Risk treatment planner for ISO 27001 clauses 6.1.2 and 6.1.3
One risk, worked all the way through. Score it, compare it against your own acceptance criteria, pick a treatment option, map it to the Annex A controls it needs, and see what signing off the residual risk actually requires.
Clause 6.1.2 asks for a risk assessment process that identifies risks, analyses them, and evaluates them against criteria you set in advance. Clause 6.1.3 asks you to choose treatment options, determine the controls needed, compare that set against Annex A, produce a Statement of Applicability and a risk treatment plan, and obtain risk owners' approval of the plan and their acceptance of the residual risks. Most registers stop after scoring.
This runs one risk the whole way through so you can see what the process looks like when it finishes. The result appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
The four steps, and where registers stop
A risk register that scores risks and stops has done the analysis and skipped the decision. The standard treats identification, analysis, evaluation and treatment as four separate activities with four separate outputs, and an auditor samples the last one first, because it is the one that shows the management system is running rather than being described.
| Step | Clause | Output an auditor asks for |
|---|---|---|
| Identification | 6.1.2 c | Risks to confidentiality, integrity and availability of information in scope, each with a named risk owner. Not an asset list. |
| Analysis | 6.1.2 d | Consequence and likelihood assessed, and a level of risk determined, using the method you documented before you started. |
| Evaluation | 6.1.2 e | Results compared against the acceptance criteria, and risks prioritised for treatment. Criteria written first, not reverse engineered from the scores. |
| Treatment | 6.1.3 | Option chosen, controls determined, compared against Annex A, Statement of Applicability produced, plan written, risk owners' approval and residual acceptance recorded. |
Sharing a risk does not move the accountability
Insurance pays for some of the consequence and a contract term may shift some of the cost, but the obligation to protect the information stays where it was. Under Canadian privacy law an organization remains accountable for personal information it transfers to a third party for processing, and an auditor reads a shared risk the same way: the control still has to exist somewhere, and you still have to show it does.
Common questions
Do I have to give an email address to see the result?
No. The scores, the treatment decision, the control mapping and the acceptance requirements render on this page as soon as you finish. The field underneath sends a written version formatted as a register entry, which is useful when the risk owner is not the person who filled this in. Skipping it costs you nothing.
Is a five by five matrix required?
No. The standard does not prescribe a method at all. It requires that you define one, apply it consistently, and produce comparable, reproducible results. A five by five matrix is common because it is easy to explain to a risk owner who does not work in security. A qualitative three-band scheme passes equally well if the criteria behind the bands are written down.
Who is allowed to accept a residual risk?
The risk owner, and the risk owner is the person with the authority and the accountability to manage that risk, which usually means a department head or an executive rather than the person running the management system. An ISMS manager accepting every residual risk in the register is one of the more common findings, because it shows the decision never left the security function.
How often does the risk assessment have to be redone?
At planned intervals and when significant changes occur, which in practice means at least annually plus a trigger list. Write the triggers down: a new product, a new jurisdiction, a material supplier change, a serious incident. An assessment dated once a year with no evidence of interim review is what the risk assessment page covers in detail.
Does the treatment plan go in the Statement of Applicability?
They are two documents that reference each other. The Statement of Applicability records a decision on all 93 Annex A controls with justifications. The risk treatment plan says who is doing what by when to the risks that need treating. The risk treatment plan page sets out what belongs in each.
Get the risk method reviewed
Tell us where you are and we will put it in front of Canadian firms doing ISO 27001 readiness work.
Get matched