- ISO/IEC 27001:2022 states that Annex A controls are possible controls, are not exhaustive, and do not prevent additional necessary controls.
"Information security management systems — Requirements"
For every prioritized risk, choose avoidance, modification, retention, sharing, or a justified combination. Then record the necessary controls, owners, actions, resources, timing, measures, expected residual risk, and approval.
For an ISO/IEC 27001:2022 ISMS, compare necessary controls with Annex A as a completeness check and keep the treatment plan consistent with the Statement of Applicability.
Structured answer sets in this page tree.
Cited legal and guidance references.
ISO/IEC 27005:2022 gives guidance for managing information security risk; it does not prescribe this template. For an ISMS based on ISO/IEC 27001:2022, clause 6.1.3 requires the organization to formulate an information security and obtain risk-owner approval of the plan and acceptance of the residual information security risks. Start with the prioritized assessment results. Select a treatment option for each risk, determine every control needed to carry it out, compare those controls with ISO/IEC 27001:2022 , and record the work as an approved risk treatment plan. Include accountable and responsible people, actions, resources, dependencies, milestones, performance indicators, monitoring, implementation status, expected , and the later effectiveness check. Use Annex A to check for omissions; select controls because they are necessary for the risk.
The plan should connect every risk that needs treatment to a chosen option and the work required to meet the organization's acceptance criteria. ISO/IEC 27005:2022 recognizes avoidance, modification, retention by informed choice, and sharing. Different risks can use different plans, but together the plans should cover every prioritized risk selected for treatment. The standard does not set one required form: an organization can use several plans organized by location, asset, event, or another workable grouping.
ISO/IEC 27005 distinguishes two useful views. The project view schedules implementation and becomes a historical record after delivery. The design view explains how preventive, detective, and corrective controls interact with the environment and with each other, so it remains useful for monitoring and later reassessment.
Identify the risk, assessment version, , selected option, rationale, necessary controls, and the link to the where ISO/IEC 27001 applies. For each action, distinguish the risk owner who approves the plan and decides on from the person responsible for implementation.
Assign implementation owners, retain delivery and effectiveness evidence, reassess residual risk, and set review triggers.
Select the treatment option from the evaluated risk and expected cost and benefit. Determine the controls needed from appropriate sources, including sector-specific and custom controls. Check each control's effect on consequence or likelihood and remove controls that do not contribute to the treatment decision.
Make the option concrete. ISO/IEC 27005 gives closing a flood-exposed office and choosing not to collect certain personal information as examples of avoidance. Modification can reduce likelihood or consequence. Sharing can use insurance or a contract, but at least one control still modifies the risk and the organization retains accountability for its decision.
Do not equate selecting an control with completing treatment. Annex A is a reference set for the completeness comparison. Necessary controls can come from other standards or be custom, and an Annex A control is not necessary for a particular risk merely because it already operates in the organization.
Review delivery against milestones and indicators throughout implementation. ISO/IEC 27005 sets no universal annual treatment-plan deadline. ISO/IEC 27001:2022 requires risk assessments at planned intervals and when significant changes are proposed or occur. Reassess after effectiveness testing and when a missed milestone, failed test, incident, new threat or vulnerability, changed requirement, cost or resource constraint, scope change, or control dependency invalidates the plan or expected .
"Information security management systems — Requirements"
"Guidance on managing information security risks"