Skip to content

Risk Treatment Plan

Definition

A document that records, for each identified risk, the chosen treatment option (accept, avoid, transfer, or reduce), the specific controls selected to reduce it, the asset owner responsible, and the target completion date. It is the direct input to the SoA.

Records per risk
Treatment option, selected controls, asset owner, target date
Direct input to
Statement of Applicability (SoA)
Source document
Derived from the risk register
Owner
Asset owner responsible for the risk

Common questions

How does the treatment plan connect to the Statement of Applicability?+

Each control selected in the treatment plan is cross-referenced against the ISO 27001 Annex A control set, and the SoA records which controls are applicable, implemented, or excluded with justification, built directly from these entries.

Why does each entry need a target completion date rather than just a control description?+

Without a date, treatment items tend to stall indefinitely. The date lets internal audit and management review track whether risk reduction is actually happening on schedule.

Who approves the risk treatment plan before it becomes binding?+

Typically senior management or the risk owner with budget authority, since implementing the selected controls usually requires resourcing decisions beyond the risk assessor's authority.

Related terms

Annex a
The normative annex to ISO/IEC 27001 that lists 93 information security controls across four themes: organisational (37 controls), people (8), physical (14),...
Continual Improvement
The ISO/IEC 27001 requirement (clause 10) that the organisation must actively improve the suitability, adequacy, and effectiveness of the ISMS over time....
ISMS Scope
The explicit boundaries of the management system: which organisational units, sites, processes, and information assets are covered. Defined under ISO/IEC 27001 clause...
Management Review
The annual governance meeting required under ISO 17025 Clause 8.9, at which laboratory management reviews the aggregated quality performance data (PT results,...
Statement of Applicability (SoA)
A mandatory document listing every ISO/IEC 27001 Annex A control with a statement of whether it is included or excluded, the justification...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.