ISO 27001 practical guide
ISO 27001 Risk Treatment Plan
A risk treatment plan converts an assessed risk into an approved response with controls, actions, owners, resources, target dates and a method for evaluating residual risk. It should let management see what will change, why it matters, who is accountable and how completion will be verified.
- Search intent
- Turn assessed risks into accountable and verifiable treatment work.
- Guide area
- Risk
- Review status
- Practitioner reviewed
What this means in practice
A risk register may contain the scenario and assessment. The treatment plan manages delivery. The Statement of Applicability records control applicability and status. Combining them in one governed system is possible, but each decision must remain clear.
Treatment completion is not the same as residual-risk approval. Verify the action, evaluate whether the control works and then obtain the appropriate owner decision.
Step-by-step implementation
- Step 1. Select a treatment option that fits risk criteria and business context.
- Step 2. Identify controls needed to achieve the intended risk change.
- Step 3. Break the treatment into verifiable actions rather than broad intentions.
- Step 4. Assign accountable owner, contributors, resources and target date.
- Step 5. Define completion evidence and a measure of effectiveness.
- Step 6. Reassess residual risk after implementation and testing.
- Step 7. Record approval, accepted exceptions and ongoing monitoring.
What to prepare
- prioritized risk assessment
- treatment criteria and decision authority
- control design and SoA references
- delivery dependencies, cost and resources
- completion and effectiveness evidence
Documents, records and evidence
| Area or field | Example | Why it matters |
|---|---|---|
| Risk | Administrator compromise affecting production | Traceable risk identifier |
| Option and controls | Reduce; privileged access, authentication and monitoring | Coherent response |
| Action | Implement separate admin identities and quarterly review | Verifiable delivery |
| Owner/date | Platform director; 30 September | Accountability |
| Completion evidence | Configuration export, approvals and first review results | Proof beyond status text |
| Residual decision | Reassessed and approved by risk owner | Formal conclusion |
Strong treatment action
“Improve access security” is not testable. A stronger action states which production platforms are covered, requires separate privileged identities and MFA, names the accountable owner, sets a date, identifies evidence, and requires a sample review before residual-risk approval.
What an auditor will look for
- Treatments selected from assessed and prioritized risks.
- Actions with accountable owners, resources, dates and evidence.
- Consistent SoA status and control implementation.
- Residual-risk evaluation and approval after effectiveness testing.
An auditor may select different samples or follow unexpected evidence. Prepare authoritative records and owners who can explain normal operation, exceptions and improvement rather than rehearsed answers.
Common mistakes
- Using control names as actions without describing work.
- Closing treatments when technology is purchased but not adopted.
- Letting overdue dates pass without risk-based escalation.
- Approving residual risk before implementation evidence exists.
Practical checklist
- □ Every treatment links to a current risk and decision.
- □ Actions are specific, owned, resourced and time-bound where useful.
- □ Selected controls reconcile with the SoA.
- □ Completion evidence and effectiveness criteria are defined.
- □ Residual risk is reassessed and approved by appropriate authority.
Frequently asked questions
Can one treatment address several risks?
Yes, provided the affected risks, expected effect and residual decisions remain traceable.
Is accepting a risk a treatment plan?
Acceptance is a decision under defined criteria; retain owner approval and monitoring or review triggers.
Should completed actions be deleted?
No. Retain history needed to explain the decision, implementation and residual-risk conclusion.
Continue through the practical guide library
Use the topic hub to connect this task with related implementation, risk, governance, evidence and audit-preparation guidance.