What documentation is required for risk treatment?
- A.The risk treatment plan including selected options, rationale, responsible parties, timelines, and approved residual risk levels
- B.Only the budget
- C.Only the selected controls. Under Clause 10.1 this task falls to the internal audit team, who reports the outcome directly to the certification body.
- D.Only implementation dates. Annex A control 8.9 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the information security committee rather than with the process owner named in the question.
Why A is correct
Risk treatment documentation includes selected treatment options, rationale, implementation actions, responsibilities, timelines, and accepted residual risk levels.
Know someone studying for ISO 27001? Send them this one.