ISO 27001:2022 Clause 6.1.3 Information Security Risk Treatment Explained

ISO 27001 Clause 6.1.3 Information Security Risk Treatment Certification Guide

In this guide you will learn how to implement ISO 27001 Clause 6.1.3 Information Security Risk Treatment and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.

The ISO 27001 standard is a risk based management system that requires an organisation to select appropriate risk treatment options based on the risk assessment results.

Definition

The organization shall define and apply an information security risk treatment process to:

select appropriate information security risk treatment options, taking account of the risk assessment results;

determine all controls that are necessary to implement the information security risk treatment option(s) chosen;

compare the controls determined with those in Annex A and verify that no necessary controls have been omitted;

produce a Statement of Applicability that contains the necessary controls justification for their inclusion; whether the necessary controls are implemented or not; and the justification for excluding any of the Annex A controls.

formulate an information security risk treatment plan; and

obtain risk owners’ approval of the information security risk treatment plan and acceptance of the residual information security risks.

The organization The organization shall retain documented information about the information security risk treatment process.

Stuart Barker - High Table - ISO27001 Director

Instant download of mandatory ISMS core policies and documentation. Verified by Lead Auditors and used by 5,000+ businesses worldwide to pass Stage 1 certification first time.

FREE ISO 27001 Clause 6.1.3 Training Video

What is ISO 27001 Clause 6.1.3?

ISO 27001 Clause 6.1.3 is a security control that mandates the definition and application of an information security risk treatment process. Its primary implementation requirement is to select appropriate treatment options and verify them against Annex A controls. The business benefit is ensuring that all identified risks are modified, retained, or avoided to match the organizational risk appetite.

This clause is all about risk treatment.

The ISO 27001 standard for ISO 27001 certification wants you define and implement a risk assessment process and to treat those risks appropriately.

It is, after all, a risk based management system. Not a rule based system.

That risk treatment process has to set out risk criteria which are the parameters of your risk management.

ISO 27001 Toolkit Business Edition

How to implement ISO 27001 Clause 6.1.3

Risk Treatment Options

You are expected to select appropriate information security risk treatment options, taking account of the risk assessment results.

Risk treatment options can include

  • accepting the risk
  • treating the risk
  • mitigating the risk
  • transfer the risk
  • avoiding the risk

Risk Controls

Risk controls where required as necessary are identified and the information security risk treatment option(s) is chosen. A great place to identify what those controls are is in the Statement of Applicability ( SOA ). This is the list of ISO 27002 / Annex A controls that apply to you. Of course if you have not defined your Statement of Applicability yet then you can choose directly from the ISO 27002 / Annex A control list.

Of course there may be additional controls that you want to consider but the ISO 27001 standard and the provided list of Annex A controls is designed specifically as a common sense set of controls. It therefore makes perfect sense to you that list of controls as the controls you will use to mitigate risk. It also helps with your ISO 27001 certification by staying on point.

You will compare the controls determined in 6.1.3 above with those in ISO 27001 Annex A and verify that no necessary controls have been omitted.

Statement of Applicability (SOA)

It is down to you to produce a Statement of Applicability that contains the necessary controls and justification for inclusions, whether they are implemented or not, and the justification for exclusions of controls from Annex A.

As mentioned the Statement of Applicability is not a particular difficult or complex document. Moreover it is just a list of controls with a date they were assessed and if they are not applicable why not. Don’t over think it.

Risk Treatment Plan

Once you have decided on what your risk treatment will be then you need a plan to address it.

For risks that you accept you will want to update the risk register and then minute that you accepted the risks at an appropriate Management Review Team Meeting.

For other risks you will formulate a plan. The plan will include what you will do, who will do it, when they will do and a check of the results.

Once the risk treatment has completed you will then risk assess again using the new controls in place. This gives you what is called Residual Risk. All of this is documented in the risk register.

Risk Treatment Approval

Risk owners will approve the risk treatment plan and the acceptance of the residual information security risks. This will also be shared at the next Management Review Team meeting and agreed and minuted.

ISO 27001 Clause 6.1.3 FAQ

What is ISO 27001 Clause 6.1.3 Information Security Risk Treatment?

ISO 27001 Clause 6.1.3 is the requirement for organisations to define and apply an information security risk treatment process. It ensures that 100% of identified risks are addressed through a formal selection of controls, typically resulting in a Risk Treatment Plan (RTP) and a Statement of Applicability (SoA).

What are the four primary risk treatment options in ISO 27001?

The four primary risk treatment options, often referred to as the 4Ts, include:

  • Risk Modification (Treat): Applying technical or organisational controls to reduce the risk level.
  • Risk Retention (Tolerate): Formally accepting the risk because it falls within the organisation’s risk appetite.
  • Risk Avoidance (Terminate): Eliminating the risk entirely by stopping the activity or removing the asset.
  • Risk Sharing (Transfer): Moving the financial or operational impact to a third party, such as an insurance provider.

How do you comply with ISO 27001 Clause 6.1.3 requirements?

Compliance is achieved by following a documented five-step workflow: first, select treatment options for each risk; second, determine all controls necessary to implement the options; third, compare these against Annex A; fourth, produce a Statement of Applicability (SoA); and fifth, formulate a formal Risk Treatment Plan (RTP) signed off by risk owners.

Why is the Statement of Applicability (SoA) critical for Clause 6.1.3?

The Statement of Applicability is a mandatory document that lists the 93 controls from Annex A, identifying which are included or excluded. It serves as the master record for auditors to verify that no necessary controls were missed during the risk treatment process, ensuring 27001 certification readiness.

Who must approve ISO 27001 residual risks?

Residual risks must be formally approved by the designated Risk Owners. These individuals are typically senior managers with the authority and budget to accept the potential impact of a risk remaining after controls have been applied, as specified in Clause 6.1.3(f).

About the author

Stuart Barker
🎓 MSc Security 🛡️ Lead Auditor ⚡ 30+ Years Exp 🏢 Ex-GE Leader

Stuart Barker

ISO 27001 Ninja

Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigor with extensive operational experience, including a decade leading Data Governance for General Electric (GE).

As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.

Shopping Basket
Scroll to Top