Skip to main content
Category: ISMS Clauses and Planning

Operation (Clause 8)

Also known as: ISO 27001 Clause 8, Operation Clause, Clause 8 Operation
Simply put

Operation (Clause 8) is the part of the ISO/IEC 27001 standard that deals with actually carrying out the security activities the organization has planned. It focuses on putting the information security management system (ISMS) into practice on a day-to-day basis, including regularly re-checking security risks and applying the plans made to address them. It is one of the clauses (4 through 10) that an organization must meet to be certified against ISO 27001.

Formal definition

Clause 8 ("Operation") is one of the certifiable ISMS requirement clauses (clauses 4-10) of ISO/IEC 27001. It addresses operational planning and control, requiring the organization to plan, implement, and control the processes needed to meet information security requirements and to carry out the actions determined in the planning clause. In most implementations it also covers the recurring performance of information security risk assessments and the execution of the risk treatment plan, so that the controls selected via the Statement of Applicability and informed by risk assessment are put into effect and maintained. The clause is concerned with regular re-assessment and treatment of risks and with control over operations, including outsourced processes, rather than with prescribing specific technical controls (those reference controls appear in Annex A). Its scope is limited to the operational execution and control of the defined ISMS; the specific documented information, cadence of re-assessment, and treatment of outsourced processes vary depending on the organization's scope, risk assessment outcomes, and certification body expectations.

Why it matters

Clause 8 is where an ISO/IEC 27001 information security management system stops being a set of documents and becomes an operational reality. The planning clauses establish what an organization intends to do about its information security risks, but Clause 8 requires that those intentions are actually carried out, controlled, and maintained on a day-to-day basis. Without effective operation, the risk assessments, the Statement of Applicability, and the selected controls remain theoretical, and a certification body would typically find that the ISMS is not being executed as designed.

One of the reasons this clause carries weight in most engagements is its emphasis on regular re-assessment and treatment of risks. Information security threats and organizational circumstances change over time, and Clause 8 supports the expectation that risk assessments are performed on a recurring basis rather than once, so that the risk treatment plan is kept current and applied. This ongoing operational discipline is part of what distinguishes a living management system from a point-in-time exercise.

Clause 8 also extends to control over outsourced processes, which matters because organizations increasingly depend on third parties and cloud providers for functions within the ISMS scope. Ensuring the organization retains control over these operations is part of demonstrating that the ISMS boundary is being managed. It is worth noting that Clause 8 concerns operational execution and control of the defined ISMS scope; it does not prescribe specific technical controls, which appear as reference controls in Annex A, and certification against it covers only the defined scope of the ISMS.

Who it's relevant to

ISMS managers and information security leads
Those responsible for running the ISMS rely on Clause 8 as the framework for turning planned controls and risk treatments into ongoing operational activity. They typically own the execution of the risk treatment plan and the scheduling of recurring risk assessments within the defined scope.
Internal and certification auditors
Auditors assess whether operational planning and control are functioning as intended and whether risk re-assessment and treatment are being carried out. Because Clause 8 is a certifiable requirement, evidence of operational execution is generally part of what is examined during certification and surveillance audits.
Vendor and third-party risk managers
Clause 8's emphasis on control over outsourced processes makes it relevant to those managing suppliers and cloud providers within the ISMS scope. They help demonstrate that the organization retains appropriate control over operations performed by third parties, though the exact treatment depends on scope and risk assessment outcomes.
GRC professionals coordinating multiple frameworks
Professionals mapping ISO 27001 against other frameworks such as SOC 2 may reference Clause 8 when demonstrating ongoing operational controls. They should note that mapping between frameworks is partial, and satisfying Clause 8 does not automatically satisfy the operational expectations of another standard.

Inside Operation (Clause 8)

Operational Planning and Control
Clause 8 requires the organization to plan, implement, and control the processes needed to meet ISMS requirements and to carry out the actions determined in the planning stage (Clause 6). This typically includes maintaining documented information sufficient to have confidence that processes have been carried out as planned.
Control of Changes
The organization is expected to control planned changes and review the consequences of unintended changes, taking action to mitigate any adverse effects as necessary. This links operational execution back to the ISMS objectives set in earlier clauses.
Control of Externally Provided Processes
Processes, products, or services that are outsourced or provided externally and that are relevant to the ISMS are expected to be determined and controlled, depending on scope and the organization's risk assessment.
Information Security Risk Assessment (Operational)
Clause 8 calls for performing information security risk assessments at planned intervals, or when significant changes occur, in accordance with the criteria established during ISMS planning. Documented information on the results is typically retained.
Information Security Risk Treatment (Operational)
The organization is expected to implement the information security risk treatment plan developed during planning and to retain documented information of the results. This connects the operational phase to the Statement of Applicability and Annex A reference controls selected via risk assessment.

Common questions

Answers to the questions practitioners most commonly ask about Operation (Clause 8).

Is Clause 8 where the Annex A controls are listed?
No. Clause 8 (Operation) is one of the ISMS requirement clauses (clauses 4 through 10) and addresses how the organization plans, implements, and controls the processes needed to meet its information security requirements. Annex A is a separate reference list of controls that are selected via the Statement of Applicability and informed by the risk assessment; it is not the content of Clause 8. Clause 8 does, however, cover carrying out the risk assessment and risk treatment activities that ultimately drive which Annex A controls are applied.
Does satisfying Clause 8 mean my SOC 2 operational controls are also covered?
Not automatically. Clause 8 is part of the ISO/IEC 27001 ISMS requirements, which lead to a certification issued by an accredited certification body. A SOC 2 examination is a separate attestation performed by a licensed CPA firm against the Trust Services Criteria and results in a report, not a certification. Mapping between the two frameworks is possible but partial, so operational activities under Clause 8 may support SOC 2 evidence but do not by themselves satisfy SOC 2 requirements. Each framework should be scoped and assessed on its own terms.
What operational activities does Clause 8 typically require an organization to demonstrate?
Clause 8 generally covers operational planning and control, the performance of the information security risk assessment, and the implementation of the risk treatment plan. In most implementations, organizations show that security processes are planned, implemented, and controlled, that changes are managed and their consequences considered, and that outsourced processes are determined and controlled. The specific evidence expected can vary by scope and certification body.
How often should the risk assessment and risk treatment under Clause 8 be performed?
Clause 8 calls for the information security risk assessment to be performed at planned intervals and when significant changes occur. The frequency and triggers are typically defined by the organization based on its context and risk environment rather than fixed by the standard. Many organizations align these activities with their broader ISMS review cycle, but the exact cadence depends on scope, risk profile, and internal decisions.
What documentation is typically expected to evidence Clause 8 conformity?
Organizations commonly retain documented information showing that processes have been carried out as planned, along with results of the information security risk assessments and records of risk treatment decisions. The precise records depend on scope and the certification body's expectations, so it is advisable to confirm what documented information will be examined during the audit rather than assuming a universal checklist.
How does Clause 8 relate to change management and outsourced processes?
Clause 8 typically requires that planned changes be controlled and that the consequences of unintended changes be reviewed and mitigated as needed. It also generally requires that externally provided or outsourced processes relevant to the ISMS be determined and controlled. The depth of control expected for outsourced processes usually depends on the defined ISMS scope and the associated risk, so boundaries should be clarified during scoping.

Common misconceptions

Clause 8 is where the specific technical security controls are listed and made mandatory.
Clause 8 is an ISMS requirement clause (part of clauses 4 through 10) focused on operating the management system, planning, executing, and controlling processes. The reference controls themselves are listed in Annex A and are selected through the Statement of Applicability informed by risk assessment, not prescribed as universally mandatory by Clause 8.
Risk assessment is a one-time activity completed before certification and not part of ongoing operations.
Clause 8 requires that information security risk assessments be performed at planned intervals or when significant changes are proposed or occur, making risk assessment an ongoing operational activity rather than a single upfront exercise.
Satisfying Clause 8 demonstrates the same operating effectiveness that a SOC 2 Type II report evaluates.
ISO/IEC 27001 certification against clauses 4 through 10, including Clause 8, is a certification of an ISMS by an accredited certification body and covers only the defined scope. A SOC 2 Type II is an attestation examination by a CPA firm assessing design and operating effectiveness over a review period against the Trust Services Criteria. Mapping between the two is partial, and satisfying one does not automatically satisfy the other.

Best practices

Maintain documented information sufficient to demonstrate that operational processes were carried out as planned, since this evidence is typically relied upon during certification audits.
Define and follow a schedule for information security risk assessments at planned intervals, and trigger reassessment whenever significant changes are proposed or occur.
Ensure the operational execution of the risk treatment plan traces back consistently to the Statement of Applicability and the Annex A reference controls selected during planning.
Establish a change-control process that reviews the consequences of both planned and unintended changes and drives mitigating action where adverse effects are identified.
Determine and control externally provided or outsourced processes relevant to the ISMS in a manner proportionate to your scope and risk assessment.
Retain documented results of risk assessment and risk treatment activities so operational evidence remains available for internal review and external audit within the defined ISMS scope.