What to do at this stage
- 01
Compare treatment options against the assessed risk and the organisation’s criteria.
- 02
Record the agreed action, owner, due date and evidence required to demonstrate completion.
- 03
Define security requirements that can be traced into design and verified by test.
Questions to work through
- What will the treatment change?
- Who is accountable for delivering it?
- How will we know the requirement has been met?
Replace “improve access control” with a requirement that identifies the protected area, authorised users, required behaviour and acceptance evidence.
A common trap
Recording an action in a register is not the same as deciding, funding and assigning a treatment.
When the work needs to return
Suggested resources
Selected for their likely use at this stage. Resource associations are guidance, not a compliance crosswalk.
Risk Register Starter Pack
Start documenting risks and the actions needed to treat them.
View in the SRMBOK shopThe Bow-Tie Field Kit
Support a bow-tie workshop and review the resulting analysis.
View in the SRMBOK shopRisk Treatment Schedule — Template 13.4
Connect treatment actions with their owners and timeframes.
View in the SRMBOK shopSRMBOK Guide to ChatGPT Prompt Engineering
Use and adapt prompts for risk identification, assessment, stakeholder engagement and treatment planning.
View in the SRMBOK shopRisk Thinking for Domestic and Family Violence Practice (an SRMBOK Guide)
Risk thinking for domestic and family violence practitioners, covering uncertainty, controls and defensible decisions. A companion to mandated assessment processes.
View in the SRMBOK shopThe Risk Bow-Tie Method eBook
Learn the bow-tie method through its nine elements, a factory-fire example and a workshop outline.
View in the SRMBOK shopSRMBOK Template 13.2 Risk Register
Record risks, categories, treatment options, risk levels and monitoring comments in an editable Word register.
View in the SRMBOK shopSRMBOK Template 13.3 Risk Treatment Schedule
Document risk treatment actions, responsibilities and timescales in an editable Word schedule.
View in the SRMBOK shopRisk Control Effectiveness Criteria Template
Use defined criteria when evaluating control effectiveness.
View in the SRMBOK shopSRMBOK Security Plan Templates
Adapt three editable security and risk treatment plans, with worked examples for enterprise and operational planning.
View in the SRMBOK shopSRMBOK Guide to AI for Risk Practitioners (Ed. 1.0).pdf
Practical guidance on AI use, information handling, verification and the evidence behind professional risk judgements.
View in the SRMBOK shopSRMBOK Guide to the Risk Management Process
A printable explanation of the risk management process, distinguishing assessment actions from the supporting activities.
View in the SRMBOK shopSRMBOK Guide to Intellectual Assets
Guidance on protecting intellectual assets, with attention to research environments, organisational culture and information risks.
View in the SRMBOK shopIncident Response & Disaster Recovery Template
Prepare an editable incident response and disaster recovery plan, with step-by-step guidance for response and recovery.
View in the SRMBOK shopSRMBOK Guide to the 30 Day Risk Assessment
A structured assessment method with workshop materials, facilitator guidance, checklists and planning templates.
View in the SRMBOK shopSRMBOK Security Postures Template
Adapt worked examples of security postures that change operational precautions as threat levels change.
View in the SRMBOK shopSRMBOK Guide to Insider Threat Management Programs
Guidance on establishing an insider threat programme, from assessment and policies to awareness, detection and response.
View in the SRMBOK shopSRMBOK Guide to Treating Complex Risks
A structured approach to developing treatments for persistent risks whose solutions are difficult to identify or agree.
View in the SRMBOK shopSRMBOK Risk Assessment Spreadsheet
An enterprise risk workbook linking risk ratings, barriers, treatment actions, review dates and board reporting.
View in the SRMBOK shopEnterprise Security Risk Assessment Template
Adapt a fully worked enterprise security risk assessment using a fictional corporation, with editable examples and treatment content.
View in the SRMBOK shopKeep the whole life cycle in view
Security Risk Management Life Cycle Wall Charts
Keep the whole life cycle in view, from initiation to change and disposal.
View in the SRMBOK shopGuide to the Security Risk Management Life Cycle
Explore the published SRMBOK guide behind the life cycle.
View in the SRMBOK shopThese practical prompts are editorial guidance for the navigator. Consult the published SRMBOK life cycle guide and charts for the full method. About this edition and its sources.