FAQGlobalISO/IEC 27005

ISO/IEC 27005 FAQ Treatment Options

Information security risk treatment can avoid the activity, remove a risk source, change likelihood or consequences, share risk, or retain risk by informed decision. Choose the option, determine necessary controls, assess residual risk, and obtain risk-owner approval.

The standard supplies guidance rather than a mandatory scoring model, legal rule, or standalone certification scheme.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Select for a specific evaluated risk, not from a default control list. ISO/IEC 27005:2022 treats selection, control determination, planning, implementation, effectiveness assessment, residual-risk acceptance, and further treatment as an iterative process.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

What are the treatment options under ISO/IEC 27005, and how do we choose?

Information security treatment can avoid the risk by not starting or continuing the activity, remove the risk source, change likelihood, change consequences, share the risk through agreed arrangements, or retain the risk by informed decision. General risk management can also take or increase risk to pursue an opportunity, but ISO/IEC 27005 states that this is not an information security option.

An option can create new risks or modify existing ones. through insurance or a contract depends on the reliability and clarity of the arrangement and can be limited, prohibited, or required by law or regulation. still requires an informed acceptance decision.

  • Choose one or more options against the evaluated scenario, acceptance criteria, objectives, requirements, resources, and implementation constraints.
  • Determine every control needed for the chosen option, including controls outside ISO/IEC 27001 Annex A when necessary.
  • Estimate the expected and repeat assessment or treatment if the remaining risk is not acceptable.
  • Example of avoidance: stop operating an office in a flood zone when physical controls cannot reduce the availability risk enough, or choose not to collect information that the organization would otherwise need to protect.
  • Example of modification: encryption can reduce the consequence of disclosure even though it does not prevent a laptop from being stolen; backup can reduce the consequence of data loss without preventing the initiating equipment failure.

What are the information security options in ISO/IEC 27005?

Choose one or more of four practical options for the evaluated scenario: avoid the risk by stopping or not starting the activity, modify its likelihood or consequence, share responsibility with another party under an agreed arrangement, or retain it by informed decision. Removing a risk source is one way to modify or eliminate the relevant exposure. Taking or increasing risk to pursue an opportunity belongs to general risk management, not information security under ISO/IEC 27005.

Does ISO/IEC 27005 require every Annex A control?

No. Determine the controls necessary for the chosen treatment and the identified risks, including sector-specific or custom controls where needed. ISO/IEC 27001:2022 then requires a comparison with Annex A as a safety check so no necessary control has been omitted; the comparison is not an instruction to select every Annex A control.

Does insurance or outsourcing remove the risk?

No. distributes responsibility through an agreed arrangement, but the result depends on the arrangement's scope, clarity, reliability, and legal limits. ISO/IEC 27005 says at least one control is still required to modify likelihood or consequence, even when another party implements that control, and the organization must assess and decide on the remaining exposure.

What happens after a treatment option is selected?

Determine every necessary control, compare that set with ISO/IEC 27001 Annex A, update the , create a treatment plan with owners, resources, measures, dates, and status, obtain risk-owner approval, implement and test the controls, reassess residual likelihood and consequence, and decide whether the is acceptable or needs further treatment.

Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 defines the treatment options and Clauses 8.2 through 8.6 describe selection, necessary controls, the treatment plan, risk-owner approval, and residual-risk acceptance.

Question 2

What evidence should support the treatment options decision?

The treatment record should identify the evaluated risk, selected option and rationale, necessary controls, control owners, resources, priorities, target dates, expected effect on likelihood or consequence, expected , dependencies, implementation status, effectiveness measures, and approvals.

  • Compare necessary controls with ISO/IEC 27001:2022 Annex A to verify that no necessary control was omitted, then document the controls and exclusions through the organization's process.
  • Keep design, implementation, operation, and effectiveness evidence distinct; a planned or installed control does not prove that it modifies risk as expected.
  • For sharing, record the agreement, scope, exclusions, counterparty, and remaining exposure. For retention, record the authorized acceptance decision and review conditions.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 8.3 through 8.6 cover necessary controls, comparison with Annex A, the Statement of Applicability, treatment-plan content, approval, and residual-risk acceptance.

Question 3

Who owns and approves treatment options decisions?

The risk owner approves the treatment plan and decides whether is acceptable. Treatment owners implement assigned actions and control owners operate controls. Analysts can estimate expected risk reduction, but they do not replace the risk owner's approval.

  • Assign each action, resource, target date, and effectiveness measure to a named owner.
  • Escalate when exceeds the owner's delegated acceptance level or treatment needs authority across organizational boundaries.
  • Obtain approval again when material changes alter the plan, expected , cost, or completion date.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clause 8.6 and Clause 10.3 distinguish risk-owner approval and acceptance from implementation and communication responsibilities.

Question 4

When should treatment options be reviewed?

Review treatment at planned milestones and when implementation, effectiveness, context, threats, vulnerabilities, controls, criteria, or the scenario changes. If treatment is ineffective or the remains unacceptable, revise the plan or repeat the assessment and treatment process.

  • Measure whether controls operate and modify likelihood or consequence as expected.
  • Trigger review after delays, failed controls, audit findings, incidents, user circumvention, new threats or vulnerabilities, or changed requirements.
  • Record the new and obtain a new acceptance or further-treatment decision.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 5.1, 9.2, 10.7, and 10.8 describe iterative treatment, implementation, effectiveness review, plan revision, and ongoing monitoring.

Primary sources

References and citations

iso.org
Referenced sections
  • Official listing for ISO/IEC 27001:2022, whose risk-treatment requirements include necessary controls, Annex A comparison, a Statement of Applicability, risk-owner approval, and residual-risk acceptance.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 Clauses 5.1, 9.2, 10.7, and 10.8 describe iterative treatment, implementation, effectiveness review, plan revision, and ongoing monitoring.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.