scope (clause 4.3) around its cloud product, then runs a risk assessment that also covers an unrelated legacy internal tool nobody flagged as in scope. The assessment is technically thorough, but it does not map to the ISMS boundary — an auditor will ask why, and the mismatch undermines confidence in the whole risk file.
What the standard expects
When planning for the ISMS, the standard expects you to consider the issues and requirements identified under clause 4 and to plan actions that address relevant risks and opportunities, how those actions will be integrated into ISMS processes, and how their effectiveness will be evaluated. In practice, this is the requirement that keeps 6.1.2 and 6.1.3 anchored to the rest of the system rather than floating free of it.
In practice
- Make sure your risk assessment scope (6.1.2) matches your ISMS scope (4.3) exactly — same systems, same sites, same services.
- Reference the interested parties and issues from clause 4 explicitly when you set risk criteria, rather than starting from a generic checklist.
- Decide upfront how you will measure whether your risk treatment actions actually worked — this feeds directly into clause 9.
Evidence the auditor will ask for
- A documented link between the ISMS scope (4.3) and the risk assessment scope (6.1.2).
- Evidence that risk criteria account for the interested parties and issues identified in clause 4.
Common pitfalls
- Running risk assessment as a standalone project with no traceable link to clause 4 or clause 5.
- A risk assessment scope that silently drifts from the declared ISMS scope over time.
Related requirements
6.1.2 Risk assessment
The identification and analysis work this general provision frames.
6.1.3 Risk treatment
What happens once risks have been assessed.
4.3 ISMS scope
The boundary your risk assessment scope has to match exactly.
Parent link: 6.1 Actions to address risks and opportunities
Frequently asked questions
Does 6.1.1 require its own separate document?
Align your risk work with your ISMS scope.
Sentrix keeps your ISMS scope, risk criteria, and treatment plan connected — so nothing drifts apart between audits.