Clause 8 — Operation
The shortest of the seven certifiable clauses, and the one that turns everything else into practice. Clause 8 is where the plans from clause 6 stop being documents and start being executed: processes run under defined criteria, changes are controlled instead of improvised, external providers relevant to the ISMS are kept in check, and — critically — risk assessment and treatment happen again, on a recurring basis, not just once at certification. An auditor reading clause 8 evidence is really asking one question: is the plan from clause 6 still the plan you are actually running?
The structure of clause 8
8.1 · Operational planning and control
8.2 · Information security risk assessment
8.3 · Information security risk treatment
What clause 8 covers
Clause 8 is the shortest of the seven certifiable clauses — just three flat requirements, no sub-clauses. 8.1 covers running the ISMS day to day: executing processes under defined criteria, controlling both planned changes and the fallout of unplanned ones, and keeping outsourced processes relevant to the ISMS in check. 8.2 and 8.3 are the operational twins of clause 6.1.2 and 6.1.3 — the same risk assessment and treatment discipline, but repeated at planned intervals or whenever something significant changes, rather than performed once and filed away.
Why it is central
Certifications commonly fail here not because clause 6’s original risk assessment was wrong, but because it was never repeated. A risk register that is a year and a half stale at the surveillance audit — with no evidence it was revisited at planned intervals or after a significant change — is a clause 8 finding, even if the original assessment was excellent.
The documents that come out of clause 8
- Evidence that operational processes are running to their defined criteria (8.1)
- Records of controlled changes and reviewed consequences of unintended changes (8.1)
- The results of each recurring risk assessment (8.2)
- The results of each recurring risk treatment cycle (8.3)
Frequently asked questions
How is 8.2 different from 6.1.2?
Why does clause 8 have no sub-clauses?
Does 8.1 cover suppliers?
Need hands-on support running your operational risk cycle? See our ISO 27001 certification support service
Keep your risk assessment as current as the day you were certified.
Sentrix reruns your risk assessment on a schedule and flags when a significant change means it is due early.