TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

Treatment types

Estimated reading: 3 minutes 1606 views

Treatment types in TrustRegister

Treatment types define the different strategies organizations use to manage identified risks. Since controls alone cannot fully eliminate risk, residual risk must be addressed through one of the following treatment approaches:

  1. Remediate: Take corrective actions to eliminate or significantly reduce the risk.
  2. Mitigate: Apply additional controls or measures to reduce the likelihood or impact of the risk.
  3. Transfer: Shift the risk to a third party, such as through insurance or outsourcing.
  4. Accept: acknowledge the risk without further action if it falls within acceptable limits.
  5. Avoid: Change business processes or strategies to eliminate the risk altogether.

The choice of treatment type depends on factors such as the nature of the risk, organizational objectives, and risk tolerance.

For a more detailed explanation and visual representation, visiting the TrustRegister documentation directly would be beneficial.

Treatment types

The following screenshot shows the “Treatment Types.”

TR - Treatment Type

Remediation

Remediation is a risk treatment type that addresses the root cause of a risk by implementing a control that fully or nearly eliminates the risk. This approach typically involves adding new controls or fixing underlying issues as part of the next risk assessment.

Example
A vulnerability is identified on a server storing critical assets. Applying a security patch to address this vulnerability is a remediation action, as it directly resolves the issue and reduces the associated risk.

Mitigation

Mitigation involves reducing the likelihood and/or impact of a risk without fully eliminating it. This approach includes adding more controls or developing a risk treatment plan independent of controls during the next risk assessment.

Example
A vulnerability is identified on a server storing critical assets. Instead of patching the vulnerability, a firewall rule is implemented to restrict access, allowing only specific systems to communicate with the vulnerable service. This reduces the risk but does not fully eliminate it.

Transference

Transference involves shifting the financial burden of a risk to another entity, typically through insurance or contractual agreements. This approach does not reduce the likelihood of the risk occurring but ensures that the organization can recover from the costs if the risk materializes.

Example
A company purchases a cyber insurance policy to cover potential financial losses if vulnerable systems are exploited.

Acceptance

Acceptance involves acknowledging a risk without taking action to mitigate or transfer it. This approach is appropriate when the potential impact is minimal or when the cost of mitigation exceeds the potential damage. Organizations choosing this option may need to justify their decision to auditors.

Example
A vulnerability is identified on a server, but after assessment, it is determined that the server contains no sensitive data, cannot be used to access critical assets, and would be difficult to exploit. Given these factors, the organization decides not to allocate resources to address the vulnerability.

Avoidance

Avoidance involves eliminating exposure to a risk by discontinuing the associated activity or addressing the root cause. This may require documentation or justification for auditors.

Example

An organization identifies that certain servers are running outdated operating systems that will no longer receive security patches. These servers store both sensitive and non-sensitive data. To avoid the risk of sensitive data being compromised, the organization migrates the sensitive data to secure, up-to-date servers. The older servers continue to process non-sensitive data while a decommissioning plan is implemented. By removing sensitive data from vulnerable systems, the organization successfully avoids the risk.

To learn more about TrustRegister, click here!

Join the conversation

You might also be interested in

Treatment plans and tasks

Treatment plans and tasks are components that outline strategies and specific actions to address...

Connected controls

Control effectiveness refers to how ‘effective’ your selected controls are at mitigating the risk....

Controls vs treatment plans

The balance between controls and treatment plans can be set with TrustRegister....

Residual risk

Residual risk is a key measure of risk before or after treatment or mitigation...

Treating risks

Treating risks is made easy with TrustRegister. The "Treatment Plan" tab in TrustRegister is...

Mitigation and treatment plans

Mitigation and treatment plans stand as the linchpins of effective risk management, central to...

Risk Details

Risk details encapsulate the intricacies of potential threats. These concise entries provide a snapshot...

Assessments

The Assessments tab in TrustRegister provides crucial insights into each identified risk, detailing the...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue