Operation (Clause 8)
Operation (Clause 8) is the part of the ISO/IEC 27001 standard that deals with actually carrying out the security activities the organization has planned. It focuses on putting the information security management system (ISMS) into practice on a day-to-day basis, including regularly re-checking security risks and applying the plans made to address them. It is one of the clauses (4 through 10) that an organization must meet to be certified against ISO 27001.
Clause 8 ("Operation") is one of the certifiable ISMS requirement clauses (clauses 4-10) of ISO/IEC 27001. It addresses operational planning and control, requiring the organization to plan, implement, and control the processes needed to meet information security requirements and to carry out the actions determined in the planning clause. In most implementations it also covers the recurring performance of information security risk assessments and the execution of the risk treatment plan, so that the controls selected via the Statement of Applicability and informed by risk assessment are put into effect and maintained. The clause is concerned with regular re-assessment and treatment of risks and with control over operations, including outsourced processes, rather than with prescribing specific technical controls (those reference controls appear in Annex A). Its scope is limited to the operational execution and control of the defined ISMS; the specific documented information, cadence of re-assessment, and treatment of outsourced processes vary depending on the organization's scope, risk assessment outcomes, and certification body expectations.
Why it matters
Clause 8 is where an ISO/IEC 27001 information security management system stops being a set of documents and becomes an operational reality. The planning clauses establish what an organization intends to do about its information security risks, but Clause 8 requires that those intentions are actually carried out, controlled, and maintained on a day-to-day basis. Without effective operation, the risk assessments, the Statement of Applicability, and the selected controls remain theoretical, and a certification body would typically find that the ISMS is not being executed as designed.
One of the reasons this clause carries weight in most engagements is its emphasis on regular re-assessment and treatment of risks. Information security threats and organizational circumstances change over time, and Clause 8 supports the expectation that risk assessments are performed on a recurring basis rather than once, so that the risk treatment plan is kept current and applied. This ongoing operational discipline is part of what distinguishes a living management system from a point-in-time exercise.
Clause 8 also extends to control over outsourced processes, which matters because organizations increasingly depend on third parties and cloud providers for functions within the ISMS scope. Ensuring the organization retains control over these operations is part of demonstrating that the ISMS boundary is being managed. It is worth noting that Clause 8 concerns operational execution and control of the defined ISMS scope; it does not prescribe specific technical controls, which appear as reference controls in Annex A, and certification against it covers only the defined scope of the ISMS.
Who it's relevant to
Inside Operation (Clause 8)
Common questions
Answers to the questions practitioners most commonly ask about Operation (Clause 8).