Step 4 · Risks
Risk treatment Reduce, avoid, transfer or accept.
For every assessed risk you decide what happens. The result is the risk treatment plan – with measures, owners and deadlines.
What it is about
ISO/IEC 27001 clause 6.1.3 requires you to select treatment options, determine the necessary controls and compare them with Annex A so that no necessary control is overlooked. Risk owners approve the plan and accept the residual risks. Clause 8.3 requires the plan to be implemented and the results documented.
- before treatment
- after
Sample values
How to go about it
- 01
Choose an option for each risk.
- 02
Define controls and compare them with Annex A.
- 03
Assign owners and deadlines.
- 04
Have risk owners accept the residual risks.
Common mistakes
- Risks are “accepted” without anyone with authority agreeing.
- Measures have no deadline and no owner.
- Residual risk is not reassessed after implementation.
What an auditor wants to see
- Risk treatment plan
- Approval and acceptance of residual risk by risk owners
- Evidence of implementation
How UniqSuite helps
In UniqSuite you choose the treatment directly on the risk. Measures go into the plan with owners and deadlines and show up on the dashboard.
References
- ISO/IEC 27001, clauses 6.1.3 and 8.3
- Section 38(1) BSIG: implementation and oversight by management
Frequently asked questions
Can we accept a high risk?
Yes, if it is done consciously, with a justification and the agreement of the responsible management. Under NIS2 your measures must still be appropriate overall.
What does risk transfer mean?
For example insurance or outsourcing to a provider. Accountability for information security stays with you.
Can we choose controls that are not in Annex A?
Yes. According to the notes to clause 6.1.3, Annex A is not exhaustive and additional controls can be included. The comparison with Annex A is only there to make sure nothing necessary is missing.
How does the plan relate to the Statement of Applicability?
The controls from the treatment plan appear in the SoA with justification and implementation status. When the plan changes, update the SoA.
May costs play a role?
Yes. Section 30(1) BSIG explicitly names the cost of implementation as a criterion of proportionality, alongside risk exposure, size, the likelihood and severity of incidents and their societal and economic impact. Record the trade-off in writing.
See what this looks like in UniqSuite.
In half an hour we walk you through it with your own questions.
