Clause 6.1.3 Information security risk treatment
Clause 6.1.3 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Information security risk treatment. The organization must define and use a risk treatment process to choose suitable treatment options in light of the assessment results; determine every control needed to implement the chosen options (controls can be designed or taken from any source); compare those controls with Annex A to check nothing necessary has been left out (Annex A lists possible controls and is not exhaustive); produce a Statement of Applicability listing the necessary controls, why each is included, whether each is implemented, and why any Annex A control is excluded; draw up a risk treatment plan; and get risk owners to approve the plan and accept the residual risks. Documented information about the process must be retained. The process aligns with the principles and guidelines of ISO 31000.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 6.1.3 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 6), in our words, not a statement of the standard and not binding on an assessor.
- A risk treatment plan showing the option chosen and the controls determined for each risk
- The Statement of Applicability listing necessary controls, inclusion justifications, implementation status and justifications for each excluded Annex A control
- Evidence of the comparison of determined controls with Annex A
- Risk owner approval of the treatment plan and signed acceptance of residual risks