ISO 27001 Clause 8.3: Information Security Risk Treatment
Read the requirements of ISO 27001 Clause 8.3: Information Security Risk Treatment, which involves organisations implementing a security risk treatment plan.
Information security (or infosec) risk treatment for ISO 27001 requirement 8.3 is a process to minimise the risk impact and find the best suitable treatment for any risks that senior leadership have identified in previous clauses.
The information security risk treatment process is determined in clause 6.1.3, and all results from this risk treatment process must be kept in a documented form by the organisation.