6.3 Clause 6: Planning

Key Takeaways

  • Clause 6 turns leadership intent (Clause 5) into a concrete plan: it addresses risks/opportunities and sets objectives
  • 6.1.2 requires a formal information security risk assessment process with defined criteria (impact, likelihood, acceptance) — this is the bridge to the dedicated risk-management chapter
  • 6.1.3 requires a risk treatment process that produces a Statement of Applicability (SoA) — explicitly required at 6.1.3 d) — and a risk treatment plan
  • 6.2 requires information security objectives to be SMART: specific, measurable, monitored, communicated, and updated, and consistent with the policy
  • The SoA must include justification for control inclusion/exclusion and the status of implementation — a high-yield exam topic
Last updated: July 2026

Clause 6 is where the ISMS becomes a plan. After Clause 4 establishes context and Clause 5 commits leadership, Clause 6 requires the organization to plan actions that address risks and opportunities (6.1) and to set measurable information security objectives (6.2). This is the Plan stage of PDCA in its purest form, and it is the bridge from the main clauses to the risk-management chapter you have already studied.

6.1 Actions to Address Risks and Opportunities

6.1.1 General

When planning for the ISMS, the organization must consider the issues (4.1) and requirements (4.2) referred to above, and determine the risks and opportunities that need to be addressed to:

  1. Give assurance that the ISMS can achieve its intended outcomes
  2. Prevent, or reduce, undesired effects
  3. Achieve continual improvement

The organization must then plan actions to address those risks and opportunities, including how to integrate and implement them into the ISMS processes and how to evaluate the effectiveness of those actions.

Risk vs. Opportunity

ConceptWhat it AddressesExample
RiskUndesired effects on information securityData breach, regulatory fine, system outage
OpportunityFavorable effects that can be exploitedNew secure-by-design product line, automation that reduces human error

Both must be addressed — the exam sometimes assumes Clause 6.1 is only about risk; that is a trap.


6.1.2 Information Security Risk Assessment

The organization must define and apply an information security risk assessment process that:

  1. Establishes and applies information security risk criteria including: risk acceptance criteria, criteria for performing risk assessments, and criteria for the evaluation of risks
  2. Ensures that consistent, valid, and comparable risk assessment results are produced
  3. Ensures the risk assessment identifies risks, analyses them, and evaluates them
  4. Keeps the risk assessment results as documented information

The Three Phases of Risk Assessment

PhaseWhat Happens
IdentificationIdentify risks associated with the loss of confidentiality, integrity, and availability of information, asset owners, threat sources, vulnerabilities, and impacts
AnalysisEstimate consequences (impact) and likelihood; combine to produce a risk level
EvaluationCompare the risk level against risk acceptance criteria to decide whether the risk is acceptable or needs treatment

Risk Acceptance Criteria

Risk acceptance criteria define the threshold above which a risk must be treated. They are set before the assessment is performed, often by top management or a risk owner, and they must be documented. A common trap is to claim criteria are set after the assessment so they can be tuned to the results — that defeats the purpose and is not allowed.

Connection to the Risk-Management Chapter

Clause 6.1.2 is the authoritative hook for everything in the dedicated risk-management chapter: threat catalogs, vulnerability identification, impact/likelihood scoring, risk registers, and the difference between qualitative and quantitative methods. The Foundation exam assumes you understand that 6.1.2 is the standard-side anchor of those techniques.


6.1.3 Information Security Risk Treatment

Once the risk assessment identifies risks that need treatment, the organization must implement a risk treatment process that:

  1. Selects appropriate risk treatment options — the four classic options are:
    • Avoid — eliminate the risk by changing the activity
    • Modify (reduce/mitigate) — apply controls to lower likelihood or impact
    • Share (transfer) — outsource or insure (note: insurance does not transfer the underlying information risk, only the financial impact)
    • Retain (accept) — consciously accept the risk after analysis
  2. Determines all necessary controls from Annex A and, if required, additional controls, comparing them against those in the 2013 version if a transition is in progress
  3. Compares the controls determined in step b) with those in Annex A and verifies that no necessary control has been omitted
  4. Produces a Statement of Applicability (SoA) that contains:
    • The necessary controls (Annex A and any additional) and their justifications
    • Controls that are included and their justification for inclusion
    • Controls that are excluded and their justification for exclusion
    • The status of implementation of each included control
  5. Produces a risk treatment plan and obtains risk owners' approval of the plan and the residual risks

The SoA at 6.1.3 d) — High-Yield Topic

The Statement of Applicability is the single most tested artifact of Clause 6. The exam expects you to know that:

  • The SoA is required at 6.1.3 d)
  • The SoA must justify both inclusion and exclusion of Annex A controls — omitting a control is allowed but must be explained
  • The SoA must state the status of implementation for each included control (e.g., implemented, in progress, planned)
  • The SoA is documented information that must be maintained and reviewed

Risk Treatment Plan and Risk Owner Approval

The risk treatment plan documents what will be done, who will do it, with what resources, and by when. The plan and the residual risks must be approved by the risk owners — not by top management in general, and not by the implementer. Risk owner approval is a specific, mandatory signature in the standard.

Common Traps on 6.1.3

  • "The SoA lists only the controls that are implemented." Wrong — it lists all necessary controls, including those not yet implemented, with their implementation status.
  • "Controls can be excluded without justification." Wrong — exclusions must be justified.
  • "The risk treatment plan is approved by top management." Wrong — it is approved by risk owners.
  • "Risk treatment options are limited to mitigate and accept." Wrong — there are four options: avoid, modify, share, retain.

6.2 Information Security Objectives and Planning to Achieve Them

The organization must establish information security objectives at relevant functions and levels. The objectives must:

  1. Be consistent with the information security policy (Clause 5.2)
  2. Be measurable (where practicable)
  3. Take into account applicable requirements and the results of risk assessment and risk treatment
  4. Be monitored
  5. Be communicated
  6. Be updated as appropriate

The organization must keep objectives as documented information and plan how to achieve them by determining what will be done, with what resources, by whom, when, and how the results will be evaluated.

SMART Objectives

The criteria above map closely to the well-known SMART model:

SMART ElementISO/IEC 27001 Requirement
SpecificEstablished at relevant functions and levels; consistent with policy
MeasurableMust be measurable (where practicable)
AchievablePlanned with resources, responsibility, and timeline
RelevantTakes into account applicable requirements and risk results
Time-bound"When" is part of the planning requirement

Plus two additional ISO-specific requirements: monitored and communicated, and updated as appropriate.

Good vs. Bad Objectives — Exam Examples

Bad ObjectiveGood Objective
"Improve security.""Reduce phishing click rate from 12% to under 4% by Q4 2026."
"Train employees.""Deliver security awareness training to 100% of in-scope staff within 30 days of hire, with annual refreshers."
"Implement controls.""Implement MFA on all remote access pathways by 30 June 2026, verified by access logs."

Bad objectives are vague and unverifiable; good objectives are specific, measurable, time-bound, and tied to risk results.


How Clause 6 Connects to Other Clauses

Input fromUsed in 6.1/6.2 to...
4.1 issuesIdentify risks and opportunities
4.2 requirementsSet risk criteria and objectives
5.1 leadershipEnsure risk owners are appointed
5.2 policyProvide framework for objectives (6.2)
5.3 rolesAssign risk owners who approve treatment
6.1 outputsDrive 7.2 competence, 7.3 awareness, 7.4 communication, 8.1 operational planning, 9.1 monitoring
6.2 objectivesEvaluated in 9.1 monitoring and 9.3 management review

Clause 6 is the pivot point of the entire standard. Everything before it sets the stage; everything after it depends on its outputs.


Exam Scenarios and Traps

  • Trap 1: An option claims the SoA is optional. Wrong — it is required at 6.1.3 d).
  • Trap 2: An option says risk acceptance criteria are determined after the assessment. Wrong — they are set before.
  • Trap 3: An option lists only three risk treatment options. Wrong — there are four (avoid, modify, share, retain).
  • Trap 4: An option states that objectives must always be measurable. Wrong — they must be measurable where practicable.
  • Trap 5: An option says the risk treatment plan is approved by top management. Wrong — risk owners approve the plan and the residual risks.
  • Trap 6: An option says controls can be excluded silently. Wrong — exclusions must be justified in the SoA.

Key Takeaways

  • Clause 6 plans the ISMS: risks/opportunities (6.1) and SMART objectives (6.2).
  • 6.1.2 requires a documented risk assessment process with pre-defined risk acceptance criteria — the link to the risk-management chapter.
  • 6.1.3 requires a Statement of Applicability with justifications for inclusions, exclusions, and implementation status, plus a risk treatment plan approved by risk owners.
  • 6.2 objectives must be consistent with the policy, measurable (where practicable), monitored, communicated, and updated.
  • The four risk treatment options — avoid, modify, share, retain — are a must-know for the exam.
Test Your Knowledge

Under Clause 6.1.3, which artifact must the organization produce that justifies the inclusion and exclusion of Annex A controls and states the status of implementation of each included control?

A
B
C
D
Test Your Knowledge

Which of the following is the complete set of risk treatment options recognized by ISO/IEC 27001 Clause 6.1.3?

A
B
C
D
Test Your Knowledge

An organization sets an objective to "improve information security awareness." Which requirement of Clause 6.2 does this objective most clearly fail to meet?

A
B
C
D