The four options
For each risk above the acceptance criteria, the organisation chooses how to treat it. Modify or mitigate it with controls, which is the most common option. Avoid it by stopping the activity that creates it. Share or transfer it, for example through a supplier contract or cyber insurance. Retain or accept it, when the cost of treatment outweighs the benefit. Acceptance must be a conscious decision by the risk owner, not an oversight.
What the plan contains
For each treated risk: the selected controls, the actions needed to implement them, the owner, the resources, the deadline and the expected residual risk. Risk owners must approve the plan and formally accept the residual risks.
Its place in ISO 27001
ISO 27001 requires the organisation to define a risk treatment process (clause 6.1.3) and to implement the plan (clause 8.3). The controls chosen are compared with Annex A, and the result is documented in the Statement of Applicability. Auditors check that the plan exists, that actions are progressing and that it matches the risk assessment.
Keeping it alive
The plan is not a one time document. Actions are tracked like any project, the plan is updated after each risk assessment, incident or major change, and progress is reported to management. A plan full of overdue actions is a common audit finding, and a sign that security is not getting the resources it needs.




