- This source is the governing requirements context for ISO/IEC 27001 scope, control governance, and review cadence in ISMS operations.
"Information security management systems — Requirements"
Use one traceable workflow from assessed risk to treatment option, necessary control, implementation action, residual-risk decision, and approval.
The register supports the risk-treatment plan but does not replace the SoA: keep risk actions and approvals linked to Annex A applicability, exclusions, status, and control evidence.
Structured answer sets in this page tree.
Cited legal and guidance references.
ISO/IEC 27001 requires documented risk-assessment results, a risk-treatment plan, risk-owner approval, acceptance of , and documented treatment results. It does not require a document named 'risk-treatment register.' Use this register format when one controlled record helps connect those required outputs from assessed risk through implementation and review.
Begin with an assessed information security risk, its owner, level, and priority under the organization's documented criteria. Then capture the chosen treatment option, every necessary control, the Annex A completeness comparison, planned actions, owners, resources, target dates, and dependencies. ISO/IEC 27001 requires appropriate treatment options but does not prescribe labels such as reduce, avoid, share, or accept.
After implementation, record results and the recalculated . Close the decision only when the risk owner has approved the treatment plan and accepted the residual risk under the organization's criteria. If implementation is incomplete, the rating exceeds the acceptance criteria, or the risk owner refuses acceptance, keep the record open and revise the treatment, resources, deadline, or escalation.
Stable identifiers are a practical traceability control, not a prescribed ISO field. Use them to connect the assessment, treatment plan, SoA, implementation tickets, operating evidence, effectiveness result, and acceptance when those records live in different systems.
Preserve both planned and actual dates and both pre-treatment and residual ratings. That distinction prevents incomplete actions from appearing as completed risk reduction.
Assign actions, connect necessary controls to the SoA, retain implementation evidence, and record risk-owner approval and residual-risk acceptance.
Create assigned treatment tasks, evidence requests, approval steps, and reassessment checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
The assessor applies the approved method and identifies the risk owner. The organization chooses who proposes treatment and implements controls. Clause 6.1.3 requires the risk owner to approve the treatment plan and accept the ; it does not prescribe a committee, assessor, or control-owner title.
Governance can set thresholds and escalation paths, but it should not erase accountability. A committee approval without a named risk owner does not satisfy the standard's explicit risk-owner approval and acceptance step.
Common failures are using a generic 'security' owner, recording only the target rating, treating planned controls as implemented, or closing treatment without evidence and residual-risk acceptance.
Another failure is limiting controls to Annex A. Necessary controls can be designed by the organization or identified from any source. Annex A is then used to check whether a necessary control was overlooked.
ISO/IEC 27001 requires risk assessment at planned intervals and when significant changes are proposed or occur. Reopen the register entry when that assessment changes the risk result or when scope, assets, suppliers, threats, vulnerabilities, incidents, controls, or implementation evidence invalidate the recorded decision.
Preserve the old rating and approval as history, calculate the current consistently, and route changed treatment or acceptance decisions to the accountable risk owner.
"Information security management systems — Requirements"
"Information security controls"
"Guidance on managing information security risks"