Risk treatment
Also known as: risk response
Choosing what to do about each risk - accept it, reduce it, share it with someone else, or avoid it altogether.
Draft - this entry has not been reviewed yet.
Formal
The step in risk management where each assessed risk gets one of four responses - retained as it is, reduced with controls, shared with or transferred to another party, or avoided by stopping the activity - each with an owner and a plan.
In plain English
Like facing a leaky roof - you can live with it, patch it, buy insurance, or move out.
In practice
A shipping company's board buys cyber insurance to share the cost of a ransomware attack, adds MFA to reduce the risk from stolen passwords, and accepts the small risk of an office printer failing.
Why it matters
Finding risks is pointless without a decision about each one, and that decision shows who owns it and what it costs.
Technical deep dive
The familiar four options are a simplification. ISO 31000:2018 clause 6.5.2 lists seven: avoiding the risk by not starting or continuing the activity; taking or increasing the risk to pursue an opportunity; removing the risk source; changing the likelihood; changing the consequences; sharing the risk, for example through contracts or insurance; and retaining the risk by informed decision. NIST SP 800-39 uses five risk responses, separating sharing from transfer, while ISO/IEC 27005 has traditionally grouped the options as modification, retention, avoidance and sharing. The options are not mutually exclusive: a typical ransomware treatment combines mitigation (MFA, segmentation, offline backups), sharing (cyber insurance for the tail) and formal retention of what is left.
ISO/IEC 27001:2022 clause 6.1.3 turns treatment into a sequence of auditable steps: a) select treatment options in light of the assessment results; b) determine all controls necessary to implement them, from any source; c) compare those controls with Annex A to verify that nothing necessary has been omitted; d) produce the Statement of Applicability with justification for inclusions and exclusions; e) formulate a risk treatment plan; and f) obtain the risk owners' approval of the plan and their acceptance of the residual risks. Clause 8.3 then requires the plan to be implemented and its results retained.
ISO 31000:2018 clause 6.5.3 describes what a treatment plan should contain: the rationale for the chosen options including expected benefits, who is accountable for approving and implementing it, the proposed actions, resources, performance measures, constraints, required reporting and monitoring, and timing. In practice this means each treated risk is linked in the register to named actions, an owner, a deadline, a budget line and the expected residual rating, so that monitoring can later compare the expected with the achieved effect.
Selection is a cost-benefit decision bounded by obligations. Legal and contractual requirements can rule options out entirely (a mandatory control cannot simply be retained away), stakeholder expectations and ethics count alongside expected-loss arithmetic, and ISO 31000 notes that treatment can introduce new risks and may not work as intended, so treatments must themselves be monitored. Treatment differs from incident response despite the similar-sounding synonym risk response: treatment decides in advance how a risk will be handled, whereas incident response deals with an event that has already occurred.
What to learn first
Everything this builds on, foundations first.
- CIA triad
- →Threat
- →Asset
- →Vulnerability
- →Impact
- →Likelihood
- →Risk
- →Security control
- →Risk assessment
- →Risk treatment
Relationships
- Part of
- Risk management
- Causes
- Residual risk
- Used with
- Risk heat mapISO 27002
Sources & further reading
Standards & official texts
- ISO/IEC 27005:2022
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…