Sub-clauses
- 6.1 Actions to address risks and opportunities (6.1.1 General, 6.1.2 Risk assessment, 6.1.3 Risk treatment)
- 6.2 Information security objectives and planning to achieve them
- 6.3 Planning of changes
Why it matters
This is where risk-based thinking gets operationalized. The standard doesn't want a static control checklist — it wants controls chosen because a real risk assessment surfaced them.
What it requires
A repeatable risk assessment method, a risk treatment plan (your Statement of Applicability is the output of this), objectives that are measurable and consistent with your policy, and a stated approach to planning significant changes to the ISMS.
How a self-led small team handles it
Don't skip straight to Annex A. Do the risk register first and let it drive which controls you actually need — keep objectives few, specific, and measurable rather than aspirational.
Track Clause 6 directly — itsbestpractice has a dedicated Risk register & Objectives section built around exactly this clause.
Start your ISMS