Skip to content

Risk Treatment Plan

This Risk Treatment Plan formalizes how Cadence OneFive treats information security risks identified through the risk assessment process, in accordance with ISO 27001:2022 clause 6.1.3. It connects the risk assessment outputs to control selection, implementation, and residual risk acceptance.

This plan applies to all information security risks identified through the Risk Assessment Policy, covering all information assets within the ISMS scope.

For each identified risk, one or more of the following treatment options is selected:

Option Description
Mitigate Implement controls to reduce the likelihood or impact of the risk
Transfer Transfer the risk through insurance, contractual arrangements, or vendor services
Avoid Eliminate the risk by removing the source or ceasing the activity
Accept Accept the risk where it falls within risk appetite, with documented rationale

The selected treatment option must be proportionate to the risk level and aligned with Cadence OneFive’s risk appetite.

Treatment timelines are determined by risk level (see ISMS Manual §6.1.2 for the scoring methodology):

Risk Level Score Range Treatment Timeline
Critical 15–25 Immediate action required
High 12–14 Treatment within 30 days
Medium 6–11 Treatment within next review cycle
Low 1–5 Accept with monitoring

Risk owners are responsible for implementing treatments within these timelines.

The risk register is maintained as a Google Sheet with access restricted to authorized personnel. It serves as the central record of all identified risks and their treatment status. For each risk, the register documents the risk assessment, the selected treatment option, the control owner, and the residual risk after treatment.

Controls selected for risk treatment are drawn from the 93 controls in ISO 27001:2022 Annex A. Cadence OneFive’s Statement of Applicability (SoA) is the definitive record of which Annex A controls apply, why each is included or excluded, its implementation status, and the implementing policy. When a risk treatment requires a new or strengthened control, the SoA is updated accordingly.

When selecting controls, the following are considered:

  • The nature of the risk and the treatment option chosen
  • Existing controls already in place (as documented in the SoA)
  • Feasibility and cost-effectiveness of implementation
  • Regulatory and contractual obligations

After treatment is applied, residual risk is assessed using the same scoring methodology as the initial assessment. The Head of Platform formally accepts residual risk for each treated risk, documented in the risk register.

Residual risk that exceeds the organization’s risk appetite requires escalation to the CEO for review and acceptance decision.

Role Responsibility
CEO Overall accountability for information security risk management; accepts residual risk escalated beyond risk appetite
Head of Platform Oversight of risk treatment implementation; formal acceptance of residual risk; reports risk treatment status in management review
CISO Maintains the risk register; coordinates risk assessments; monitors treatment progress; reports to Head of Platform
Risk Owners Implement assigned risk treatments within defined timelines; report progress and any impediments to the CISO
All Personnel Report new or changed risks to the CISO via the Discord #tech_security channel

This Risk Treatment Plan and the associated risk register are reviewed:

  • Annually — As part of the scheduled risk assessment cycle
  • Upon significant change — When changes to the organization, technology, or threat landscape materially affect the risk profile
  • After a security incident — When an incident reveals previously unidentified or underestimated risks

Review results and risk treatment status are reported during management review per ISMS Manual §9.3.

  • This policy will be reviewed annually and updated as necessary to reflect changes in the risk assessment, organizational context, or regulatory requirements.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.