What Is ISO 27005?
ISO/IEC 27005 is an international standard published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) that provides guidelines for information security risk management. Unlike ISO 27001, which is a certifiable management systems standard, ISO 27005 is a guidance document. Organizations cannot be certified against ISO 27005 directly, but it is the primary reference for satisfying the risk assessment and risk treatment requirements embedded in ISO/IEC 27001.
ISO 27005 describes a structured process for establishing context, identifying and analyzing information security risks, evaluating those risks against acceptance criteria, and selecting appropriate treatment options. It does not prescribe a specific risk assessment methodology, which allows organizations to apply it alongside other frameworks such as NIST SP 800-30 or sector-specific risk models while still satisfying ISO 27001 clause 6.1.2 and clause 8.2 requirements.
Framework Metadata Block
- Governing Body: International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC)
- Current Version: ISO/IEC 27005:2022
- First Release Year: 2008
- Last Major Update: 2022 (fourth edition, aligned with ISO/IEC 27001:2022 and restructured around risk scenarios)
The 2022 revision moved away from the asset-threat-vulnerability model used in earlier editions and introduced an event-based and asset-based approach to defining risk scenarios, along with clearer guidance on iterative strategic and operational risk assessment cycles.
Why It Matters to Security & Compliance Leaders
For CISOs, vCISOs, and MSSP/MSP teams managing multiple client environments, ISO 27005 is not optional reading. It is the de facto interpretive guide for how auditors expect risk assessments to be structured under ISO 27001. Because ISO 27001 requires a "consistent, valid, and comparable" risk assessment approach without specifying the method, auditors frequently look to ISO 27005 as the benchmark for what a defensible risk management process looks like.
This matters directly for:
- Audit readiness. Auditors evaluating an ISMS under ISO 27001 will scrutinize whether the risk assessment methodology is documented, repeatable, and produces comparable results across assessment cycles.
- Enterprise procurement. Enterprise buyers and their vendor risk teams increasingly ask suppliers to describe their risk management methodology, not just list controls. A documented ISO 27005-aligned process answers that question credibly.
- Vendor risk assessments. MSSPs and MSPs supporting multiple clients benefit from a standardized risk process that scales across engagements without reinventing methodology per client.
- Regulatory alignment. Many sector regulations reference "risk-based" security programs without defining the process; ISO 27005 provides a recognized structure regulators and auditors accept.
Risks & Business Impact
Skipping or poorly documenting information security risk management carries direct consequences:
- Audit failure risk. ISO 27001 certification audits routinely cite inadequate or inconsistent risk assessment methodology as a nonconformity. A weak risk register or undocumented treatment rationale can delay or block certification.
- Contractual exposure. Enterprise contracts and cyber insurance applications increasingly require evidence of a formal risk management process. Absence of one can trigger contract renegotiation or coverage denial.
- Regulatory penalties. In sectors with risk-based regulatory expectations (financial services, healthcare, critical infrastructure), the inability to demonstrate a structured risk process can compound findings during regulatory examination.
- Operational burden. Ad hoc risk assessments that are not repeatable create rework every audit cycle, consuming security team time that could go toward remediation.
- Reputational risk. Enterprise customers and partners performing due diligence view a mature, ISO 27005-aligned risk program as a signal of security maturity; its absence can affect deal velocity.
- Security exposure. Beyond compliance optics, an unstructured risk process increases the likelihood that material risks go unidentified, unprioritized, or untreated.
Requirements & Control Expectations
ISO 27005 does not define named "controls" the way ISO 27002 does. Instead, it defines process expectations that support the risk-related requirements in ISO 27001:
- Context establishment. Defining risk criteria, evaluation criteria, impact criteria, and risk acceptance criteria before assessment begins.
- Risk identification. Identifying information assets, relevant threats and vulnerabilities, or risk scenarios (in the 2022 edition's event-based approach) that could lead to a loss of confidentiality, integrity, or availability.
- Risk analysis. Assessing likelihood and consequence for identified risks, using qualitative, quantitative, or semi-quantitative methods.
- Risk evaluation. Comparing analyzed risk levels against acceptance criteria to determine which risks require treatment.
- Risk treatment. Selecting from four treatment options: modify (apply controls), retain, avoid, or share (e.g., transfer via insurance or contract), and documenting the rationale.
- Documentation requirements. A documented risk assessment methodology, a risk register capturing identified risks and treatment decisions, and a Statement of Applicability reference back to ISO 27001 Annex A or ISO 27002 controls.
- Monitoring requirements. Ongoing risk communication, monitoring of risk indicators, and periodic review as required by ISO 27001 clause 9.
- Audit involvement. Internal auditors and certification body auditors will sample risk assessments to verify the methodology was applied consistently and that treatment decisions map to implemented controls.
Process Overview (Implementation Lifecycle)
- Readiness Assessment — Confirm ISMS scope and existing risk management maturity before applying ISO 27005 guidance.
- Gap Analysis — Compare current risk assessment practices (if any) against ISO 27005's context-establishment and risk-scenario requirements.
- Remediation — Build or refine the risk assessment methodology, risk criteria, and risk register structure.
- Control Testing — Validate that selected risk treatments are actually implemented as documented controls, typically mapped to ISO 27002.
- Audit or Certification — Undergo internal audit and, where applicable, ISO 27001 certification audit, where the risk assessment methodology is reviewed for consistency and defensibility.
- Ongoing Monitoring — Reassess risks on a defined cadence, track changes to the threat landscape and business context, and update the risk register accordingly.
Common Misconceptions
- "You can get certified to ISO 27005." ISO 27005 is a guidance standard, not a certifiable management systems standard. Certification applies to ISO 27001, not ISO 27005.
- "ISO 27005 mandates a specific risk methodology." It does not. ISO 27005 supports multiple methodologies (qualitative, quantitative, asset-based, event-based) as long as the approach is documented and consistently applied.
- "ISO 27005 and ISO 27001 risk requirements are separate exercises." ISO 27005 exists specifically to support ISO 27001's risk assessment and treatment clauses; they are meant to be applied together, not independently.
- "Risk assessment is a one-time project." ISO 27005 frames risk management as an iterative cycle with both strategic and operational review points, not a single point-in-time exercise.
- "ISO 27005 only applies to large enterprises." The standard is explicitly written to apply to organizations of any type, size, or sector.
Framework Relationships & Crosswalks
ISO 27005 intersects with several adjacent frameworks that compliance leaders manage in parallel:
- ISO 27001: ISO 27005 directly supports ISO 27001's risk assessment and risk treatment clauses (6.1.2 and 8.2/8.3). Most organizations pursuing ISO 27001 certification use ISO 27005 as their risk methodology reference.
- ISO 27002: After risk treatment decisions are made under an ISO 27005-aligned process, the selected controls are typically drawn from ISO 27002's control catalog.
- NIST: NIST SP 800-30 provides a comparable risk assessment methodology used heavily in U.S. federal and regulated environments; organizations subject to both ISO and NIST expectations often crosswalk the two rather than choose one exclusively.
- HIPAA: The HIPAA Security Rule requires a risk analysis; an ISO 27005-aligned risk process can support (though not replace) that legally mandated analysis.
- PCI DSS: PCI DSS requires an annual risk assessment process; organizations already running ISO 27005-based risk management can often reuse much of that documentation for PCI evidence.
- CMMC: CMMC's risk-informed control implementation expectations align conceptually with ISO 27005's context-and-treatment approach, though CMMC follows NIST 800-171 for its actual control set.
- GDPR: GDPR's requirement for appropriate technical and organizational measures is often supported by an ISO 27005-based risk assessment, particularly for Data Protection Impact Assessments.
These relationships support alignment across standards rather than equivalency; a risk assessment performed under ISO 27005 does not automatically satisfy every requirement of these other frameworks.
How Compliance Automation Platforms Support This
Maintaining an ISO 27005-aligned risk management process manually across spreadsheets becomes difficult to sustain once an organization is managing multiple frameworks or client environments. Compliance automation platforms support this work in several ways:
- Control mapping between identified risks, selected treatments, and the specific ISO 27002 or ISO 27001 Annex A controls implemented to address them.
- Evidence collection that ties risk treatment decisions to the artifacts auditors expect to see (policies, configurations, test results).
- Cross-framework alignment, so a single risk assessment can inform control status across ISO 27001, SOC 2, and other frameworks in parallel rather than being re-run per standard.
- Continuous monitoring of risk-relevant control status rather than relying solely on point-in-time assessments.
- Reporting that presents the risk register, treatment status, and residual risk in a format auditors and executive stakeholders can both use.
Apptega's Risk Manager and framework crosswalking capabilities help MSSPs, MSPs, and internal security teams operationalize an ISO 27005-style risk process without maintaining it entirely by hand, keeping risk data connected to the controls it justifies.
Real-World Use Cases
- MSSPs: Standardizing a single ISO 27005-aligned risk methodology across dozens of clients so risk assessments remain consistent and defensible during each client's respective audits.
- SaaS providers: Using ISO 27005 to support both ISO 27001 certification and the risk assessment expectations embedded in customer security questionnaires and SOC 2 examinations.
- Healthcare organizations: Layering an ISO 27005-based process on top of the HIPAA-required risk analysis to give the assessment more structure and audit defensibility.
- Financial services firms: Using ISO 27005 to satisfy risk-based expectations from regulators while also supporting PCI DSS's mandated annual risk assessment.
- Government contractors: Applying ISO 27005 principles alongside NIST SP 800-30 where contracts require both ISO alignment and federal risk assessment documentation.