World Of Taxonomy
8_3Level 2

8.3 Information security risk treatment

Clause 8.3 of ISO/IEC 27001:2022 requires organizations to select and apply appropriate controls to treat identified information-security risks, documenting a risk-treatment plan that links each risk to specific actions, responsible parties and timelines. The clause also mandates acceptance of any residual risk after treatment and regular review to ensure the treatment remains effective and aligned with the overall risk-assessment process.

GET/api/v1/systems/reg_iso_27001/nodes/8_3
Manual TranscriptionProprietary (ISO copyright)Source

Hierarchy Explorer

Loading...

Cross-system equivalences0

No cross-system equivalences mapped for this node.