Clause 6 — Planning
The heart of the ISMS: this is where you turn your risks into a defensible action plan. Clause 6 is often considered the most decisive clause of the standard. It requires you to assess your information security risks, decide how to treat them, produce the Statement of Applicability (SoA) — the centerpiece of any ISO 27001 file — and set measurable security objectives. The 2022 version added a requirement on planning changes (6.3). Done well, this clause gives your entire system a backbone; done poorly, it derails the audit.
The structure of clause 6
6.2 · Information security objectives and planning to achieve them
6.3 · Planning of changes
What clause 6 covers
Clause 6 answers three connected questions. First: what risks threaten the confidentiality, integrity, and availability of your information, and which ones come first (6.1.1 and 6.1.2)? Next: what do you decide to do about those risks, which measures do you retain and why — that is the role of risk treatment and the SoA (6.1.3)? Finally: what concrete security objectives do you set, and how do you plan changes to your ISMS (6.2 and 6.3)? It is the passage from “why” to “what to do.”
Why it is central
The SoA (produced under 6.1.3) is the document an auditor opens first: it connects your risks to the 93 Annex A controls, justifying every inclusion or exclusion. It is the bridge between the clauses (the ISMS) and Annex A (the measures). Without a solid clause 6, the rest of the system rests on nothing.
The documents that come out of clause 6
- The risk assessment process (6.1.2)
- The risk treatment process (6.1.3)
- The Statement of Applicability — SoA (6.1.3)
- The information security objectives (6.2)
Frequently asked questions
What is the difference between 6.1.2 and 6.1.3?
What is the Statement of Applicability (SoA)?
What did the 2022 version add to clause 6?
Need hands-on support structuring your risk management and Statement of Applicability? See our ISO 27001 certification support service
Structure your risk management and your SoA.
Sentrix helps you turn clause 6 into a defensible risk register, treatment plan, and Statement of Applicability — ready for the certification audit.