Control Mapping Readerplace a control, see the map

Clause 6.1.3 Information security risk treatment

Clause 6.1.3 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.

The control as we hold it

Information security risk treatment. The organization must define and use a risk treatment process to choose suitable treatment options in light of the assessment results; determine every control needed to implement the chosen options (controls can be designed or taken from any source); compare those controls with Annex A to check nothing necessary has been left out (Annex A lists possible controls and is not exhaustive); produce a Statement of Applicability listing the necessary controls, why each is included, whether each is implemented, and why any Annex A control is excluded; draw up a risk treatment plan; and get risk owners to approve the plan and accept the residual risks. Documented information about the process must be retained. The process aligns with the principles and guidelines of ISO 31000.

Reviewed and closest counterparts in the other frameworks

We hold no cross-framework row for Clause 6.1.3 yet. The reviewed pairs page lists the released pairs and their coverage.

What an auditor commonly asks for

General guidance for this control area (domain: Clause 6), in our words, not a statement of the standard and not binding on an assessor.

Buy the reviewed crosswalk pair Place your own control