ISO/IEC 27005Free Resource

ISO/IEC 27005 Implementation guides, decision points, and evidence records

ISO/IEC 27005:2022 gives organizations of every type, size, and sector guidance for managing information security risk in support of an ISO/IEC 27001 information security management system (ISMS). It is aimed at organizations implementing or improving an ISMS and at ISMS professionals, risk owners, and other people involved in risk decisions. The standard is guidance, not a law, required scoring formula, or standalone certification scheme, although legislation, a regulator, a contract, or an internal policy can create a separate obligation to use it.

By Sorena AIFourth edition (2022)No signup required
Quick scan
ISO/IEC 27005
Risk criteria
Define consequence, likelihood, level-of-risk, acceptance, exception, time-limit, and delegated-authority rules.
Scenario-based assessment
Describe a causal path from source or event to an unwanted consequence, then assess it with scope-specific evidence.
Review and approval
Keep the owner, plan version, control status, residual assessment, authority, conditions, and reassessment trigger traceable.

Use this hub as implementation guidance. Organizations can certify an ISMS against ISO/IEC 27001; ISO/IEC 27005 explains how to operate the supporting risk process. ISO/IEC 27002 supplies control guidance, while the risk assessment determines which controls are necessary.

Key dates
Guides
Deep pages
FAQ
Standalone answers
Compare
Side-by-side
Evidence
Reusable
What this hub helps you do
Scope and criteria
Set the assessment purpose and boundary, applicable legal and contractual requirements, consequence and likelihood scales, acceptance rules, and decision authority before scoring starts.
Identify and assess
Use event-based or asset-based identification, assign an authorized , and tie consequence and likelihood to current evidence, existing controls, and stated uncertainty.
Treat, decide, and review
Select necessary controls, approve the treatment plan, distinguish forecast from achieved , record the acceptance decision, and monitor planned and event-driven triggers.
Scope
Evidence
Review
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

ISO lists the fourth edition as published on 25 October 2022 and the 2018 edition as withdrawn. There is no ISO/IEC 27005 transition deadline or fixed reassessment interval. Define context, basic interested-party requirements, and risk criteria first. Then identify risks and owners; analyse consequence and likelihood; evaluate against the criteria; select, plan, and implement treatment; obtain the 's approval of the plan and decision on ; and keep the process communicated, recorded, monitored, and reviewed.

Recommended path

Follow the risk decision from context to review

Start with how ISO/IEC 27005 supports an ISMS, then define the method and criteria, identify and assess scenarios, plan and implement treatment, approve or reject , and preserve enough evidence to reproduce each decision.

3

Assess and record risks

Identify risks to confidentiality, integrity, and availability; assign authorized owners; analyse consequence and likelihood; evaluate against every applicable rule; and retain the rationale.

4

Treat and accept risk

Choose necessary controls, compare them with Annex A, track implementation and effectiveness, reassess the remaining risk, and route the decision to the authorized owner.

Next step

Run a cited ISO/IEC 27005 workflow

Route ISO/IEC 27005 implementation into owned tasks, evidence requests, and review checkpoints so standards work does not remain scattered across documents.

What this unlocks
  • Start from the ISO/IEC 27005 page that matches the decision or evidence gap.
  • Use Research Copilot for interpretation questions tied to cited sources.
  • Use SSOT to keep evidence, owners, and review history governed.