ISO 27001 risk treatment plan
The risk treatment plan is where the assessment becomes action. Here's how to apply the four Ts, map each risk to Annex A controls, and produce a plan auditors actually accept.
The risk treatment plan is where the assessment becomes action. Here's how to apply the four Ts, map each risk to Annex A controls, and produce a plan auditors actually accept.
ISO 27001 clause 6.1.3 says: for every unacceptable risk identified in your assessment, choose a treatment option, determine the controls needed, compare those controls to Annex A, produce a Statement of Applicability, and get the risk owners to approve the plan and accept the residual risk. The risk treatment plan is the document that ties all of that together.
Risk: Phishing of staff credentials leads to account takeover (inherent 5×4 = 20).
Treatment: Treat. Driver is likelihood.
Annex A controls: A.5.17, A.8.5, A.6.3 (information security awareness), A.8.16 (monitoring activities).
Owner: Head of IT. Target residual: 2×3 = 6. Due: 90 days. Residual accepted by: CISO.
ISO-STANDARD.app links every risk to Annex A controls, treatment decisions, owners and target residual scores in one place — and exports the treatment plan and Statement of Applicability auditors expect.
ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.