Zum Hauptinhalt springen
Starter Kit · Register

Risk Treatment Plan

Updated on 2 min Reviewed by: Cenedril-Redaktion
Clause 6.1.3 ISO 27001ISO 27005

The risk treatment plan translates the results of your risk analysis into concrete actions. For every risk above the acceptance threshold, it documents what will be done, who is responsible, and by when implementation must be complete.

ISO 27001 Clause 6.1.3 requires a risk treatment plan that records the chosen treatment options, the associated controls, and the approval of risk owners. Without this plan, risk analysis remains an academic exercise.

What does it contain?

The CSV template bridges the risk register and operational action planning. Key columns:

  • Risk ID — link to the risk register
  • Treatment option — mitigate, avoid, transfer, or accept
  • Control(s) — concrete steps to treat the risk
  • Related Annex A control — which ISO 27001 control is being implemented?
  • Owner and deadline — who implements, by when?
  • Implementation status — planned, in progress, completed
  • Residual risk — the remaining risk after the control is in place

How to use it

Derive it from the risk register. Every risk above the acceptance threshold receives a treatment decision. For the “mitigate” option, you define specific controls — often Annex A controls from ISO 27001. The mapping between risk, treatment option, and control makes the plan traceable.

Monitor implementation. The plan functions as a project management document. Each control has an owner, a deadline, and a status. During the management review, you report progress — overdue controls are a typical audit finding.

Document residual risk. After all controls are implemented, residual risk remains. This residual risk must be assessed and formally accepted by the risk owner. Documenting that acceptance is an explicit requirement of Clause 6.1.3.

Register Template

Risk Treatment Plan

IDRisk IDActionAnnex A ControlOwnerStart DateDue DateBudget (EUR)StatusVerificationResidual Score After
RTP-001R-001Deploy phishing-resistant MFA (FIDO2) for all admin accountsA 5.17 A 8.5IT Operations Lead2026-02-012026-06-308000In progressAudit test Q36
RTP-002R-001Segment backup network and isolate credentialsA 8.12 A 8.20IT Operations Lead2026-03-012026-07-3112000OpenPentest6
RTP-003R-001Quarterly restore test on offline backupA 8.13IT Operations Lead2026-02-01Recurring2000In progressTest log6
RTP-004R-002Roll out FIDO2 keys to all staffA 5.17ISO2026-05-012026-09-3015000OpenCoverage report6
RTP-005R-002Monthly phishing simulation + targeted retrainingA 6.3HR Lead2026-01-01Recurring3000In progressLMS report6
RTP-006R-003Deploy outbound DLP rule for PII in email and webA 8.12ISO2026-04-012026-09-3010000OpenDLP alerts6
RTP-007R-003Implement strict leaver access revocation within 2hA 5.11 A 6.5HR Lead2026-03-012026-06-150In progressAudit sample6
RTP-008R-004Qualify a second logistics SaaS provider as standbyA 5.30 A 5.22Procurement2026-04-012026-12-3120000OpenSupplier review6
RTP-009R-004Monthly supplier status reviewA 5.22Procurement2026-01-01Recurring0In progressReview notes9
RTP-010R-005Implement IaC scanning in CI pipelineA 8.28 A 8.9Head of Engineering2026-03-152026-06-305000In progressPipeline logs6
RTP-011R-005Enable S3 public-access block at account levelA 8.9IT Operations Lead2026-03-012026-04-150CompletedConfig report6

Sources

ISO 27001 Controls Covered

Clause 6.1.3 Information security risk treatment

Frequently asked questions

What treatment options are available?

ISO 27001 defines four options: mitigate (implement controls), avoid (discontinue the risky activity), transfer (e.g. through insurance or outsourcing), and accept (consciously retain the risk if it falls below the acceptance threshold). Each option must be justified and approved by the risk owner.

Does every risk need to appear in the treatment plan?

Every risk from the risk register needs a documented treatment decision. Accepted risks belong in the plan too — with a justification for why they are accepted. Auditors check whether acceptance was conscious and authorised.

How does the risk treatment plan relate to the SoA?

The Statement of Applicability (SoA) lists all Annex A controls and justifies which are applied and which are not. The risk treatment plan references the specific measures — many of which are Annex A controls. The SoA is the overall picture; the plan is the operational implementation.