ISO 27001 clause guide

ISO 27001 Clause 6.1.3: Information security risk treatment

Define how evaluated risks will be modified, retained, avoided or shared, select necessary controls and document the resulting treatment decisions. This guide explains how to turn the clause into decisions, operating evidence and a defensible audit trail.

Clause
6.1.3
Theme
Planning
Primary outcome
Select, justify, own and track treatments, compare necessary controls with Annex A and maintain the Statement of Applicability.

What Clause 6.1.3 means in practice

Select, justify, own and track treatments, compare necessary controls with Annex A and maintain the Statement of Applicability. Treat the clause as part of a management system rather than an isolated document request. Its outputs should influence connected decisions, and later records should show that those decisions were carried out.

The level of formality should match risk and complexity. What matters is clarity, consistency and a traceable connection between the organization’s circumstances, chosen approach and observed result.

Step-by-step implementation

  1. Step 1. Choose treatment options appropriate to each priority risk.
  2. Step 2. Determine necessary controls and compare them with Annex A to check that relevant control areas were considered.
  3. Step 3. Maintain a Statement of Applicability showing applicable controls, implementation status and rationales.
  4. Step 4. Create a treatment plan, obtain risk-owner approval and record residual-risk acceptance.
  5. Final step. Test a recent example, record the result and improve weak handoffs or decisions.

Ownership

  • Risk owners
  • Control owners
  • ISMS manager

Evidence and records

Implementation evidence

  • risk treatment methodology and plan
  • Statement of Applicability
  • control selection rationale
  • risk-owner approvals
  • residual-risk decisions

Effectiveness evidence

  • treatments completed and residual risk reassessed
  • Statement of Applicability decisions match implemented controls and current risk

A document can show intent. A complete sample also shows who made the decision, what happened next, whether the result was reviewed and how exceptions were handled.

How an auditor may test Clause 6.1.3

  1. Select a current business or ISMS example affected by the clause.
  2. Confirm the method, criteria, owner and required output.
  3. Trace the example through its decision records and connected processes.
  4. Corroborate the record with operational evidence or participant interviews.
  5. Follow an exception, change or adverse result to its accountable conclusion.
  6. Check that review and improvement occur when circumstances or results change.

Questions to prepare for

  • How were treatment options selected?
  • Show how the Statement of Applicability connects to risk treatment.
  • How are control inclusions and exclusions justified?
  • Who accepted residual risk and on what basis?

Worked example

A high supplier-access risk is reduced through contractual duties, restricted privileged access and monitoring, with residual risk approved by the owner.

A strong audit trail would identify the trigger, relevant information, accountable participants, decision, resulting actions and later verification. It should be possible to explain why the approach was reasonable without reconstructing it from memory.

Smaller and mature implementation approaches

Smaller organization

Use existing leadership, service-management or risk meetings, assign a named owner and retain concise decision records. Avoid parallel governance where an established process can produce the required outcome.

Mature or complex organization

Define group-wide criteria, delegated accountabilities, integrated workflow, quality checks and consolidated performance reporting while preserving local context and evidence.

Practical implementation checklist

  • □ Choose treatment options appropriate to each priority risk.
  • □ Determine necessary controls and compare them with Annex A to check that relevant control areas were considered.
  • □ Maintain a Statement of Applicability showing applicable controls, implementation status and rationales.
  • □ Create a treatment plan, obtain risk-owner approval and record residual-risk acceptance.
  • □ A recent example has been traced through its connected ISMS processes.
  • □ Weak results and overdue actions have accountable follow-up.

Common mistakes

  • selecting Annex A controls without considering risk
  • allowing the SoA and treatment plan to diverge
  • weak or missing exclusion rationale
  • treating control implementation as automatic risk acceptance

Frequently asked questions

Must every Annex A control be implemented?

No. Necessary controls follow risk and requirements; applicability decisions and justification are recorded.

Can controls come from outside Annex A?

Yes. Organizations may design or use other controls where needed.

What should a treatment plan contain?

Actions, owners, target dates, resources, selected controls and a method for evaluating residual risk.

Explore the clause in the interactive tool

Open Clause 6.1.3 in the free explainer to browse its connected clauses and implementation prompts.

Open Clause 6.1.3 in the clause explainer →