All posts
ISO 270019 min readJul 30, 2026

ISO 27001 planning requirements explained

Anish / CTO/Co-Founder
ISO 27001 planning requirements explained

ISO 27001 planning is the bridge between information security risk decisions and auditable operations. Not just a certification project plan. Under ISO/IEC 27001:2022, organisations must plan actions for ISMS risks and opportunities, integrate and implement those actions in ISMS processes, and evaluate their effectiveness (IS/ISO/IEC 27001:2022).

In practical terms, planning should answer five questions:

  • What risks, opportunities, objectives, controls, and operational processes need to be planned?
  • Who owns each decision or action?
  • What resources, timing, and evaluation methods are needed?
  • What records show the plan was implemented?
  • How will changes, outsourced processes, and reviews be controlled?

Planning becomes audit-ready when the outputs from Clause 6 are traceable into Clause 8.1 operations: risk assessment, treatment decisions, Statement of Applicability entries, owners, procedures, monitoring, retained evidence, and review.

What ISO 27001 planning requirements mean

ISO 27001 planning covers the decisions an organisation makes about how its ISMS will address risk, meet objectives, implement controls, operate processes, and retain evidence. A project schedule may help manage certification work, it is not enough by itself.

The planning requirement is broader because the ISMS has to operate after the project plan is complete. Risk treatment actions need owners. Controls need implementation status. Objectives need monitoring. Outsourced processes and planned changes need control. Evidence needs to show that planned processes were carried out as intended.

A useful way to think about it is:

Clause 6 defines what must be planned. Clause 8.1 requires those planned actions to be implemented, controlled, and evidenced.

That distinction matters because an auditor is not only interested in whether a risk treatment plan exists. They may also look for whether the planned treatment was implemented, whether the relevant control is reflected in the Statement of Applicability, whether an owner is accountable, and whether operating records support the decision.

The ISO 27001 clauses that matter for planning

The planning-related clauses sit mainly in Clause 6 and Clause 8.1.

  • Clause 6.1 — actions to address risks and opportunities: the organisation plans how to address ISMS-level risks and opportunities, how to integrate those actions into ISMS processes, and how to evaluate whether the actions are effective.
  • Clause 6.1.2 — information security risk assessment: the organisation defines and applies a risk assessment process, including criteria, risk identification and ownership, analysis, and evaluation. Documented information about the process and assessment results must be retained.
  • Clause 6.1.3 — information security risk treatment: the organisation selects treatment options, determines necessary controls, compares them with Annex A to check that necessary controls have not been omitted, formulates a treatment plan, and obtains risk-owner approval of the plan and residual-risk acceptance. The Statement of Applicability records necessary controls, inclusion justification, implementation status, and reasons for excluding Annex A controls.
  • Clause 6.2 — information security objectives: objectives must be set at relevant functions and levels, be measurable where practicable, take account of relevant requirements and risk assessment/treatment results, be monitored, updated as appropriate, and available as documented information. Planning to achieve them must define activities, resources, responsibility, timing, and evaluation.
  • Clause 8.1 — operational planning and control: the organisation plans, implements, and controls the processes needed to meet requirements and implement Clause 6 actions. This includes setting process criteria, controlling processes against those criteria, retaining documented information as necessary to provide confidence that processes were carried out as planned, controlling planned changes, reviewing unintended changes, and controlling relevant externally provided processes, products, and services.

These requirements do not prescribe one fixed template, risk register format, ticketing system, or review calendar. ISO 27001 requires specified documented information and any additional documented information the organisation determines is necessary for ISMS effectiveness; the extent of documentation can differ based on size, activities, process complexity, and personnel competence (IS/ISO/IEC 27001:2022).

Planning outputs and records you should be able to show

The table below is an illustrative planning matrix, not an ISO-mandated template. It shows the kinds of outputs, owners, and evidence that make planning easier to operate and assess.

Requirement areaPlanning outputTypical ownerCommon evidence to retainAudit question
ISMS risks and opportunitiesPlanned actions to address ISMS risks and opportunities, including how actions will be integrated and evaluatedISMS owner, security lead, risk ownerRisk and opportunity records, action plan records, review records, effectiveness evaluationCan the organisation show what ISMS risks and opportunities were planned for and how actions were evaluated?
Risk assessmentRisk assessment process, criteria, risk owners, assessment resultsSecurity lead, GRC lead, risk ownersRisk assessment methodology or criteria, risk assessment results, risk-owner assignmentsIs there a defined and applied process for assessing information security risks?
Risk treatmentTreatment options, treatment plan, residual-risk acceptanceRisk owner, control owner, security leadRisk treatment plan, treatment approvals, residual-risk acceptance records, treatment resultsAre treatment decisions approved and implemented according to the plan?
Statement of ApplicabilityNecessary controls, inclusion justification, implementation status, exclusions and reasonsISMS owner, GRC lead, control ownersCurrent SoA, control mapping, implementation status evidenceDo control decisions correspond to the risk assessment and treatment plan?
Information security objectivesMeasurable objectives where practicable, activities, resources, responsibility, timing, evaluation methodLeadership, ISMS owner, functional ownersDocumented objectives, monitoring results, progress reviewsAre objectives planned, assigned, monitored, and updated as appropriate?
Operational planning and controlProcess criteria and controlled procedures or workflows for planned actionsControl owners, operations, engineering, securityProcedures, workflow records, tickets, approvals, logs, review recordsAre planned ISMS actions being carried out under controlled operating processes?
Changes affecting planned processesPlanned change controls and review of unintended changesChange owner, engineering, operations, securityChange requests, approvals, impact assessments, post-change reviewsAre changes controlled where they affect ISMS processes or risk treatment?
Externally provided processes, products, or servicesOversight of relevant outsourced or supplier-provided processesProcurement, vendor owner, security, legalSupplier assessments, contracts or security requirements, review records, issue trackingAre relevant externally provided processes controlled within the ISMS planning model?
Monitoring and measurementWhat is monitored, methods, timing, responsibility, and resultsISMS owner, control owners, leadershipMetrics, monitoring results, review records, corrective actionsCan the organisation show whether planned actions and objectives are being monitored?

For a small organisation, some of these records may live in a controlled document set, ticketing tool, spreadsheet, or shared repository. The format is less important than whether the evidence is complete, current, controlled, owned, and traceable to the ISMS.

How planning becomes audit-ready: the risk-to-evidence workflow

The practical chain is:

  1. Identify and assess the risk.
  2. Decide how to treat it.
  3. Determine necessary controls.
  4. Record the control decision in the Statement of Applicability where relevant.
  5. Assign an accountable owner.
  6. Define the operating process or procedure.
  7. Set an objective, metric, or review point where useful.
  8. Collect and retain evidence that the process operated.
  9. Review results and update the plan when significant changes are proposed or occur.

This traceability is not a required ISO template. More exactly, ISO does not require this table or this exact sequence. It is a practical way to show the relationship between planning decisions and operating evidence.

RiskTreatment decisionSoA/control referenceOwnerOperational processEvidence recordReview cadence
Supplier users retain access to systems or data after their business need endsReduce the risk by implementing defined supplier access approval, periodic review, and removal stepsSoA entry for selected supplier access and access review controls; Annex A comparison documentedSystem owner and supplier relationship ownerSupplier access requests require approval; supplier accounts are reviewed; removals are tracked through the access management workflowAccess request approvals, user review results, removal tickets, supplier access exceptionsAt planned intervals and when supplier scope, system access, or contract status changes

The same pattern can be used for other risks, such as backup recovery, vulnerability remediation, privileged access, or supplier security. The key is not the table itself. The key is that a reviewer can follow the path from assessed risk to treatment decision, selected control, owner, operating process, evidence, and review.

What audit-ready planning evidence looks like

A practical readiness check is whether planning evidence is:

  • current;
  • approved where appropriate;
  • tied to the ISMS scope;
  • linked to risk assessment and treatment decisions;
  • assigned to accountable owners;
  • supported by operational records;
  • reviewed on a defined cadence;
  • updated when significant changes are proposed or occur.

Examples may include risk assessment results, risk treatment plans, the Statement of Applicability, security objectives and monitoring results, management review inputs where relevant, control operation logs, workflow tickets, procedure records, supplier oversight records, change records, and internal review findings.

This matters because certification assessment is not limited to collecting documents. For ISMS certification, Stage 1 includes obtaining required ISMS documentation, while Stage 2 evaluates the correspondence between controls, the SoA, risk assessment and treatment, policies, and objectives, as well as control implementation and relevant monitoring, measurement, and analysis (HKCAS 007 Annex II(F2)).

So the planning question is basically not simply, “Do we have a plan?” It is, “Can we show that the plan drove controlled activity and produced retained evidence?”

Common ISO 27001 planning gaps to avoid

Use these as quick diagnostic prompts, not a formal nonconformity list.

  • Treating planning as a certification schedule only. Add the risk, control, owner, monitoring, and evidence view.
  • Recording risks without treatment decisions. Each material assessed risk should have a clear treatment path and risk-owner involvement.
  • Selecting controls without showing why. Link control decisions to the risk treatment plan and SoA justification.
  • Creating objectives that cannot be evaluated. Define what will be done, who owns it, what resources are needed, when it should be completed, and how it will be evaluated.
  • Assigning actions without operational ownership. A named document owner is not always enough; identify who operates the process.
  • Keeping evidence scattered. Maintain a traceable path from risk records to treatment, SoA, workflows, and retained records.
  • Ignoring outsourced processes. Include relevant externally provided processes, products, and services in operational planning and oversight.
  • Failing to update after change. Reassess risk and planning records when significant changes are proposed or occur.
  • Leaving Clause 6 disconnected from Clause 8.1. Planned actions should be visible in controlled processes and retained evidence.

A practical way to keep ISO 27001 planning current

ISO 27001 planning is easier to maintain when it becomes part of the operating rhythm rather than a pre-audit reconstruction exercise. Risk decisions, treatment plans, SoA entries, control owners, evidence locations, monitoring results, supplier oversight, and change records should be connected enough that a reviewer can follow the chain without relying on memory.

Smaller teams can keep this lightweight if records are controlled, versioned, assigned, and reviewed. Larger or distributed teams usually need stronger coordination because planning outputs span security, engineering, procurement, operations, legal, and leadership.

Ciphrix approaches ISO 27001 planning as an operating system for compliance: connecting risk decisions, owners, workflows, evidence, and readiness review so planning remains visible after the initial documentation work is done. The practical next step is to test one material risk end to end: assessment, treatment, SoA decision, owner, operating process, evidence, and review. If that chain is unclear, there is probably still planning work to do.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents