4.2 The Four Risk Treatment Options
Key Takeaways
- ISO/IEC 27001 recognises exactly four risk treatment options: modify, retain, avoid, and share — "ignore" is never a valid option
- Modify means applying selected controls (often from Annex A) to reduce likelihood or impact; it is the option most commonly selected in an ISMS and is colloquially called "mitigate"
- Retain means accepting a risk that is already within the organisation's risk criteria — it is an informed decision, not inaction
- Avoid means deciding not to start or to stop an activity that generates the risk; the risk disappears because the activity does
- Share transfers part of the risk to another party through insurance, outsourcing, or contractual provisions, but accountability for the risk outcome remains with the organisation
Once a risk has been evaluated and exceeds the organisation's acceptance criteria, Clause 6.1.3 — "Information security risk treatment" — requires the organisation to do something about it. ISO/IEC 27001 recognises exactly four treatment options. Every other word you may have seen in risk literature is either a synonym for one of these four or is not a valid option under the standard.
The Four Options at a Glance
| Option | Core Definition | One-Line Exam Cue |
|---|---|---|
| Modify | Apply controls to reduce likelihood and/or impact so the residual risk falls within acceptance criteria | "Reduce the risk" |
| Retain | Accept the risk as it stands because it is already within risk criteria, or because treatment cost is disproportionate | "Accept the risk" |
| Avoid | Decide not to start, or to cease, the activity that gives rise to the risk | "Stop the activity" |
| Share | Transfer part of the risk to another party able to bear it more effectively | "Transfer the risk" |
Modify (Often Called "Mitigate")
Modify is the option most frequently chosen inside an ISMS. The organisation selects and implements controls — many of them drawn from Annex A of ISO/IEC 27001 and detailed in ISO/IEC 27002 — that lower the likelihood of the risk materialising, the impact if it does, or both. The risk is not eliminated; it is reduced to a residual level that the risk owner is willing to accept.
Exam Scenario
A web application is exposed to SQL injection. The organisation adds input validation (Annex A.8.28 secure coding), a web application firewall, and parameterised queries. Likelihood drops from "Likely" to "Unlikely"; impact drops from "Major" to "Moderate". The risk moves from High to Medium on the matrix. This is modify.
Common Distractors
- "Mitigate" is a colloquial synonym for modify. The exam may use "mitigate" in a wrong answer to test whether you know the standard's official term is "modify".
- "Eliminate" is not modify — if a control truly removes the risk, that is closer to avoid (you have removed the activity or the vulnerable component).
- "Reduce" is acceptable shorthand for modify, but the official term is still modify.
Retain (Risk Acceptance)
Retain means the organisation knowingly accepts the risk, either because it already falls within risk criteria or because the cost of treatment exceeds the benefit. Retention is an active, documented decision, not negligence. The risk owner must sign off, and the decision must be recorded in the risk register.
Exam Scenario
A small branch office faces a "Low" risk of physical break-in. The cost of upgrading to biometric doors and 24/7 guards would exceed the value of the assets inside. Top management formally accepts the risk, records the decision, and continues normal operations. This is retain.
Common Distractors
- "Ignore" is never a valid option. Ignoring a risk without analysis or sign-off is a failure of the ISMS and a nonconformity at audit.
- "Defer" (postponing the decision) is not one of the four options. A deferred risk is still on the books and must eventually be treated or formally retained.
- "Accept" is the synonym used in many frameworks; ISO/IEC 27001 calls this option retain, and the formal act is risk acceptance by the risk owner.
Avoid
Avoid means the organisation removes the source of the risk by not starting or by stopping the activity. Because the activity no longer exists, the risk no longer exists either. Avoid is often the right choice when the risk is high, the asset is not business-critical, and no control can bring the residual risk within acceptance criteria.
Exam Scenario
A cloud-based file-sharing service is found to have a critical vulnerability that the vendor will not patch, and customer data is exposed. The organisation decides to terminate the contract, migrate users to an internally hosted solution, and decommission the service. The risk is avoided — the vulnerable activity has been removed entirely.
Common Distractors
- "Remove the risk by patching" is modify, not avoid. Avoid requires removing the activity, not just the vulnerability.
- "Cancel a project because risk is too high" is the textbook example of avoid, but only if the project is genuinely halted — not merely paused.
- "Outsource the activity" is share, not avoid. The activity still happens; another party now bears part of the risk.
Share (Risk Transfer)
Share means transferring part of the risk to a third party that can manage it more effectively. Common mechanisms include:
- Insurance — a cyber-insurance policy pays out in the event of a breach, transferring the financial impact.
- Outsourcing — a managed security services provider (MSSP) takes operational responsibility for detecting and responding to attacks.
- Contractual provisions — a supplier contract includes penalties, indemnities, or right-to-audit clauses that shift specific risk consequences.
A critical nuance: share does not transfer accountability. The organisation still owns the risk in the eyes of regulators, customers, and the ISMS. If the MSSP fails, the organisation is still liable for the breach. Share moves some of the consequences, not the ownership.
Exam Scenario
An e-commerce company purchases a $5 million cyber-insurance policy to cover breach-response costs. The technical risk of a breach is unchanged, but the financial impact on the company is reduced because the insurer will absorb most of the cost. This is share.
Common Distractors
- "Transfer the accountability" is wrong — accountability cannot be transferred; only operational responsibility or financial consequence can.
- "Buy a firewall" is modify, not share — a firewall reduces likelihood, it does not move the risk to another party.
- "Take out cyber-insurance" is the textbook share example.
Combining Options
A single risk may be treated with more than one option. The organisation might modify a risk by deploying encryption, share the residual financial impact via cyber-insurance, and have the risk owner retain what remains. The Risk Treatment Plan must document which combination was selected for each risk scenario.
Comparison Table for Exam Recall
| Option | What Happens to the Risk | What Happens to the Activity | Typical Tool |
|---|---|---|---|
| Modify | Reduced (likelihood and/or impact) | Continues, with controls | Annex A controls |
| Retain | Unchanged, accepted | Continues as before | Risk acceptance record |
| Avoid | Removed | Stopped or never started | Project cancellation |
| Share | Partially transferred | Continues, third party involved | Insurance, contract |
The Most Common Exam Trap
A question will list five options: modify, retain, avoid, share, and ignore. Ignore is never valid. A risk that has not been assessed, treated, or formally accepted is an ISMS nonconformity. If you see "ignore," "do nothing," or "defer" as an option, eliminate it immediately.
Key Takeaways
- The four valid options are modify, retain, avoid, and share — no others.
- Modify is the default in an ISMS because it draws on Annex A controls.
- Retain is a documented, owner-approved acceptance — never "ignore."
- Avoid removes the activity; share keeps the activity but transfers part of the consequence.
- Accountability cannot be transferred — share moves consequences, not ownership.
An organisation decides not to launch a new mobile payment feature because the residual risk after all feasible controls is still above its risk acceptance criteria. Which risk treatment option has it applied?
Which of the following is NOT one of the four ISO/IEC 27001 risk treatment options?
A company purchases a cyber-insurance policy to cover the financial cost of a potential data breach. The technical likelihood of a breach is unchanged. Which risk treatment option does this represent?