What are the treatment options under ISO/IEC 27005, and how do we choose?
Information security treatment can avoid the risk by not starting or continuing the activity, remove the risk source, change likelihood, change consequences, share the risk through agreed arrangements, or retain the risk by informed decision. General risk management can also take or increase risk to pursue an opportunity, but ISO/IEC 27005 states that this is not an information security option.
An option can create new risks or modify existing ones. through insurance or a contract depends on the reliability and clarity of the arrangement and can be limited, prohibited, or required by law or regulation. still requires an informed acceptance decision.
- Choose one or more options against the evaluated scenario, acceptance criteria, objectives, requirements, resources, and implementation constraints.
- Determine every control needed for the chosen option, including controls outside ISO/IEC 27001 Annex A when necessary.
- Estimate the expected and repeat assessment or treatment if the remaining risk is not acceptable.
- Example of avoidance: stop operating an office in a flood zone when physical controls cannot reduce the availability risk enough, or choose not to collect information that the organization would otherwise need to protect.
- Example of modification: encryption can reduce the consequence of disclosure even though it does not prevent a laptop from being stolen; backup can reduce the consequence of data loss without preventing the initiating equipment failure.
What are the information security options in ISO/IEC 27005?
Choose one or more of four practical options for the evaluated scenario: avoid the risk by stopping or not starting the activity, modify its likelihood or consequence, share responsibility with another party under an agreed arrangement, or retain it by informed decision. Removing a risk source is one way to modify or eliminate the relevant exposure. Taking or increasing risk to pursue an opportunity belongs to general risk management, not information security under ISO/IEC 27005.
Does ISO/IEC 27005 require every Annex A control?
No. Determine the controls necessary for the chosen treatment and the identified risks, including sector-specific or custom controls where needed. ISO/IEC 27001:2022 then requires a comparison with Annex A as a safety check so no necessary control has been omitted; the comparison is not an instruction to select every Annex A control.
Does insurance or outsourcing remove the risk?
No. distributes responsibility through an agreed arrangement, but the result depends on the arrangement's scope, clarity, reliability, and legal limits. ISO/IEC 27005 says at least one control is still required to modify likelihood or consequence, even when another party implements that control, and the organization must assess and decide on the remaining exposure.
What happens after a treatment option is selected?
Determine every necessary control, compare that set with ISO/IEC 27001 Annex A, update the , create a treatment plan with owners, resources, measures, dates, and status, obtain risk-owner approval, implement and test the controls, reassess residual likelihood and consequence, and decide whether the is acceptable or needs further treatment.
ISO/IEC 27005:2022 defines the treatment options and Clauses 8.2 through 8.6 describe selection, necessary controls, the treatment plan, risk-owner approval, and residual-risk acceptance.