What it covers
The full risk management cycle: establishing the context and risk criteria, identifying risks, analysing their likelihood and consequences, evaluating them against acceptance criteria, deciding on treatment, accepting residual risk, communicating with stakeholders and monitoring over time. It also includes examples of threats, vulnerabilities and typical risk scenarios.
The 2022 edition
The current edition, published in 2022, is aligned with ISO 27001:2022 and with the general risk management standard ISO 31000. It describes two complementary ways to identify risks: an event based approach, which starts from strategic scenarios and risk sources, and an asset based approach, which starts from assets, threats and vulnerabilities.
How it is used
ISO 27001 requires a risk assessment process but does not prescribe a method. ISO 27005 gives organisations a recognised way to design one that auditors will understand. It is guidance, so it cannot be certified and companies are free to adapt it.
Other methods
In Spain, the MAGERIT methodology and the CCN's PILAR tool are widely used, especially for the ENS. Other options include NIST guidance and the French EBIOS method. The choice matters less than applying a method consistently and keeping the risk assessment up to date.




