Solutions The best route to security compliance
Platform A powerful suite of ISMS features
Resources Everything you need to know
Knowledge Base Learn more about infosec
Company Security and customers first

ISO 27001 Clause 8.3: Information Security Risk Treatment

Read the requirements of ISO 27001 Clause 8.3: Information Security Risk Treatment, which involves organisations implementing a security risk treatment plan.


Information security (or infosec) risk treatment for ISO 27001 requirement 8.3 is a process to minimise the risk impact and find the best suitable treatment for any risks that senior leadership have identified in previous clauses.

The information security risk treatment process is determined in clause 6.1.3, and all results from this risk treatment process must be kept in a documented form by the organisation.