Practical toolGlobalISO/IEC 27005

ISO/IEC 27005 Risk Treatment Plan Template

For every prioritized risk, choose avoidance, modification, retention, sharing, or a justified combination. Then record the necessary controls, owners, actions, resources, timing, measures, expected residual risk, and approval.

For an ISO/IEC 27001:2022 ISMS, compare necessary controls with Annex A as a completeness check and keep the treatment plan consistent with the Statement of Applicability.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27005:2022 gives guidance for managing information security risk; it does not prescribe this template. For an ISMS based on ISO/IEC 27001:2022, clause 6.1.3 requires the organization to formulate an information security and obtain risk-owner approval of the plan and acceptance of the residual information security risks. Start with the prioritized assessment results. Select a treatment option for each risk, determine every control needed to carry it out, compare those controls with ISO/IEC 27001:2022 , and record the work as an approved risk treatment plan. Include accountable and responsible people, actions, resources, dependencies, milestones, performance indicators, monitoring, implementation status, expected , and the later effectiveness check. Use Annex A to check for omissions; select controls because they are necessary for the risk.

Section 1

What should an ISO/IEC 27005 risk treatment plan contain?

The plan should connect every risk that needs treatment to a chosen option and the work required to meet the organization's acceptance criteria. ISO/IEC 27005:2022 recognizes avoidance, modification, retention by informed choice, and sharing. Different risks can use different plans, but together the plans should cover every prioritized risk selected for treatment. The standard does not set one required form: an organization can use several plans organized by location, asset, event, or another workable grouping.

ISO/IEC 27005 distinguishes two useful views. The project view schedules implementation and becomes a historical record after delivery. The design view explains how preventive, detective, and corrective controls interact with the environment and with each other, so it remains useful for monitoring and later reassessment.

  • Option and rationale: state why the option was chosen, the expected benefit, constraints, affected parties, and the consequence or likelihood it is intended to change.
  • Necessary controls: choose controls from any suitable source or design custom controls, then check what each control does to the specific risk.
  • Target state: state the expected residual consequence, likelihood, and level, the criteria it is expected to meet, and any temporary exposure before full effectiveness.
Section 2

Which records make the treatment plan reviewable?

Identify the risk, assessment version, , selected option, rationale, necessary controls, and the link to the where ISO/IEC 27001 applies. For each action, distinguish the risk owner who approves the plan and decides on from the person responsible for implementation.

  • Delivery: proposed actions, resources and contingencies, dependencies and sequencing, constraints, start and completion dates, priority, implementation status, cost level, and reporting cadence.
  • Effectiveness: performance indicators, implementation checks, operating-effectiveness tests, evidence owner, test date, tolerance or success criterion, and follow-up assessment.
  • Decision control: plan version, risk-owner approval, expected and assumptions, acceptance status, conditions, monitoring indicators, review date, and change history.
Section 3

How should teams formulate, approve, and implement the plan?

Select the treatment option from the evaluated risk and expected cost and benefit. Determine the controls needed from appropriate sources, including sector-specific and custom controls. Check each control's effect on consequence or likelihood and remove controls that do not contribute to the treatment decision.

Make the option concrete. ISO/IEC 27005 gives closing a flood-exposed office and choosing not to collect certain personal information as examples of avoidance. Modification can reduce likelihood or consequence. Sharing can use insurance or a contract, but at least one control still modifies the risk and the organization retains accountability for its decision.

  • Select: the and assessor choose avoidance, modification, retention, sharing, or a justified combination from the evaluated scenario, cost, benefit, urgency, and affected-party context.
  • Determine controls: control owners and specialists identify controls with more than a negligible effect on the risk, including custom or sector controls, and state whether each changes likelihood, consequence, or both.
  • Check completeness: compare the necessary controls for each risk with ISO/IEC 27001:2022 to find omissions; do not add a control only because it appears in Annex A or already exists.
  • Plan and approve: the plan owner sequences dependencies, resources, measures, contingencies, dates, reporting, and status; the is updated; the approves the plan.
  • Implement and decide: implementation owners retain delivery and effectiveness results, the assessor reassesses residual consequence and likelihood, and the authorized accepts the , adds conditions, escalates, or returns it for further treatment.
Section 4

Which treatment-planning mistakes should teams avoid?

Do not equate selecting an control with completing treatment. Annex A is a reference set for the completeness comparison. Necessary controls can come from other standards or be custom, and an Annex A control is not necessary for a particular risk merely because it already operates in the organization.

  • Risk sharing can delegate control implementation or share consequences, but it does not transfer the 's accountability for the remaining decision.
  • A project plan that ends at deployment is incomplete without effectiveness measures, follow-up assessment, residual-risk acceptance, and monitoring.
  • Do not assume every control must operate at maximum effectiveness; define the effectiveness needed for the risk to meet the acceptance criteria and verify that result.
Section 5

When should the treatment plan be reviewed?

Review delivery against milestones and indicators throughout implementation. ISO/IEC 27005 sets no universal annual treatment-plan deadline. ISO/IEC 27001:2022 requires risk assessments at planned intervals and when significant changes are proposed or occur. Reassess after effectiveness testing and when a missed milestone, failed test, incident, new threat or vulnerability, changed requirement, cost or resource constraint, scope change, or control dependency invalidates the plan or expected .

  • The implementation owner updates action evidence and status; the reviews whether the plan still modifies the risk as intended.
  • When the treatment changes, repeat the necessary-control and completeness checks and update the where applicable.
  • After implementation, record measured control effectiveness and the follow-up residual assessment before renewing, changing, or rejecting acceptance.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO/IEC 27001:2022 states that Annex A controls are possible controls, are not exhaustive, and do not prevent additional necessary controls.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 clauses 5.2, 8.6.3, 9.2, and 10.5 ground implementation review, effectiveness assessment, residual-risk reassessment, and change-driven updates.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.