ISO 27701:2019
PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

ISO 27701:2019 5.6.3: Information security risk treatment

The requirement of ISO/IEC 27001 to implement the risk treatment plan applies to the PIMS, so the privacy controls chosen during treatment must actually be implemented and their implementation evidenced.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 31 controls across 18 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.RM-02 Risk appetite and risk tolerance statements are established, communicated, and maintained
  • NIST-CSF-ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded
  • NIST-CSF-ID.RA-06 Risk responses are chosen, prioritized, planned, tracked, and communicated
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

SOC 2 · 4 controls

  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC5.1 CC5.1 Selecting control activities that mitigate risk (COSO principle 10)
  • SOC2-CC9.1 CC9.1 Mitigating risks of business disruption
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.OR.210 Information Security Risk Treatment

CMMC 2.0 · 2 controls

ISO 27002:2022 · 2 controls

  • 5.1 Policies for information security
  • 5.36 Compliance with policies, rules and standards for information security

ISO/IEC 27003:2017 · 2 controls

  • 27003-6.1.3 Information Security Risk Treatment
  • ISO27003-8.3 Information security risk treatment

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security

NIST SP 800-53 Rev 5 · 2 controls

  • AUCDR-IS-STEP3 Step 3 - Have and maintain an information security capability

CIS Controls v8 · 1 control

  • CIS-7.2 Establish and Maintain a Remediation Process

FedRAMP High · 1 control

  • CA-5 Plan of Action and Milestones

FedRAMP Moderate · 1 control

  • CA-5 Plan of Action and Milestones

HIPAA Security Rule · 1 control

ISO 27005:2022 · 1 control

  • 8.6 Information security risk treatment plan

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 5.6.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 31 it maps to, and the evidence behind each claim, over MCP and REST.