- IAF confirms that the 2022 reference set contains 93 controls in four clauses and explains the Annex A completeness comparison.
"93 controls in 4 clauses"
ISO/IEC 27001 risk treatment selects options and necessary controls for assessed risks, produces the SoA and treatment plan, and ends with risk-owner approval of the plan and acceptance of residual information security risks.
Separate the initial approval from later implementation evidence. Clause 8 requires the treatment plan to be implemented and its results retained; monitoring and reassessment then show whether the remaining risk still meets the organization's criteria.
Structured answer sets in this page tree.
Cited legal and guidance references.
Start with an assessment performed under the organization's maintained risk criteria. Clause 6.1.3 then requires appropriate treatment options, all necessary controls, an Annex A completeness check, the Statement of Applicability (SoA), a treatment plan, and risk-owner approval and . ISO/IEC 27001 does not prescribe a treatment taxonomy or acceptance form; the record must be sufficient to demonstrate the required decision and support later operation, monitoring, and reassessment.
Start with an assessment process that maintains risk-acceptance and assessment criteria and produces consistent, valid, and comparable results. For each in-scope information-security risk, identify the risk owner, assess potential consequences and realistic likelihood, determine the risk level, compare it with the criteria, and prioritize treatment.
Select an appropriate treatment option based on the assessment and determine every control necessary to implement it. ISO/IEC 27001 leaves the option taxonomy to the organization. Guidance such as ISO/IEC 27005 can help define options and methods, but it does not replace the Clause 6.1.3 requirements.
Compare those necessary controls with Annex A to verify that none were overlooked. Annex A is a reference check, not the only source of controls and not an instruction to implement all 93 controls. The organization can design controls or select them from other sources when needed.
Record the necessary controls, inclusion justifications, implementation status, and Annex A exclusion justifications in the SoA. Formulate the treatment plan, then obtain the risk owners' approval of the plan and acceptance of the residual information security risks.
The required records are the risk-assessment and treatment processes, assessment results, SoA, treatment plan, risk-owner approval and acceptance, and treatment results. A practical decision record can link these items to the assessed scenario, criteria, necessary controls, implementation actions, monitoring results, and current residual-risk evaluation.
Keep planned treatment separate from implemented treatment. Clause 6.1.3 requires approval of the plan and acceptance of residual risks, while Clause 8.3 separately requires implementation and retained treatment results. If the initial acceptance assumes planned controls, state that assumption and require a post-implementation review instead of presenting the controls as already effective.
Track risk criteria, treatment decisions, necessary controls, plan approval, implementation results, residual-risk acceptance, monitoring, and reassessment without confusing planned controls with operating controls.
Convert ISO/IEC 27001 Risk Treatment and Residual Risk into accountable tasks, evidence requests, and review checkpoints.
Review your ISO/IEC 27001 risk treatment scope, residual-risk evidence gaps, and next implementation steps.
Use a linked workflow: assess under maintained criteria, choose the treatment option, determine necessary controls, compare them with Annex A, produce or update the SoA, formulate and approve the plan, record , implement the plan, retain treatment results, monitor the controls and risk, and reassess when required.
Keep mandated and assigned roles clear. The risk owner approves the treatment plan and accepts residual risk. The organization assigns who implements controls, maintains ISMS records, monitors results, and escalates decisions. Top management remains responsible for ISMS leadership, resources, and management review.
A treatment decision is incomplete when a risk register names an option without the required treatment plan and SoA, or when an SoA reports a control as implemented without support from actual treatment results and operating evidence.
An organization can accept residual risk when approving the treatment plan, but it must not describe planned controls as already operating. Record assumptions and conditions, implement the plan under Clause 8.3, evaluate the result, and reopen the decision if the remaining risk does not meet the criteria.
Copying all Annex A controls into a checklist does not satisfy Clause 6.1.3. Determine necessary controls from the chosen treatment first, use Annex A to check completeness, and justify excluded Annex A controls. Exclusion from the SoA does not cancel a legal, regulatory, contractual, or other relevant interested-party requirement.
Clause 8.2 requires information-security risk assessments at planned intervals and when significant changes are proposed or occur. Supplier changes, incidents, control failures, new threats, scope changes, or changed legal and contractual requirements are possible triggers when they are significant to the scoped ISMS.
If reassessment shows that the remaining risk no longer meets the maintained acceptance criteria, select or revise treatment, update necessary controls and the SoA as applicable, revise the treatment plan, obtain the required risk-owner approval and acceptance, and retain the new assessment and treatment results.
"93 controls in 4 clauses"
"when significant changes are proposed or occur"
"Information security controls"
"Guidance on managing information security risks"