Risk Treatment Plan
Purpose
Section titled “Purpose”This Risk Treatment Plan formalizes how Cadence OneFive treats information security risks identified through the risk assessment process, in accordance with ISO 27001:2022 clause 6.1.3. It connects the risk assessment outputs to control selection, implementation, and residual risk acceptance.
This plan applies to all information security risks identified through the Risk Assessment Policy, covering all information assets within the ISMS scope.
Risk Treatment Options
Section titled “Risk Treatment Options”For each identified risk, one or more of the following treatment options is selected:
| Option | Description |
|---|---|
| Mitigate | Implement controls to reduce the likelihood or impact of the risk |
| Transfer | Transfer the risk through insurance, contractual arrangements, or vendor services |
| Avoid | Eliminate the risk by removing the source or ceasing the activity |
| Accept | Accept the risk where it falls within risk appetite, with documented rationale |
The selected treatment option must be proportionate to the risk level and aligned with Cadence OneFive’s risk appetite.
Treatment Timelines
Section titled “Treatment Timelines”Treatment timelines are determined by risk level (see ISMS Manual §6.1.2 for the scoring methodology):
| Risk Level | Score Range | Treatment Timeline |
|---|---|---|
| Critical | 15–25 | Immediate action required |
| High | 12–14 | Treatment within 30 days |
| Medium | 6–11 | Treatment within next review cycle |
| Low | 1–5 | Accept with monitoring |
Risk owners are responsible for implementing treatments within these timelines.
Risk Treatment Register
Section titled “Risk Treatment Register”The risk register is maintained as a Google Sheet with access restricted to authorized personnel. It serves as the central record of all identified risks and their treatment status. For each risk, the register documents the risk assessment, the selected treatment option, the control owner, and the residual risk after treatment.
Control Selection
Section titled “Control Selection”Controls selected for risk treatment are drawn from the 93 controls in ISO 27001:2022 Annex A. Cadence OneFive’s Statement of Applicability (SoA) is the definitive record of which Annex A controls apply, why each is included or excluded, its implementation status, and the implementing policy. When a risk treatment requires a new or strengthened control, the SoA is updated accordingly.
When selecting controls, the following are considered:
- The nature of the risk and the treatment option chosen
- Existing controls already in place (as documented in the SoA)
- Feasibility and cost-effectiveness of implementation
- Regulatory and contractual obligations
Residual Risk Acceptance
Section titled “Residual Risk Acceptance”After treatment is applied, residual risk is assessed using the same scoring methodology as the initial assessment. The Head of Platform formally accepts residual risk for each treated risk, documented in the risk register.
Residual risk that exceeds the organization’s risk appetite requires escalation to the CEO for review and acceptance decision.
Roles and Responsibilities
Section titled “Roles and Responsibilities”| Role | Responsibility |
|---|---|
| CEO | Overall accountability for information security risk management; accepts residual risk escalated beyond risk appetite |
| Head of Platform | Oversight of risk treatment implementation; formal acceptance of residual risk; reports risk treatment status in management review |
| CISO | Maintains the risk register; coordinates risk assessments; monitors treatment progress; reports to Head of Platform |
| Risk Owners | Implement assigned risk treatments within defined timelines; report progress and any impediments to the CISO |
| All Personnel | Report new or changed risks to the CISO via the Discord #tech_security channel |
Review and Maintenance
Section titled “Review and Maintenance”This Risk Treatment Plan and the associated risk register are reviewed:
- Annually — As part of the scheduled risk assessment cycle
- Upon significant change — When changes to the organization, technology, or threat landscape materially affect the risk profile
- After a security incident — When an incident reveals previously unidentified or underestimated risks
Review results and risk treatment status are reported during management review per ISMS Manual §9.3.
Related Documents
Section titled “Related Documents”- ISMS Manual — Governance framework and risk management methodology
- Risk Assessment Policy — Risk assessment process and scope
- Statement of Applicability — Annex A control selection and justification
Policy Review
Section titled “Policy Review”- This policy will be reviewed annually and updated as necessary to reflect changes in the risk assessment, organizational context, or regulatory requirements.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
