Home/ ISO 27001 clauses guide/ Clause 6 · Planning/ 6.1 Actions to address risks
Clause 6 · Planning

6.1 — Actions to address risks and opportunities

The requirement that turns your ISMS from a document exercise into a risk-driven system: identify what could go wrong, decide what to do about it, and prove both were done consistently.

Mandatory requirement

In plain language

In plain language: sub-clause 6.1 requires you to identify the risks and opportunities relevant to your ISMS, then split that work into two disciplines: assessing risks (6.1.2) and treating them (6.1.3), on top of the general provisions that frame both (6.1.1).

Position in the standard

Clause 6 · Planning
6.1 · Actions to address risks and opportunities ← you are here
See also: 6.2 · 6.3

The sub-requirements of 6.1

How these requirements fit together

The three sub-clauses form a straight line. 6.1.1 sets the general expectation that risks and opportunities are addressed in a planned way, consistent with the context defined in clause 4 and the commitments made in clause 5. 6.1.2 then does the identification and analysis work: what could happen, how likely, how severe. 6.1.3 picks up those results and decides what to do about them — reduce, accept, avoid, or transfer each risk — and that decision-making produces the Statement of Applicability, the document that ties your risk work to the 93 Annex A controls. Skipping straight to 6.1.3 without a real 6.1.2 behind it is the single most common way organizations end up with a SoA an auditor does not trust.

Need hands-on support building your risk assessment and treatment process? See our ISO 27001 certification support service

↑ Back to clause 6 · Planning

Turn risk assessment into a defensible SoA.

Sentrix structures your 6.1 workflow end to end — from risk identification to a Statement of Applicability an auditor will trust.