Operational planning and control
Clause 8 requires the organization to plan, implement, and control the processes needed to meet information security requirements. Essentially, it is the "execution" phase where you turn your risk treatment plans and security policies into operational reality and maintain documented proof that these activities are occurring as intended.
What it means
While previous clauses focus on planning (risk assessment and objectives), Clause 8 focuses on delivery. It requires you to establish a consistent way of operating so that security controls are not applied randomly, but through defined processes.
This includes managing any planned changes to your operational environment to ensure they don't introduce new risks. If you outsource parts of your operations (such as cloud hosting or managed security services), you must ensure these external processes remain under your control and meet the same security standards.
In practice, this means moving from "we intend to do X" to "this is how we do X, here is who does it, and here is the record showing it was done."
How to meet it
- Define clear operational processes or Standard Operating Procedures (SOPs) for critical security activities (e.g., user onboarding/offboarding, backup schedules, vulnerability scanning).
- Implement the specific controls identified in your Risk Treatment Plan (from Clause 6), ensuring each is assigned an owner and a timeline.
- Establish a formal change management process to review and approve modifications to systems or processes before they are implemented.
- Create a mechanism for reviewing "unplanned" changes—such as emergency patches or incident responses—to ensure the security posture remains intact after the event.
- Define clear requirements for outsourced providers and establish a cadence for monitoring their performance against those requirements.
- Maintain documented information (logs, checklists, tickets) to prove that your defined processes are actually being followed in daily operations.
Evidence an auditor asks for
- Documented process maps or SOPs showing how security requirements are integrated into operational workflows.
- A completed Risk Treatment Plan showing that planned actions have been implemented and verified.
- Change management logs or tickets demonstrating a review/approval cycle for system changes.
- Records of third-party service reviews or performance reports from outsourced providers.
- Operational logs (e.g., backup success logs, patch management reports) proving processes are running as scheduled.
Common pitfalls
- Confusing "Planning" with "Operational Control": Having a policy that says you *will* do backups is planning; having the daily logs showing those backups actually happened is operational control.
- Ignoring unplanned changes: Failing to document the security review conducted after an emergency fix or workaround was applied.
- Lack of evidence for outsourced controls: Assuming a vendor's SOC2 report is enough without demonstrating how the organization actively monitors that vendor's adherence to specific requirements.