Risk Treatment Plan
What is Risk Treatment Plan?
A documented plan specifying the actions, resources, timelines, and responsibilities for implementing risk treatment measures.
Frameworks that govern risk treatment plan
What the standards actually require on risk treatment plan
Requirements naming risk treatment plan across 6 standards, quoted from the control text.
Requirement defined in ISO 27005:2022, clause 8.6.1 (Formulation of the risk treatment plan). See licensed source for normative text.
iso-27005-2022::8.6.1 · Formulation of the risk treatment plan →Requirement defined in ISO 31000:2018, clause 6.5.3 (Preparing and implementing risk treatment plans). See licensed source for normative text.
iso-31000-2018::6.5.3 · Preparing and implementing risk treatment plans →Requirement defined in ISO/IEC 23894:2023, clause 6.5.3 (Preparing and implementing risk treatment plans). See licensed source for normative text.
iso-iec-23894-2023::6.5.3 · Preparing and implementing risk treatment plans →Implement the information security risk treatment plan and retain evidence of results.
27003-8.3 · Risk Treatment Implementation →The management review shall consider the status of actions from previous reviews, changes in external and internal issues relevant to the management system, changes in the needs and expectations of interested parties, feedback on information security performan...
iso-27001-2022::9.3.2 · Management review inputs →The requirement of ISO/IEC 27001 to implement the risk treatment plan applies to the PIMS, so the privacy controls chosen during treatment must actually be implemented and their implementation evidenced.
iso-27701-2019::5.6.3 · Information security risk treatment →Questions people ask about risk treatment plan
What is Risk Treatment Plan?
Why is Risk Treatment Plan important for compliance?
Which compliance frameworks address Risk Treatment Plan?
Where can I learn more about Risk Treatment Plan?
See how Risk Treatment Plan applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.