Home/ ISO 27001 clauses guide/ Clause 8 · Operation
Requirement 8 · “Do” phase of the PDCA cycle

Clause 8 — Operation

The shortest of the seven certifiable clauses, and the one that turns everything else into practice. Clause 8 is where the plans from clause 6 stop being documents and start being executed: processes run under defined criteria, changes are controlled instead of improvised, external providers relevant to the ISMS are kept in check, and — critically — risk assessment and treatment happen again, on a recurring basis, not just once at certification. An auditor reading clause 8 evidence is really asking one question: is the plan from clause 6 still the plan you are actually running?

The structure of clause 8

What clause 8 covers

Clause 8 is the shortest of the seven certifiable clauses — just three flat requirements, no sub-clauses. 8.1 covers running the ISMS day to day: executing processes under defined criteria, controlling both planned changes and the fallout of unplanned ones, and keeping outsourced processes relevant to the ISMS in check. 8.2 and 8.3 are the operational twins of clause 6.1.2 and 6.1.3 — the same risk assessment and treatment discipline, but repeated at planned intervals or whenever something significant changes, rather than performed once and filed away.

Why it is central

Certifications commonly fail here not because clause 6’s original risk assessment was wrong, but because it was never repeated. A risk register that is a year and a half stale at the surveillance audit — with no evidence it was revisited at planned intervals or after a significant change — is a clause 8 finding, even if the original assessment was excellent.

The documents that come out of clause 8

  • Evidence that operational processes are running to their defined criteria (8.1)
  • Records of controlled changes and reviewed consequences of unintended changes (8.1)
  • The results of each recurring risk assessment (8.2)
  • The results of each recurring risk treatment cycle (8.3)

Frequently asked questions

How is 8.2 different from 6.1.2?
6.1.2 establishes your risk assessment methodology and criteria as part of planning. 8.2 is the operational requirement to actually run that methodology again — at planned intervals or after significant changes — using the same criteria clause 6.1.2 set.
Why does clause 8 have no sub-clauses?
It is one of the shorter clauses in the standard — its three requirements are direct and operational enough that the standard does not break them into further numbered sub-points, unlike clauses 6, 7, and 9.
Does 8.1 cover suppliers?
Yes — it explicitly requires controlling externally provided processes, products, or services relevant to the ISMS, which is the anchor point for supplier and third-party risk oversight within the standard.

Need hands-on support running your operational risk cycle? See our ISO 27001 certification support service

↑ Back to the 7-clause guide

Keep your risk assessment as current as the day you were certified.

Sentrix reruns your risk assessment on a schedule and flags when a significant change means it is due early.