- ISO's official ISO/IEC 27001 page identifies that standard as ISMS requirements and uses the wording 'certified to ISO/IEC 27001:2022.'
"Information security management systems — Requirements"
Use ISO/IEC 27005:2022 to design and operate the information security risk process required by an ISO/IEC 27001 information security management system (ISMS). ISO/IEC 27001 sets the requirements; ISO/IEC 27005 explains implementation choices without prescribing one risk method.
ISO/IEC 27005 is not a standalone certification scheme or law. A contract, policy, regulator, or other legal instrument can still require an organization to use a standard or particular risk practices.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use ISO/IEC 27005:2022 to operate the ISO/IEC 27001 risk requirements as a repeatable process. Define the scope, context, basic interested-party requirements, and risk criteria; assess risks consistently; choose and implement treatment; obtain risk-owner decisions; retain the required documented information; and reassess at planned intervals or after significant change. The organization may choose its method, but the method must produce consistent, valid, and comparable results.
ISO/IEC 27001 requires an organization to establish and maintain risk criteria, apply a defined assessment process, identify risk owners, select treatment, determine necessary controls, compare those controls with Annex A, produce a Statement of Applicability, obtain risk-owner approval of treatment plans and residual-risk decisions, and retain documented information about the processes and results. ISO/IEC 27005 supplies guidance for carrying out those steps.
ISO/IEC 27005 does not prescribe a single qualitative, quantitative, or semiquantitative method. The organization should select a method suited to its context and use it consistently enough to produce valid and comparable results. ISO/IEC 27002 has a different role: it gives control guidance and does not replace risk assessment or make every control applicable.
ISO/IEC 27005 applies to organizations of every type, size, and sector. Within an ISO/IEC 27001 implementation, top management sets and reviews risk appetite, authorized management approves acceptance criteria, risk owners manage assigned risks and approve treatment and acceptance decisions, and control or action owners implement and evidence the plan. Certification bodies assess conformity with ISO/IEC 27001 within the stated scope; they do not certify an organization to ISO/IEC 27005.
ISO/IEC 27001 requires documented information about the risk assessment and treatment processes and their results. Process records should define the criteria, explain how the method supports consistent, valid, and comparable results, describe identification and ownership, and state how analysis, evaluation, control selection, Annex A comparison, treatment planning, and approval work. Result records should show each identified risk and owner, consequence and likelihood, criteria result, treatment priority, necessary controls, Statement of Applicability, treatment plan, implementation evidence, residual-risk decision, and later reassessment.
Keep enough rationale to reproduce the decision. Record the evidence and assumptions used, method or scale version, date, accountable owner, delegated approval authority, treatment status, acceptance conditions, and review trigger. A completed template without evidence that these decisions occurred does not show that the process operated.
Establish context and risk criteria first. Identify risks and owners, analyse consequence and likelihood, determine each level of risk, and compare the result with the criteria. For risks that need treatment, choose avoidance, modification, sharing, or informed retention as applicable; determine the necessary controls; compare them with Annex A; prepare the Statement of Applicability and treatment plan; and obtain the risk owner's approval and residual-risk decision. Information security treatment does not use the general-risk option of increasing risk to pursue an opportunity.
Assessment and treatment can iterate. If information is insufficient, return to assessment. If proposed treatment does not reduce risk to an acceptable level, revise treatment or reassess the relevant scope. Communication, documented information, monitoring, and review continue across the cycle rather than occurring only at the end.
Do not describe an organization as certified to ISO/IEC 27005. ISO identifies ISO/IEC 27001 as the requirements standard used for certification, while ISO/IEC 27005 is implementation guidance. Also avoid treating an ISO standard as law by itself; check the organization's legislation, regulator instructions, contracts, and policies for any separate obligation to use it.
Perform risk assessments at planned intervals and when significant changes are proposed or occur. ISO/IEC 27005 sets no universal annual deadline. The organization chooses intervals appropriate to its and should schedule routine work early enough to support funding, procurement, implementation, and effectiveness testing. Review can also be triggered by changes to the ISMS scope or context, objectives, interested-party requirements, business processes, assets, suppliers, threat landscape, vulnerabilities, incidents, controls, criteria, or delegated authority.
Monitor whether assumptions remain valid, controls were implemented and work as intended, treatment deadlines are being met, and accepted risks remain within their approval conditions. A changed factor does not automatically change the rating, but it should prompt the owner to decide whether reassessment is needed.
Define owner, evidence requirements, evidence requests, and the next review date before approval.
Convert the ISO/IEC 27005 risk process into accountable tasks, evidence requests, and review checkpoints.
Review your ISO/IEC 27005 scope, evidence gaps, and next implementation steps.
"Information security management systems — Requirements"
"Information security controls"
"Guidance on managing information security risks"