Risk Treatment
Definition
The process of selecting and implementing options to modify risk. ISO/IEC 27005 defines four treatment options: accept, avoid, mitigate (reduce), and transfer (share). The selected option and its rationale must be documented and approved.
- Standard
- ISO/IEC 27005
- Options
- Accept, avoid, mitigate, transfer
- Also called
- Risk treatment options or risk response
- Requirement
- Chosen option and rationale must be documented and approved
Common questions
What is the difference between mitigating and transferring a risk?+
Mitigation reduces the likelihood or impact through a control implemented by the organisation itself, such as encryption or access restrictions. Transfer shifts the financial or operational consequence to a third party, typically through insurance or a contractual clause with a vendor.
When is accepting a risk the appropriate choice?+
Acceptance is appropriate when the cost of further treatment exceeds the potential loss, or when the risk falls within the organisation's stated risk appetite. It still requires sign-off from an owner with the authority to accept that level of exposure.
Can more than one treatment option be applied to the same risk?+
Yes. A common pattern is to mitigate a risk with technical controls and transfer the remaining exposure through insurance, then accept whatever residual risk is left after both are applied.
Related terms
- Residual Risk
- The risk that remains after controls are applied. If residual risk exceeds the organisation's risk appetite, further treatment is required or management...
- Risk Appetite
- The amount and type of risk an organisation is willing to accept in pursuit of its objectives, as defined by its governing...
- Risk Owner
- The individual or role accountable for ensuring a risk is treated appropriately and that the treatment remains effective. Owners should control the...
- Risk Register
- A structured record of all identified risks, each with its description, inherent risk score, owner, treatment decision, controls selected, residual risk score,...
- Statement of Applicability (SoA)
- A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...