markdowneditor

Risk Treatment Plan

Treatment options, residual acceptance

ISO 및 컴플라이언스표준risktreatmentplan

사용법: Pairs with SoA. Residual acceptance needs executive sign-off with expiry – acceptance is not permanent.

미리보기

Risk Treatment Plan

Mandatory – ISO/IEC 27001:2022 cl.6.1.3 e + cl.8.3. For each risk above the acceptance threshold: option chosen, controls, owner, timeline, expected residual.

FieldValue
PeriodYYYY cycle
Based onRisk register DOC-ISMS-012
Approved byRisk owners + management

Treatment actions

Risk IDRiskOptionControls (Annex A)Action planOwnerDueBudgetResidual target
R-001Data breachMitigateA.8.3, A.8.24Implement MFA + encryption@nameYYYY-MM$NLow
R-003Lost deviceMitigateA.8.1, A.7.9Full-disk encryption rollout@nameYYYY-MM$NLow
R-004Vendor outageMitigateA.5.22Backup vendor contract@nameYYYY-MM$NMed

Treatment decisions pending

Risk IDProposed optionDecision needed fromBy when
R-0NNAccept vs treatManagementYYYY-MM

Progress tracking

CheckpointDateStatus summary
QN reviewYYYY-MM-DDN% actions complete

Residual risk acceptance

Risks remaining after treatment require explicit sign-off:

Risk IDResidual scoreAccepted byDateExpiry
R-0023@execYYYY-MM-DDreview date

Linkages

  • Inputs from: risk register, SoA
  • Outputs to: SoA justification, audit evidence, management review

관련 템플릿