ISO 27001 8.1 Operational planning and control
ISO 27001 Section 8.1 – Operational planning and control
To meet the requirements for 8.1 around operational planning and control, it is necessary to plan how the ISMS will operate and how it will be controlled through the process lifecycle.
The evidence retained should demonstrate that the processes described have been implemented and are being controlled in order to meet the information security objectives as planned.
In order to meet the information security objectives noted in Sect 6.2. of the standard, actions should be implemented as determined by the documented information security risk assessment process, and the treatment thereafter in accordance with that process (section 6.1).