ISO/IEC 27003:2017
Operation – ISO/IEC 27003:2017

ISO/IEC 27003:2017 ISO27003-8.3: Information security risk treatment

Carry out the risk treatment plan and keep the results as documented information. Implementation points (general practice; the 27003 guidance text is not held): 6.1.3 produces the plan and 8.3 executes it; follow each action to completion, check that the controls put in operate as intended, keep the Statement of Applicability current, and feed the results into the next assessment so residual risk reflects what is really in place.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 150 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.4 Privacy risk treatment
  • 27557-6.6 Recording and reporting
  • 27557-7.3 Risk-based privacy program implementation

SASB Standards · 4 controls

  • SASB-3 Leadership and Governance (LG)
  • SASB-LG-2 Systemic Risk Management
  • SASB-LG-3 Critical Incident Risk Management
  • SASB-LG-5 Systemic Risk Management
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement
  • IS.D.OR.210 Information Security Risk Treatment
  • IS.I.OR.210 Information Security Risk Treatment
  • IS.I.OR.220 Information Security Risk Management
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning
  • 60601-1.4.1 General requirements
  • 60601-1.4.2 Risk management process
  • 60601-1.5.1 General requirements for testing
  • IEC62304-4.1 Quality Management System
  • IEC62304-5.1 Software Development Planning
  • IEC62304-7.4 Risk Management of Software Changes

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-5.1 Leadership and Commitment
  • ISO23894-5.2 AI Risk Management Integration
  • ISO23894-5.5 Framework Evaluation

Japan AI Guidelines · 3 controls

  • JP-AIG-Continuous-Monitoring-Lifecycle-Model-Evaluation-Performance-Drift-Post-Deployment Japan AI Guidelines Continuous Monitoring + AI System Lifecycle Management + Model Evaluation + Performance Drift + Concept Drift + Post-Deployment + Retraining Triggers + Safe Update + Decommissioning + Model Card Versioning
  • JP-AIG-Fairness-Bias-Detection-Mitigation-Inclusive-AI-Discrimination-Prevention-10-Principles-2019-Heritage Japan AI Guidelines Fairness + Bias Detection + Mitigation + Inclusive AI + Discrimination Prevention + 10 Principles 2019 Heritage + Protected Attributes + Disparate Impact + Statistical Parity + Counterfactual Fairness
  • JP-AIG-Safety-Validation-Testing-Robustness-AISI-AI-Safety-Institute-Pre-Deployment-Evaluation-Red-Teaming Japan AI Guidelines Safety + Validation + Testing + Robustness + AISI AI Safety Institute (14 Feb 2024) + Pre-Deployment Evaluation + Red Teaming + Capability Evaluations + AI Incident Database + Safe Deployment + AI Safety Reports
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-30 · 3 controls

  • NISTSP30-1 Risk Management Strategy and Risk Assessment Programme Establishment
  • NISTSP30-2 Three-Tier Risk Assessment Scoping (Organisation, Mission/Business, Information System)
  • NISTSP30-8 Risk Assessment Maintenance, Continuous Monitoring, and Integration with the RMF

NIST SP 800-53 Rev 5 · 3 controls

PCI P2PE · 3 controls

  • PCI-P2PE-16 Due diligence and onboarding
  • PCI-P2PE-18 Ongoing monitoring and assessment
  • PCI-P2PE-19 Concentration risk management

PCI PIN Security · 3 controls

  • PCI-PIN-16 Due diligence and onboarding
  • PCI-PIN-18 Ongoing monitoring and assessment
  • PCI-PIN-19 Concentration risk management

PCI SSF · 3 controls

  • PCI-SSF-03 Risk appetite and tolerance for IT risk
  • PCI-SSF-16 Due diligence and onboarding
  • PCI-SSF-17 Contractual security requirements
  • SOC-CY-DC1 Nature of Business and Operations
  • SOC-CY-DC3 Cybersecurity Risk Management Objectives
  • SOC-CY-DC4 Governance Structure
  • SOCI-S30AC Obligation to adopt a CIRMP
  • SOCI-S30AD Compliance with CIRMP
  • SOCI-S30AE Annual review of CIRMP

Solvency II · 3 controls

  • SII-P2-11 Remuneration Policy
  • SII-P2-12 Written Policies
  • SII-P3-06 SFCR Section B: System of Governance

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • BS65000-RM-01 Resilience Journey
  • BS65000-RM-02 Integrated Approach
  • CAT-D1-2 Risk management
  • CAT-ML-2 Evolving
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain

NIST SP 800-37 · 2 controls

  • NISTSP37-1 RMF Prepare Step: Organisation-Level and System-Level Preparation
  • NISTSP37-7 RMF Monitor Step: Continuous Monitoring and Ongoing Authorisation

NIST SP 800-39 · 2 controls

  • NISTSP39-4 Risk Responding: Identify, Evaluate, Decide, Implement
  • NISTSP39-5 Risk Monitoring: Effectiveness, Changes, Compliance, and Reassessment Triggers
  • NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management
  • NRFCS-2 Risk Assessment, Customer Data Inventory, Classification, and Retail Threat Model

OECD AI Principles · 2 controls

  • OECDAI-3 Robustness, Security, Safety, and Adversarial Attack Protection
  • OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation

OSFI B-13 · 2 controls

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OSFIB13-4 Third-Party Risk Management and Cloud

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs
  • AMLCTF-82 Part A Compliance

API 1164 · 1 control

  • API1164-21 TSA Pipeline Security Directive Alignment
  • SPS220-28 Annual Board Risk Management Declaration
  • AS9100D-8.1 Operational Planning and Control
  • ACQS-8-4 Risk Management
  • CJIS-19 Supply Chain Risk Management

IEC 62443 · 1 control

  • IEC62443-21 Supply chain risk management for critical components
  • ISO-20400-4.5 Key considerations for sustainable procurement

ISO 22320:2018 · 1 control

  • ISO-22320-4.3 Risk-based approach

ISO 27005:2022 · 1 control

  • 8.6 Information security risk treatment plan

ISO 27701:2019 · 1 control

  • 5.6.3 Information security risk treatment
  • ISO28001-SA-04 Security Risk Treatment Planning

ISO/IEC 27019:2024 · 1 control

  • ISO27019-21 Supply chain risk management for critical components
  • LLOYDS-CI-Risk-Selection-Cyber-Hygiene-Underwriting-Criteria-Pre-Bind-Risk-Engineering-MFA-Backup-EDR Lloyds Cyber Insurance Risk Selection + Hygiene + Pre-Bind Engineering

MTCS (Singapore) · 1 control

  • MTCS-Governance-ISMS-Risk-HR-Lifecycle-Compliance-Cloud-Strategy-Roles-Responsibilities MTCS Governance + ISMS + Risk Management + HR Security + Cloud Service Lifecycle + Compliance + Roles
  • MAS-TRM-Third-Party-IT-Audit-Chapters-14-15-Outsourcing-Notice-658-Concentration-Risk-Exit-Strategy MAS TRM Third Party + IT Audit + Chapters 14-15 + Outsourcing + Notice 658 + Concentration Risk + Exit Strategy

NERC CIP · 1 control

  • NERCCIP-8 Supply Chain Risk Management (CIP-013)

NIST SP 1800-32 · 1 control

  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NZISM-1 NZISM Governance, Documentation, and Classification System
  • ORANWG11-1 O-RAN Threat Model, Risk Management, and Security Architecture
  • OECDAI24-3 Frontier Model Risk Management, Capability Disclosure, and Independent Evaluation
  • OPENBANK-4 Third Party Provider (TPP) Onboarding, Directory Integration, Due Diligence
  • ORSA-S1 Guidance Manual Section 1: Description of the insurer's risk management framework
  • PICSGMP-1 Chapter 1: Pharmaceutical Quality System (PQS) and Quality Risk Management
  • SECCLIM-2 Risk Management: Identification, Assessment, Integration
  • SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management
  • AIGF-1.1 Risk Management and Internal Controls
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-MS-02 Risk Management
  • TSSR-SEC-3 National Security Risk Management
  • CRM-3 Risk Management Framework
  • UKAI-1 Risk-Based Approach and Pro-Innovation Principles

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation – ISO/IEC 27003:2017

Query this from an agent

The graph holds this control, the 150 it maps to, and the evidence behind each claim, over MCP and REST.