Step 5 of 6 · Do
Plan and implementation Who does what by when.
Risks turn into tasks. Each one gets an owner, a deadline and a status, and that is exactly how it is followed up.

What it is about
Most security projects do not fail at the analysis. They fail because measures sit in meeting notes and nobody follows them up. Under the BSIG, management has to implement the measures and oversee their implementation. For that it needs a list that is accurate.
How you go about it
- For each risk you create one or more measures, or adopt the ones UniqSuite suggests.
- You assign owners, deadlines and priorities.
- The owners update the status themselves and attach evidence directly to the measure.
What UniqSuite does for you
- Whatever is done shows up straight away in the dashboard and the reports. Nobody has to update slides.
- The Statement of Applicability is built from your answers and reasons. You do not have to write it by hand.
What you end up with
The Statement of Applicability, an implementation report and a report for management.
Where the requirements come from
- ISO/IEC 27001, clause 6.1.3: risk treatment plan and Statement of Applicability
- ISO/IEC 27001, clause 8: operation
- BSIG section 38(1): management implements the risk management measures and oversees their implementation
The references show where the requirements come from. They do not replace a legal assessment.
How far along are you with this step?
The quick check shows you in two minutes. Or let us show you UniqSuite with your own questions.
