“The organization shall perform information security risk assessments at planned intervals or when significant changes are proposed or occur, taking account of the criteria established in 6.1.2 a).”ISO/IEC · ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · 2022 · ISO/IEC 27001:2022, clauza 8.2 «Information security risk assessment», prima propoziție
Clause 6 writes the method, clause 8 proves it was used.
Clause 8 is where the system actually runs. At 8.1 the organization plans, implements and controls the processes needed to meet requirements and to implement the actions determined in clause 6, retains documented information showing the processes were carried out as planned, controls planned changes and reviews the consequences of unintended ones. This is also where outsourcing sits: externally provided processes, products or services relevant to the system must be determined and controlled. They do not have to be certified, they have to be controlled. The classic exam confusion is between 6.1.2 and 8.2. The first requires that a risk assessment process exist, defined and applied; the second requires that the process actually be run, at planned intervals and on significant changes, with the results retained. The same pair exists for treatment: 6.1.3 defines the process, while 8.3 requires the plan to be implemented and the results to be retained.
Why it matters A flawless clause 6 file with no clause 8 evidence describes a system that was designed, not one that runs.