isms.coach
← All clauses

Clause 6

Planning

Sub-clauses

  • 6.1 Actions to address risks and opportunities (6.1.1 General, 6.1.2 Risk assessment, 6.1.3 Risk treatment)
  • 6.2 Information security objectives and planning to achieve them
  • 6.3 Planning of changes

Why it matters

This is where risk-based thinking gets operationalized. The standard doesn't want a static control checklist — it wants controls chosen because a real risk assessment surfaced them.

What it requires

A repeatable risk assessment method, a risk treatment plan (your Statement of Applicability is the output of this), objectives that are measurable and consistent with your policy, and a stated approach to planning significant changes to the ISMS.

How a self-led small team handles it

Don't skip straight to Annex A. Do the risk register first and let it drive which controls you actually need — keep objectives few, specific, and measurable rather than aspirational.

Track Clause 6 directly — itsbestpractice has a dedicated Risk register & Objectives section built around exactly this clause.

Start your ISMS