Skip to content

Risk Treatment Option

What is Risk Treatment Option?

The different approaches available for addressing a risk, including avoidance, reduction, sharing, transfer, and acceptance.

Risk Management

What the standards actually require on risk treatment option

Requirements naming risk treatment option across 6 standards, quoted from the control text.

Requirement defined in ISO 27005:2022, clause 8.2 (Selecting appropriate information security risk treatment options). See licensed source for normative text.

iso-27005-2022::8.2 · Selecting appropriate information security risk treatment options

Requirement defined in ISO 31000:2018, clause 6.5.2 (Selection of risk treatment options). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_re...

iso-31000-2018::6.5.2 · Selection of risk treatment options

Requirement defined in ISO/IEC 23894:2023, clause 6.5.2 (Selection of risk treatment options). See licensed source for normative text.

iso-iec-23894-2023::6.5.2 · Selection of risk treatment options

Select treatment options including avoidance, modification, sharing, or retention with documented justification.

ISO27557-7.1 · Privacy Risk Treatment Options

Ghana CSA Critical Information Infrastructure (CII) regime (Part III of Act 1038). CII DESIGNATION: CSA Ghana designates CII owners across 13 SECTORS: (1) BANKING + FINANCE; (2) ENERGY (electricity + oil + gas); (3) WATER; (4) TELECOMMUNICATIONS;

GhCSA-CII-Designation-Plan-Audit-Risk · CII Designation, Registration, Cybersecurity Plan, Audit and Risk Assessment

Guidance on the risk assessment process including risk identification, analysis, evaluation, and selection of risk treatment options. Creation of the Statement of Applicability.

ISO27003-6.1 · Actions to Address Risks and Opportunities

Questions people ask about risk treatment option

What is Risk Treatment Option?
The different approaches available for addressing a risk, including avoidance, reduction, sharing, transfer, and acceptance.
Why is Risk Treatment Option important for compliance?
Risk Treatment Option is a key concept in Risk Management. Understanding risk treatment option helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Risk Treatment Option?
Risk Treatment Option appears in the requirement text of ISO 27005:2022, ISO 31000:2018, ISO/IEC 23894:2023, ISO/IEC 27557:2022 - Organisational Privacy Risk Management, Ghana Cybersecurity Act. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Risk Treatment Option?
Explore our compliance framework pages to see how risk treatment option applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Risk Treatment Option applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.