Risk assessment and treatment procedure
Download this document free
Get this document with your free trial. Choose from the full Complyzard library.
Try 1 month free30 days free, then $19/month. Trial terms apply. Card required. Cancel anytime.Document information
For the risk manager, risk owners and Statement of Applicability owner to assess information security risk, choose treatment, approve remaining risk and maintain control-necessity decisions.
- Document type
- Procedure
- Format
- DOCX
- Pages
- 8
- Language
- English
- Version
- 1.0
- Updated
- 2026-09-15
- Category
- Information security
- Licence
- Internal use
Description
For the risk manager, risk owners and Statement of Applicability owner to assess information security risk, choose treatment, approve remaining risk and maintain control-necessity decisions.
Contents
- Document control
- Purpose of this procedure
- Define the risk decision, boundary, and horizon
- Describe the risk scenario
- Assess evidence and uncertainty
- Define and calibrate the rating method
- Use specialist analysis where consequence warrants
- Record the current rating and disagreement
- Maintain risk decisions through project delivery
- Assess shared and concentrated failure
- Define testable treatment outcomes
- Verify treatment implementation and effect
- Accept residual risk within authority
- Reassess changed or expired decisions
Version history
- v1.015/09/2026