Information security risk treatment & Statement of Applicability
Summary
The organisation shall define a risk treatment process, select controls, compare them against Annex A, and produce a Statement of Applicability.
risk treatmentstatement of applicabilitysoaannex aresidual risk
Read the full official text: https://www.iso.org/standard/27001
Track ISO 27001 clause 613 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial