New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
ISO 27001 · Clause 6.1.3

Information security risk treatment & Statement of Applicability

Summary

The organisation shall define a risk treatment process, select controls, compare them against Annex A, and produce a Statement of Applicability.

risk treatmentstatement of applicabilitysoaannex aresidual risk

Read the full official text: https://www.iso.org/standard/27001

Track ISO 27001 clause 6.1.3 as evidence

eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.

Start free trial