6.1 — Actions to address risks and opportunities
The requirement that turns your ISMS from a document exercise into a risk-driven system: identify what could go wrong, decide what to do about it, and prove both were done consistently.
In plain language
In plain language: sub-clause 6.1 requires you to identify the risks and opportunities relevant to your ISMS, then split that work into two disciplines: assessing risks (6.1.2) and treating them (6.1.3), on top of the general provisions that frame both (6.1.1).
Position in the standard
The sub-requirements of 6.1
6.1.1 General
The general provisions that frame how the ISMS approaches risks and opportunities, and how the outputs feed the rest of clause 6.
6.1.2 Risk assessment
A consistent, repeatable method to identify, analyze, and evaluate information security risks.
6.1.3 Risk treatment
Deciding what to do about each assessed risk, selecting controls, and producing the Statement of Applicability.
How these requirements fit together
The three sub-clauses form a straight line. 6.1.1 sets the general expectation that risks and opportunities are addressed in a planned way, consistent with the context defined in clause 4 and the commitments made in clause 5. 6.1.2 then does the identification and analysis work: what could happen, how likely, how severe. 6.1.3 picks up those results and decides what to do about them — reduce, accept, avoid, or transfer each risk — and that decision-making produces the Statement of Applicability, the document that ties your risk work to the 93 Annex A controls. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust.
Need hands-on support building your risk assessment and treatment process? See our ISO 27001 certification support service
Turn risk assessment into a defensible SoA.
Sentrix structures your 6.1 workflow end to end — from risk identification to a Statement of Applicability an auditor will trust.