risk-treatment

Assess ISO 27001 risks and generate a Risk Treatment Plan with controls.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill risk-treatment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: risk-treatment
Source: https://github.com/gombing/ISO27001Agent/tree/main/risk-treatment
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill risk-treatment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

ISO 27001 risk treatment decisions can be manual, error-prone, and time-consuming; this Skill provides a structured, repeatable process to decide treatment options, map Annex A controls, assign owners, and generate a formal Risk Treatment Plan.

Core Features & Use Cases

  • Load and interpret the engagement risk data, identify risks above the acceptance threshold, and propose treatments (Treat/Transfer/Avoid/Accept).
  • Associate controls, owners, and target dates, and compute residual risk scores to feed into the SoA and Roadmap workflows.
  • Use cases include preparing risk treatment decisions for ISO 27001:2022 Clause 6.1.3 and creating a structured plan for implementation and audit readiness.

Quick Start

Run the risk-treatment skill to load the engagement risk register and begin making treatment decisions.

Frequently Asked Questions about risk-treatment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a formal ISO 27001 Risk Treatment Plan?

To generate an ISO 27001 Risk Treatment Plan, load your risk register to identify risks above the acceptance threshold, select treatment options, map Annex A controls with owners, and calculate residual risk scores for audit readiness.

What is the best way to decide between Treat, Transfer, Avoid, and Accept for risk management?

Risk treatment decisions require assessing each identified risk against your acceptance threshold to determine whether to Treat, Transfer, Avoid, or Accept, followed by mapping applicable ISO 27001 Annex A controls and assigning implementation owners.

How do I map Annex A controls to risks above the acceptance threshold?

Mapping Annex A controls involves evaluating risks above the acceptance threshold and associating specific ISO 27001:2022 Annex A controls to each risk, assigning owners, and setting target dates to structure the implementation roadmap.

Can I use this to calculate residual risk scores for my ISO 27001 compliance workflow?

Yes, you can calculate residual risk scores by determining treatment strategies for risks above the acceptance threshold, which feeds directly into the Statement of Applicability and implementation roadmap workflows.

Does ISO 27001 risk treatment require assigning owners and target dates for each control?

Assigning owners and target dates is a required part of ISO 27001 risk treatment to ensure accountability, capturing these decisions within the formal Risk Treatment Plan to track implementation progress and audit readiness.

When do I need a structured process for ISO 27001 Clause 6.1.3 risk treatment?

A structured process is needed when preparing risk treatment decisions for ISO 27001:2022 Clause 6.1.3 to avoid manual errors, ensure repeatable treatment selections, and create a formal plan for implementation and audit readiness.