Implementing ISO standards? Don't overlook GDPR. Try Cookiebot free →

ISO 27005

Information Security Risk Management

Management Systems Published: 2022

ISO 27005:2022 at a glance

Current edition
ISO/IEC 27005:2022 - Information security, cybersecurity and privacy protection — Guidance on managing information security risks
Published
2022
Status
Published
Type of standard
Guidance
Certifiable
No — used for reference and implementation, not certification
Previous edition
ISO/IEC 27005:2018
Official ISO page
View ISO 27005:2022 on iso.org
Last verified

Overview

Guidance on managing information security risks in support of an ISO/IEC 27001 information security management system; guidance only, not certifiable

ISO/IEC 27005:2022 provides guidance on managing information security risks. Its purpose is to help organizations meet the risk requirements of ISO/IEC 27001 — specifically the requirements to define a risk assessment process, perform risk assessments, and carry out risk treatment leading to a Statement of Applicability. The fourth edition, published in October 2022, replaced ISO/IEC 27005:2018 and was substantially restructured to align with both ISO/IEC 27001:2022 and ISO 31000:2018.

The document is guidance and contains no auditable requirements, so organizations cannot be certified to ISO/IEC 27005. Certification in this family is against ISO/IEC 27001. Practitioner qualifications based on ISO/IEC 27005 exist, but they certify individuals.

The structure follows the ISO 31000 process applied to information security: establishing the context and risk criteria (including risk acceptance criteria and criteria for performing assessments), risk identification, risk analysis, risk evaluation, risk treatment, and the supporting activities of communication and consultation, monitoring and review, and recording and reporting.

A distinguishing contribution of the 2022 edition is the explicit treatment of two complementary approaches to identifying risk. The event-based approach starts from strategic scenarios — considering the organization's context, its interested parties and plausible sources of risk — and works down. The asset-based approach starts from assets, threats and vulnerabilities and works up. The standard presents them as usable together, which resolves a long-standing methodological argument in ISMS practice.

The 2022 edition also strengthens the connection to the ISMS lifecycle: the role of the risk owner in approving the risk treatment plan and accepting residual risk, the derivation of the Statement of Applicability from risk treatment decisions, and the mapping of treatment options to the ISO/IEC 27002:2022 control set with its four themes (organizational, people, physical and technological controls) and its attributes.

Annexes provide practical material, including examples of risk criteria, techniques for assessing consequence and likelihood, and worked illustrations of both identification approaches. For a broader catalogue of assessment techniques, ISO/IEC 27005 is normally used alongside IEC 31010.

Related documents include ISO/IEC 27001 (ISMS requirements), ISO/IEC 27002 (information security controls), ISO/IEC 27003 (ISMS implementation guidance), ISO/IEC 27004 (monitoring and measurement), ISO/IEC 27035 (incident management) and ISO 31000 (generic risk management guidelines).

Purpose

To give practical guidance on identifying, analysing, evaluating and treating information security risks in a way that satisfies the risk-related requirements of ISO/IEC 27001 and follows the risk management model of ISO 31000.

Key Benefits

  • Directly supports the risk assessment and risk treatment requirements of ISO/IEC 27001
  • Aligns information security risk work with the generic ISO 31000 risk management model
  • Explains both event-based and asset-based risk identification and how to combine them
  • Clarifies the role of risk owners in approving treatment plans and accepting residual risk
  • Connects risk treatment decisions to the ISO/IEC 27002:2022 control set and the Statement of Applicability
  • Provides examples of risk criteria and consequence/likelihood scales that can be adapted
  • Helps organizations produce risk assessments that survive certification audit scrutiny
  • Applicable to organizations of any size and sector, including those not seeking certification
  • Provides consistent terminology for discussing risk between security, business and audit functions
  • Works with IEC 31010 where a wider range of assessment techniques is needed

Key Requirements

  • Note: ISO/IEC 27005 is guidance — it has no auditable requirements and cannot be certified against
  • Establish the context of the information security risk management activity, including its scope and boundaries
  • Define risk criteria, including risk acceptance criteria and criteria for performing risk assessments
  • Identify risks using an event-based approach, an asset-based approach, or both
  • Identify risk owners for each identified risk
  • Analyse risks by assessing potential consequences and likelihood, and determine levels of risk
  • Evaluate risks by comparing analysis results against risk criteria and prioritising for treatment
  • Select risk treatment options: modify, retain, avoid or share the risk
  • Determine the controls necessary to implement the chosen treatment options
  • Compare determined controls with ISO/IEC 27002 and produce a Statement of Applicability
  • Formulate a risk treatment plan and obtain risk owner approval and acceptance of residual risk
  • Communicate and consult with interested parties throughout the process
  • Monitor and review risks, risk criteria and the risk management process, including after significant change
  • Record and report risk management activities and outcomes

Who Needs This Standard?

Information security managers, ISMS implementers and internal auditors working with ISO/IEC 27001; risk managers integrating information security risk into enterprise risk management; and consultants or auditors who need a defensible, standards-based risk methodology.

Where to get ISO 27005

The full text of ISO 27005 is copyrighted and is sold by ISO and its national member bodies — buy the official edition on iso.org, or order the same document from your national standards body, often at a member price. Sites offering a free PDF of the complete standard are not authorised to distribute it, and the files circulating there are frequently superseded editions, partial scans or altered copies, with no way to tell which. What is legitimately free is the standard's page on iso.org: the abstract, the current edition and status, the table of contents, and a preview of the opening sections. This page summarises the scope and requirements of ISO 27005 in our own words; it does not reproduce the standard's text and is not a substitute for the published document.

Get our free implementation resources

Send me the implementation checklist for ISO 27005, plus an alert when this standard is revised, withdrawn or replaced. Free, no account needed.

We'll only email you about this standard. Unsubscribe anytime.

Looking to get certified?

You cannot be certified to ISO 27005 — it is guidance, and no accredited scheme exists for it. The closest standard you can certify against is ISO 27001 (Information Security Management Systems).

If that is the direction you are heading, tell us what stage you are at and we will put you in touch with people who work with it. Free and no obligation.

Get help with certification

In a hurry? You can also compare quotes from verified providers on CertBetter (affiliate link — we earn a commission, and it stays free for you).

Related Standards