GlossaryISO 27001

ISO 27005

Short answer

ISO 27005 is the international guidance standard for information security risk management. It explains how to identify, analyse, evaluate and treat information security risks in a way that meets ISO 27001 requirements. It provides guidance only and cannot be certified.

What it covers

The full risk management cycle: establishing the context and risk criteria, identifying risks, analysing their likelihood and consequences, evaluating them against acceptance criteria, deciding on treatment, accepting residual risk, communicating with stakeholders and monitoring over time. It also includes examples of threats, vulnerabilities and typical risk scenarios.

The 2022 edition

The current edition, published in 2022, is aligned with ISO 27001:2022 and with the general risk management standard ISO 31000. It describes two complementary ways to identify risks: an event based approach, which starts from strategic scenarios and risk sources, and an asset based approach, which starts from assets, threats and vulnerabilities.

How it is used

ISO 27001 requires a risk assessment process but does not prescribe a method. ISO 27005 gives organisations a recognised way to design one that auditors will understand. It is guidance, so it cannot be certified and companies are free to adapt it.

Other methods

In Spain, the MAGERIT methodology and the CCN's PILAR tool are widely used, especially for the ENS. Other options include NIST guidance and the French EBIOS method. The choice matters less than applying a method consistently and keeping the risk assessment up to date.

Related terms

Keep reading on this topic

ISO 27001 information security management: scope, risk treatment, Annex A controls, internal audit and the certification audit process, explained.

Go to the topic hub