Our own servers in Europe · GDPR · Support in your language

Module 3 of 7 · ISO 27001 · Clause 6

Planning

Planning in ISO 27001 means analyzing the risk of each asset and deciding, with judgment, which Annex A controls apply and which do not.

Content reviewed on

Risk assessment and treatment

Identify confidentiality, integrity and availability risks for each asset, evaluate them and decide on treatment: accept, mitigate, transfer or avoid.

Statement of applicability

A document justifying which Annex A controls apply and which are excluded, with their implementation status.

Security objectives and planning

Objectives consistent with the policy, measurable, with an action plan: what will be done, with what resources, who is responsible, and how results will be evaluated.

What an auditor usually asks for

  • A security risk matrix with defined treatment
  • An up-to-date statement of applicability (SOA)
  • Security objectives with an indicator, an owner and a date
  • A risk treatment plan with tracking

How to cover planning in Kimobox

  1. 1Log each asset's risk analysis with its treatment and its owner.
  2. 2Keep the statement of applicability linked to evidence for each control.
  3. 3Define security objectives with an indicator and let the system track them.

The statement of applicability stops being a spreadsheet: every control stays linked to its real evidence.

See how objectives and indicators work in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. ISO/IEC 27001:2022 — Information security management systems ISO/IEC · 25 October 2022
  2. ISO/IEC 27002:2022 — Information security controls ISO/IEC · February 2022
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024