Skip to main content
Category: ISMS Clauses and Planning

Planning (Clause 6)

Also known as: Clause 6, Clause 6 Planning
Simply put

Planning is one of the numbered clauses in an ISO management system standard that asks an organization to think ahead about the risks and opportunities it faces, set objectives, and plan how to manage changes in a controlled way. The goal is to prepare proactively rather than reacting to problems after they occur. Note that the evidence provided describes Clause 6 as it appears in ISO 9001 (a quality management standard), not ISO/IEC 27001; the specific requirements and terminology differ by standard and version.

Formal definition

In ISO management system standards, Clause 6 (Planning) sits within the common high-level structure and typically addresses actions to plan for risks and opportunities, the setting of objectives and plans to achieve them, and the controlled management of changes. The evidence supplied here documents Clause 6 within ISO 9001:2015, where it is organized into subclauses (6.1 addressing risks and opportunities, 6.2 addressing quality objectives and planning to achieve them, and 6.3 addressing planning of changes). In ISO/IEC 27001, the corresponding Planning clause is one of the management system requirement clauses and drives information security risk assessment, risk treatment, and the Statement of Applicability; however, the sources in this evidence packet describe ISO 9001 rather than ISO/IEC 27001, so its precise wording, subclause content, and applicability should be verified against the relevant standard and edition before use in an ISMS context.

Why it matters

Planning is the clause where an organization shifts from reacting to problems toward anticipating them. In an ISO management system standard, Clause 6 asks the organization to identify the risks and opportunities that could affect its objectives, decide what actions to take, set measurable objectives, and plan any changes so they are introduced in a controlled way rather than ad hoc. This proactive posture is what distinguishes a mature management system from a collection of after-the-fact fixes.

The importance is practical: unplanned or uncontrolled changes are a common source of disruption, and a structured planning clause is designed to reduce that risk. As the evidence describes for ISO 9001:2015, Clause 6 emphasizes planning actions to address risks and opportunities, managing change in a controlled manner so that changes do not negatively affect the system, and setting objectives that give the organization direction and a basis for continual improvement.

A critical caveat for compliance professionals: the evidence supplied here describes Clause 6 as it appears in ISO 9001, a quality management standard, not ISO/IEC 27001. While ISO management system standards share a common high-level structure and ISO/IEC 27001 has a corresponding Planning clause that drives information security risk assessment, risk treatment, and the Statement of Applicability, the precise wording, subclause content, and terminology differ by standard and version. Do not assume the ISO 9001 requirements documented here map directly onto an ISMS without verifying against the relevant ISO/IEC 27001 edition.

Who it's relevant to

Quality and management system managers
Those implementing or maintaining an ISO 9001 quality management system work directly with Clause 6 when identifying risks and opportunities, setting objectives, and controlling changes. This audience should treat the evidence here as ISO 9001-specific.
ISO/IEC 27001 practitioners and ISMS managers
Security professionals building an ISMS encounter a corresponding Planning clause that typically drives risk assessment, risk treatment, and the Statement of Applicability. Because the sources here describe ISO 9001, they should verify the precise ISO/IEC 27001 wording, subclause content, and applicability against the relevant edition before relying on it.
Auditors and certification bodies
Auditors assessing a management system against a Planning clause need to confirm which standard and version apply, since subclause structure and terminology differ. The distinction matters when evaluating whether planning, objectives, and change management meet the requirements of the specific standard in scope.
GRC and compliance leads working across frameworks
Professionals mapping controls between standards should note that the common high-level structure creates similar Planning clauses across ISO management system standards, but the correspondence is partial. Requirements documented for one standard, such as ISO 9001, cannot be assumed to satisfy another, such as ISO/IEC 27001, without verification.

Inside Planning (Clause 6)

Actions to Address Risks and Opportunities
Clause 6.1 requires the organization to determine the risks and opportunities that need to be addressed to give assurance the ISMS can achieve its intended outcomes, prevent or reduce undesired effects, and achieve continual improvement. This planning is informed by the context (Clause 4) and interested parties' requirements.
Information Security Risk Assessment
Clause 6.1.2 requires defining and applying a risk assessment process that establishes and maintains risk criteria (including risk acceptance criteria), ensures repeatable and comparable results, identifies risks associated with the loss of confidentiality, integrity, and availability, assigns risk owners, and analyzes and evaluates the identified risks.
Information Security Risk Treatment
Clause 6.1.3 requires defining a risk treatment process to select appropriate treatment options, determine the necessary controls, and compare them against Annex A to verify no necessary controls have been omitted. This process produces the Statement of Applicability and a risk treatment plan, with risk owners' approval of the plan and acceptance of residual risks.
Statement of Applicability (SoA)
An output of risk treatment planning that documents the necessary controls, justification for their inclusion, whether they are implemented, and justification for excluding any Annex A reference controls. In the ISO/IEC 27001:2022 revision, Annex A contains 93 controls organized into four themes, compared with 114 controls in the 2013 version; the applicable count depends on the edition.
Information Security Objectives and Planning to Achieve Them
Clause 6.2 requires establishing information security objectives at relevant functions and levels. Objectives are typically expected to be consistent with the information security policy, measurable where practicable, monitored, communicated, and updated as appropriate, with plans specifying what will be done, resources required, responsibilities, timelines, and how results will be evaluated.
Planning of Changes
The 2022 revision introduced Clause 6.3, which requires that when the organization determines the need for changes to the ISMS, those changes are carried out in a planned manner. Practitioners should specify the version when referencing this clause, as it is not present in the 2013 edition.

Common questions

Answers to the questions practitioners most commonly ask about Planning (Clause 6).

Does Clause 6 require organizations to select every control listed in Annex A?
No. Annex A is a set of reference controls, not a mandatory checklist. Clause 6 requires you to determine which controls are necessary based on your risk assessment and risk treatment decisions, then document the inclusion or exclusion of each Annex A control (and the justification) in the Statement of Applicability. Controls that are not relevant to your identified risks can be excluded, provided the exclusion is justified. Note that Annex A was restructured in the 2022 revision into fewer controls organized into themes, so the specific reference set depends on the version you are certifying against.
Is Clause 6 just about performing the risk assessment?
Not entirely. Risk assessment and risk treatment are central to Clause 6, but the clause also covers other planning requirements, including actions to address risks and opportunities, and the setting of information security objectives together with plans to achieve them. In the current structure, planning for changes to the ISMS also falls within this clause. Treating Clause 6 as only a risk assessment exercise typically leaves the objectives-setting and change-planning requirements unaddressed.
How do the outputs of Clause 6 connect to the Statement of Applicability?
The Clause 6 process typically produces the inputs the Statement of Applicability documents: the results of risk assessment inform which risks require treatment, and the risk treatment plan identifies the controls chosen to address them. The Statement of Applicability then records which reference controls are applicable, whether they are implemented, and the justification for inclusion or exclusion. In most engagements, auditors trace this chain from identified risks through treatment decisions to the Statement of Applicability, so keeping the linkage explicit and traceable helps demonstrate conformity.
What should information security objectives set under Clause 6 look like in practice?
Objectives are generally expected to be consistent with the information security policy, measurable where practicable, communicated, and monitored and updated as appropriate. In most implementations, organizations also define what will be done, the resources required, who is responsible, timelines, and how results will be evaluated. The specific objectives depend on your scope, context, and risk profile, so they should reflect what is meaningful for your ISMS rather than generic targets.
How often should the Clause 6 risk assessment and treatment be revisited?
The standard requires that risk assessments be performed at planned intervals and when significant changes occur, but it does not prescribe a fixed frequency. In practice, many organizations revisit risk assessment and treatment on a defined cycle and additionally when there are material changes to the environment, scope, threats, or business context. The appropriate cadence depends on your circumstances and should be defined within your own documented process.
Does satisfying Clause 6 mean my SOC 2 risk assessment requirements are also covered?
Not automatically. Clause 6 addresses ISO/IEC 27001 ISMS planning requirements, while SOC 2 evaluates controls against the Trust Services Criteria, including risk assessment expectations within the Common Criteria. There can be overlap, and mapping between the two is possible but partial. In most engagements, the risk assessment evidence can be leveraged across both, but each is assessed on its own terms by different parties, so satisfying Clause 6 does not by itself satisfy the corresponding SOC 2 criteria.

Common misconceptions

The Statement of Applicability must include every Annex A control, so all reference controls are mandatory.
Annex A serves as a reference set of controls that are selected via the Statement of Applicability and informed by the risk assessment. Controls may be excluded where justified, provided the organization compares its determined controls against Annex A to confirm none that are necessary have been omitted. The certifiable requirements themselves sit in Clauses 4 through 10, not in Annex A.
Clause 6 planning is a one-time exercise completed before certification.
Planning is intended to be maintained over time. Risk assessments are expected to be repeatable and comparable, objectives are monitored and updated as appropriate, and the 2022 revision's Clause 6.3 addresses handling changes to the ISMS in a planned manner, all of which support ongoing operation rather than a single up-front activity.
Satisfying ISO 27001 Clause 6 planning also satisfies SOC 2's risk-related criteria.
ISO 27001 is a management system standard certified by an accredited certification body, while SOC 2 is an attestation examination performed by a CPA firm against the Trust Services Criteria. Mapping between the two is possible but partial, and meeting ISO 27001 planning requirements does not automatically satisfy SOC 2 criteria; the two frameworks and their risk approaches remain distinct.

Best practices

Define and document a repeatable risk assessment process with explicit risk criteria and risk acceptance criteria so that results are comparable across successive assessments.
Identify risks in terms of loss of confidentiality, integrity, and availability, and assign a named risk owner accountable for each identified risk and for accepting residual risk.
Build the Statement of Applicability by comparing your determined controls against Annex A, and record clear justifications for both inclusion and exclusion of each reference control.
Always specify the ISO/IEC 27001 edition (for example, 2013 versus 2022) when documenting control counts or referencing Clause 6.3, since the structure and control numbers depend on the version.
Establish measurable information security objectives where practicable, aligned with the information security policy, and record who is responsible, what resources are needed, and how results will be evaluated.
Use Clause 6.3 to plan ISMS changes deliberately, revisiting the risk assessment and risk treatment plan when significant changes occur rather than treating planning as a fixed, one-time task.