Skip to content

Risk Treatment

Definition

The process of selecting and implementing options to modify risk. ISO/IEC 27005 defines four treatment options: accept, avoid, mitigate (reduce), and transfer (share). The selected option and its rationale must be documented and approved.

Standard
ISO/IEC 27005
Options
Accept, avoid, mitigate, transfer
Also called
Risk treatment options or risk response
Requirement
Chosen option and rationale must be documented and approved

Common questions

What is the difference between mitigating and transferring a risk?+

Mitigation reduces the likelihood or impact through a control implemented by the organisation itself, such as encryption or access restrictions. Transfer shifts the financial or operational consequence to a third party, typically through insurance or a contractual clause with a vendor.

When is accepting a risk the appropriate choice?+

Acceptance is appropriate when the cost of further treatment exceeds the potential loss, or when the risk falls within the organisation's stated risk appetite. It still requires sign-off from an owner with the authority to accept that level of exposure.

Can more than one treatment option be applied to the same risk?+

Yes. A common pattern is to mitigate a risk with technical controls and transfer the remaining exposure through insurance, then accept whatever residual risk is left after both are applied.

Related terms

Residual Risk
The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management...
Risk Appetite
The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
Risk Owner
The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
Risk Register
A structured record of all identified risks, each with its description, inherent risk score, owner, treatment decision, controls selected, residual risk score,...
Statement of Applicability (SoA)
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.