Risk treatment planning is a cybersecurity control or practice. It supports this objective: documents whether identified risk will be mitigated, transferred, avoided, or accepted. The implementation should still be validated against the organization's risk, architecture, legal obligations and operating constraints, then adapted rather than copied unchanged between environments.NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework