From the course: ISO 27001:2022-Compliant Cybersecurity: Getting Started

Unlock the full course today

Join today to access over 23,700 courses taught by industry experts.

Operational planning and control, risk assessment, and risk treatment (Clauses 8.1, 8.2, and 8.3)

Operational planning and control, risk assessment, and risk treatment (Clauses 8.1, 8.2, and 8.3)

From the course: ISO 27001:2022-Compliant Cybersecurity: Getting Started

Operational planning and control, risk assessment, and risk treatment (Clauses 8.1, 8.2, and 8.3)

- [Instructor] In earlier clauses of ISO 27001, you were asked to create plans to conduct risk management and risk treatment, achieve information security objectives, and other processes needed for your information security management system, or ISMS. In this video, you'll learn about Clause 8: Operation, where you're required to implement the plans you built earlier. Clause 8.1: Operational Planning and Control is all about taking the actions you defined as required in earlier clauses. This clause specifically refers to Clause 6: Planning, and requires your organization to implement the actions determined in that clause. You can think about Clause 6 as the planning phase for risk management and achieving security objectives, and Clause 8 as the execution phase. Because Clauses 6 and 8 eight are so closely related, they are often evaluated together during a formal ISO 27001 audit. Clause 8.1 also requires your…

Contents