isms.coach
← All clauses

Clause 8

Operation

Sub-clauses

  • 8.1 Operational planning and control
  • 8.2 Information security risk assessment
  • 8.3 Information security risk treatment

Why it matters

Where planning turns into doing. Auditors want evidence the risk treatment plan from Clause 6 is actually being executed, not just documented.

What it requires

Evidence that operational processes are controlled, that risk assessments are genuinely performed (not just planned), and that risk treatment — including implementing your Annex A controls — is actually happening.

How a self-led small team handles it

This clause doesn't need its own separate paperwork. Marking controls "Implemented" on your Statement of Applicability, with real evidence behind each one, is exactly what satisfies it.

Track Clause 8 directly — itsbestpractice has a dedicated Statement of Applicability section built around exactly this clause.

Start your ISMS