ISO 27001 Clause 8.1 - Operational planning and control
This clause is very easy to demonstrate evidence against if the organisation has already 'showed its workings.' In developing the information security management system (ISMS) to comply with requirements 6.1, 6.2 and in particular 7.5 where the whole ISMS is well structured and documented, this also achieves 8.1 at the same time.
It is about planning, implementation and control to ensure the outcomes of the information security management system are achieved.
Smart organisations going through their planning and early implementation of the information security management system with ISO 27001 certification in mind will also conduct management reviews in line with clause 9.3. We recommend these management reviews for information security happen weekly in the early stages to maintain momentum and build the habit, then stabilise to less frequent periods after the stage 1 audit.
Whilst not all the 9.3 standard agenda items can be demonstrated during implementation, administrators can note what has been achieved, what is planned next. It will give independent auditors confidence the organisation is planning well, showing consideration to its spirit of the standard as well as practicing management reviews too.