Home/ ISO 27001 clauses guide/ Clause 6 · Planning
Requirement 6 · “Plan” phase of the PDCA cycle

Clause 6 — Planning

The heart of the ISMS: this is where you turn your risks into a defensible action plan. Clause 6 is often considered the most decisive clause of the standard. It requires you to assess your information security risks, decide how to treat them, produce the Statement of Applicability (SoA) — the centerpiece of any ISO 27001 file — and set measurable security objectives. The 2022 version added a requirement on planning changes (6.3). Done well, this clause gives your entire system a backbone; done poorly, it derails the audit.

The structure of clause 6

What clause 6 covers

Clause 6 answers three connected questions. First: what risks threaten the confidentiality, integrity, and availability of your information, and which ones come first (6.1.1 and 6.1.2)? Next: what do you decide to do about those risks, which measures do you retain and why — that is the role of risk treatment and the SoA (6.1.3)? Finally: what concrete security objectives do you set, and how do you plan changes to your ISMS (6.2 and 6.3)? It is the passage from “why” to “what to do.”

Why it is central

The SoA (produced under 6.1.3) is the document an auditor opens first: it connects your risks to the 93 Annex A controls, justifying every inclusion or exclusion. It is the bridge between the clauses (the ISMS) and Annex A (the measures). Without a solid clause 6, the rest of the system rests on nothing.

The documents that come out of clause 6

  • The risk assessment process (6.1.2)
  • The risk treatment process (6.1.3)
  • The Statement of Applicability — SoA (6.1.3)
  • The information security objectives (6.2)

Frequently asked questions

What is the difference between 6.1.2 and 6.1.3?
6.1.2 (assessment) identifies and evaluates risks: what could happen and how severe it would be. 6.1.3 (treatment) decides what to do about it: reduce, accept, avoid, or transfer, then selects controls — that is where the SoA comes in.
What is the Statement of Applicability (SoA)?
It is the document that lists the 93 Annex A controls and, for each one, states whether it is retained or not, the justification, and its implementation status. It is required by clause 6.1.3 and is the centerpiece of the audit.
What did the 2022 version add to clause 6?
Sub-clause 6.3, “Planning of changes,” which requires ISMS changes to be carried out in a planned way rather than improvised.

Need hands-on support structuring your risk management and Statement of Applicability? See our ISO 27001 certification support service

↑ Back to the 7-clause guide

Structure your risk management and your SoA.

Sentrix helps you turn clause 6 into a defensible risk register, treatment plan, and Statement of Applicability — ready for the certification audit.