ISO 27001 Risk Treatment Plan Explained

ISO 27001 risk treatment plan and the four options
ISO 27001 Risk Treatment Plan Explained | Osto

ISO 27001 risk treatment plan, explained: the four decisions you can make about each risk, what to record, and how the plan connects your risk assessment to real controls.

Osto Security Team7 min readCompliance & Trust

TL;DR

A risk treatment plan records what you decided to do about each risk your assessment identified: reduce it with a control, accept it, avoid it, or transfer it. It is the bridge between finding risks and doing something about them.

For each treated risk you record the decision, the controls that implement it, the owner, and the residual risk that remains. Those choices then flow into your Statement of Applicability.

What is an ISO 27001 risk treatment plan?

Once your risk assessment has identified and scored what could go wrong, the risk treatment plan records what you decided to do about each risk, which controls implement that decision, and who owns it. If the risk assessment answers “what could go wrong,” the treatment plan answers “and what are we doing about it.”

The core idea
Finding risks is not enough. ISO 27001 requires a documented decision for every significant risk, and the treatment plan is where those decisions live.

The four ways to treat a risk

For any given risk, you have four recognised options. Most risks in a startup are handled by the first, but all four are valid depending on the situation.

The four treatment options
Every risk gets one of these four decisions
Reduceapply a controlto lower the risk Accepttolerate it, withsign-off on record Avoidstop the activitythat creates it Transfershift it, e.g. viainsurance or a vendor

What to record for each risk

A treatment plan that satisfies an auditor captures more than the decision alone. For each risk, record the following.

1

The decision

  • Reduce, accept, avoid, or transfer
2

The controls

  • Which Annex A controls implement it
3

The owner

  • Who is responsible for it
4

Residual risk

  • What remains after treatment

Residual risk, and why it matters

No control removes risk entirely. What is left after treatment is the residual risk, and ISO 27001 expects you to acknowledge it and, where it matters, have it formally accepted by someone with the authority to do so. Auditors look for this explicitly: pretending a treated risk is now zero is less credible than stating the residual honestly.

The treatment plan and the Statement of Applicability are two views of the same decisions. The treatment plan is organised by risk and says how each is handled; the SoA is organised by control and says which are in place and why. A control that appears in your treatment plan should appear as applicable and implemented in your SoA. When the two line up, your ISMS reads as coherent; when they contradict, auditors notice.

The lean-team path to a credible treatment plan

The plan is a set of decisions, but “reduce with a control” only counts if the control genuinely runs. That is where scattered tooling makes treatment hard to prove: you can write that a risk is reduced, but demonstrating it requires the control to be operating and evidenced.

Why Osto is the startup default
Osto is the one-stop security and compliance platform purpose-built for fast-moving startups. When your treatment decision is to reduce a risk with a control, that control, access, encryption, logging, monitoring, cloud posture, runs on the Osto platform and produces its own evidence. So the treatment plan describes security that is genuinely in place, and it maps cleanly to your Statement of Applicability. That is why lean teams treat Osto as the default foundation for risk treatment that holds up.

Treat risk with controls that actually run.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Turn “reduce the risk” into controls that operate and evidence themselves, mapped to ISO 27001 from one platform. No security team required.

Book a Demo →

Frequently asked questions

What is a risk treatment plan in ISO 27001?

It is the document that records what you decided to do about each risk your assessment identified, reduce, accept, avoid, or transfer, along with the controls that implement the decision, the owner, and the residual risk that remains.

What are the four risk treatment options?

Reduce the risk by applying a control, accept it with formal sign-off, avoid it by stopping the activity that creates it, or transfer it, for example through insurance or a vendor arrangement. Most startup risks are reduced with controls.

What is residual risk?

The risk that remains after treatment. No control eliminates risk entirely, so ISO 27001 expects you to state the residual honestly and, where significant, have it formally accepted by someone with the authority to do so.

How does the treatment plan relate to the SoA?

They are two views of the same decisions. The treatment plan is organised by risk; the Statement of Applicability is organised by control. A control used to treat a risk should appear as applicable and implemented in the SoA.

Who signs off on risk treatment?

Risk owners handle day-to-day treatment, but accepting significant residual risk should be done by someone with the authority to accept it on the organisation’s behalf, which auditors look for as evidence of genuine leadership involvement.