ISO 27001 Clause 8: Operation — Where Your Controls Actually Run
Clause 8 of ISO 27001:2022 is where planning becomes execution. 8.1 requires you to plan, implement and control the processes needed to meet requirements and to implement the actions decided in Clause 6 — establishing criteria for those processes, keeping documented information sufficient to show they ran as planned, controlling planned changes and reviewing unintended ones, and controlling externally provided processes, products and services relevant to the ISMS (the 2022 revision widened this from just "outsourced processes" — your cloud providers and key SaaS vendors are in scope). 8.2 requires information security risk assessments at planned intervals and when significant changes occur, with results retained. 8.3 requires the risk treatment plan to actually be implemented, with results retained. Clause 8 is short because the substance lives in Annex A: this is the clause under which your controls operate day to day. The audit findings here are correspondingly operational: risk assessments frozen since certification, treatment plans with expired deadlines, and vendor changes nobody re-assessed.
Clause 8 gets three subclauses and barely half a page in the standard — the shortest of the seven management-system clauses. Don't mistake brevity for unimportance: this is the clause your entire day-to-day security operation formally hangs from. Clauses 4 through 7 set things up; Clause 8 is the standard saying now run it, and keep the receipts. Part five of our clauses 4–10 series (hub, Clause 7 previous).
8.1 — Operational planning and control
What it requires: plan, implement and control the processes needed to meet requirements and to implement the actions determined in Clause 6 — by establishing criteria for those processes and implementing control in accordance with the criteria. Documented information shall be available to the extent necessary to have confidence that the processes have been carried out as planned. The organization shall control planned changes and review the consequences of unintended changes, acting to mitigate adverse effects. And it shall ensure that externally provided processes, products or services relevant to the ISMS are controlled.
That's dense, so unpack it into its three working parts:
- Run what you planned. The "actions determined in Clause 6" are your risk treatments and the controls in your Statement of Applicability. Clause 8.1 is the formal bridge: Annex A controls don't operate in a vacuum — they operate here, as the processes this clause requires you to control. Access reviews, change management, backup routines, continuity testing, secure development — all of it is Clause 8 in motion, and each process needs criteria (what does "done correctly" mean?) and records showing it ran.
- Control change, notice the unplanned kind. Planned changes get managed (this pairs with Clause 6.3's planning-of-changes requirement and the change-management controls in Annex A). Unintended changes — the migration that had side effects, the vendor who silently altered their product — get reviewed and mitigated. Auditors like asking for an example of each.
- Control what you've outsourced. The 2022 revision changed the wording from "outsourced processes" to "externally provided processes, products or services" — deliberately wider. Your cloud provider, your identity provider, your critical SaaS tools: relevant to the ISMS, therefore requiring control — vendor assessment, contractual requirements, monitoring of their attestations. For a modern startup this is arguably the biggest single item in Clause 8, since most of the actual infrastructure is externally provided.
Evidence in practice: operating records of your controls (tickets, review sign-offs, pipeline logs, test reports), a change-management trail, and a vendor register with assessments that are current — not from the year you onboarded them. This is where evidence collection habits pay for themselves: Clause 8's documented-information requirement is satisfied by the operational exhaust of well-run processes, if you keep it.
8.2 — Risk assessment at planned intervals
What it requires: perform information security risk assessments at planned intervals or when significant changes are proposed or occur, taking account of the criteria established in 6.1.2 — and retain documented information of the results.
Clause 6 defined how you assess risk; 8.2 makes sure you keep doing it. The two triggers matter equally. "Planned intervals" means the cadence is decided in advance (annual is the common floor, with many teams reviewing the register quarterly). "Significant changes" means the register moves when reality does: a new product line, a major architecture shift, a new critical vendor, an acquisition — each should leave a visible mark on the risk assessment, dated near the event that caused it.
The classic finding: a risk register last touched at certification, two audits ago, while the company shipped a new platform and tripled headcount. The register's timestamps tell the story before anyone answers a question.
8.3 — Risk treatment implementation
What it requires: implement the risk treatment plan — and retain documented information of the results of the risk treatment.
One sentence with teeth. The treatment plan from 6.1.3 is a commitment, and 8.3 is where the auditor checks it was kept: treatments completed, dated, with evidence; or consciously rescheduled with the risk owner's knowledge — not silently expired. A treatment plan where half the deadlines passed without action or acknowledgment is simultaneously an 8.3 finding, a resourcing question against Clause 5, and a preview of your Clause 10 corrective-action workload.
How auditors treat Clause 8
Because the clause is thin on words, auditors use it as the frame for everything operational: it's the formal citation behind most control-effectiveness testing. Expect them to pick items from the SoA and follow the thread — show me the process criteria, show me the records that it ran, show me what happened when it didn't. Expect the vendor question (how do you control your externally provided services?), the interval question (when was the last risk assessment, and what triggered it?), and the plan question (walk me through a completed treatment and a late one).
Common Clause 8 nonconformities
- The frozen risk assessment — no planned interval defined, or defined and missed; no reassessment after obvious significant change.
- Expired treatment plans — deadlines passed, no completion evidence, no formal rescheduling.
- Uncontrolled externals — critical vendors with no current assessment, or subprocessor changes nobody reviewed.
- Processes without criteria — the access review happens, but nothing defines what reviewers check or what failing looks like, so "carried out as planned" can't be demonstrated.
Ready to Streamline Your Compliance?
Discover how AuditBadger can simplify your compliance management process.
The bottom line
Clause 8 asks the simplest question in the standard: did you actually do what your ISMS says you do — and can you show it? Keep the risk assessment on a real cadence, keep the treatment plan honest, keep vendor control current, and let your operating records accumulate as you work. Next in the series: Clause 9, Performance Evaluation — monitoring, internal audit, and management review, where the ISMS turns around and checks itself.
Frequently asked questions
What does ISO 27001 Clause 8 require? +
Clause 8 (Operation) has three subclauses. 8.1 requires you to plan, implement, and control the processes needed to meet requirements and to implement the actions decided in Clause 6 — establishing criteria for those processes, keeping documented information sufficient to show they ran as planned, controlling planned changes, reviewing unintended ones, and controlling externally provided processes, products, and services relevant to the ISMS. 8.2 requires information security risk assessments at planned intervals and when significant changes occur, with results retained. 8.3 requires the risk treatment plan to actually be implemented, with results retained. It's the shortest management-system clause because the substance lives in Annex A — Clause 8 is the formal frame under which your controls operate day to day.
How often must risk assessments be performed under ISO 27001? +
The standard doesn't set a number — Clause 8.2 requires risk assessments "at planned intervals" and additionally when significant changes are proposed or occur. Both triggers carry equal weight: the cadence must be decided in advance (annual is the common floor, with many teams reviewing the register quarterly), and the register must visibly move when reality does — a new product line, a major architecture change, a new critical vendor, or an acquisition should each leave a dated mark on the risk assessment near the event that caused it. The classic audit finding is the frozen register: last touched at certification while the company shipped a new platform and tripled headcount, a story the timestamps tell before anyone answers a question.
Does ISO 27001 Clause 8 cover cloud providers and SaaS vendors? +
Yes. Clause 8.1 requires the organization to ensure that externally provided processes, products, or services relevant to the ISMS are controlled — wording the 2022 revision deliberately widened from the 2013 edition's "outsourced processes." For a modern startup this is arguably the biggest single item in the clause, since most of the actual infrastructure is externally provided: your cloud platform, identity provider, and critical SaaS tools are all in scope. "Controlled" in practice means a vendor register with current assessments (not just from onboarding year), contractual security requirements, review of vendor attestations like SOC 2 reports, and re-assessment when a vendor changes something significant — subprocessor changes being the case auditors most often find unreviewed.