Creating a treatment plan
A treatment plan turns planned controls into scheduled work. Create one from a risk’s Treatment Plans tab, or from the Treatment Plans section directly.
Before you start
Attach the planned controls to the risk first. The plan is built around them, and a plan with no controls has nothing to deliver.
Step 1 — Plan details
- Name the plan after the outcome, not the activity. “Eliminate shared admin accounts”, not “Access review project”.
- Set the plan owner — accountable for delivery, and usually not the risk owner.
- Set the target date. If the risk is above appetite, this date is what your governance obligation is measured against.
- Choose how the plan connects to Jira. See Working with Jira issues — this decision is easier to make now than to change later.
Step 2 — Actions
Break the plan into actions. Each action carries an owner, a due date, and optionally a link to the control it implements.
Actions can be nested into tasks and sub-tasks, which is what produces the rollup percentage you see on the plan and on the risk.
Keep actions small enough to finish. An action called “Implement MFA” sits at 40% for a year. Three actions — pilot, rollout, enforce — tell you where you actually are.
Importing from a control or a risk
Rather than typing actions by hand, you can import them:
- Import from control — pull the implementation steps recorded on the control.
- Import from risk — pull every planned control on the risk as a starting action list.
After creating
The plan appears on the risk, and the risk appears on the plan. Progress on the plan feeds the control’s implementation status, which in turn feeds the target score.