GuideGlobalISO/IEC 27005

ISO/IEC 27005 Using the Guidance in an ISMS

Use ISO/IEC 27005:2022 to design and operate the information security risk process required by an ISO/IEC 27001 information security management system (ISMS). ISO/IEC 27001 sets the requirements; ISO/IEC 27005 explains implementation choices without prescribing one risk method.

ISO/IEC 27005 is not a standalone certification scheme or law. A contract, policy, regulator, or other legal instrument can still require an organization to use a standard or particular risk practices.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use ISO/IEC 27005:2022 to operate the ISO/IEC 27001 risk requirements as a repeatable process. Define the scope, context, basic interested-party requirements, and risk criteria; assess risks consistently; choose and implement treatment; obtain risk-owner decisions; retain the required documented information; and reassess at planned intervals or after significant change. The organization may choose its method, but the method must produce consistent, valid, and comparable results.

Section 1

How does ISO/IEC 27005 support an ISO/IEC 27001 ISMS?

ISO/IEC 27001 requires an organization to establish and maintain risk criteria, apply a defined assessment process, identify risk owners, select treatment, determine necessary controls, compare those controls with Annex A, produce a Statement of Applicability, obtain risk-owner approval of treatment plans and residual-risk decisions, and retain documented information about the processes and results. ISO/IEC 27005 supplies guidance for carrying out those steps.

ISO/IEC 27005 does not prescribe a single qualitative, quantitative, or semiquantitative method. The organization should select a method suited to its context and use it consistently enough to produce valid and comparable results. ISO/IEC 27002 has a different role: it gives control guidance and does not replace risk assessment or make every control applicable.

ISO/IEC 27005 applies to organizations of every type, size, and sector. Within an ISO/IEC 27001 implementation, top management sets and reviews risk appetite, authorized management approves acceptance criteria, risk owners manage assigned risks and approve treatment and acceptance decisions, and control or action owners implement and evidence the plan. Certification bodies assess conformity with ISO/IEC 27001 within the stated scope; they do not certify an organization to ISO/IEC 27005.

  • Start with the scope, internal and external context, interested-party requirements, objectives, and basic requirements before scoring risk.
  • Assign each identified risk to a risk owner who understands the issue and has authority to make treatment and acceptance decisions.
  • Choose controls because they are necessary for treatment, then check them against ISO/IEC 27001 Annex A and document inclusion or exclusion in the Statement of Applicability.
  • Treat legal, regulatory, contractual, sector-standard, and internal security requirements as context inputs. ISO/IEC 27005 guidance does not itself decide whether another authority makes a particular practice binding.
Section 2

Which risk-management records should the ISMS retain?

ISO/IEC 27001 requires documented information about the risk assessment and treatment processes and their results. Process records should define the criteria, explain how the method supports consistent, valid, and comparable results, describe identification and ownership, and state how analysis, evaluation, control selection, Annex A comparison, treatment planning, and approval work. Result records should show each identified risk and owner, consequence and likelihood, criteria result, treatment priority, necessary controls, Statement of Applicability, treatment plan, implementation evidence, residual-risk decision, and later reassessment.

Keep enough rationale to reproduce the decision. Record the evidence and assumptions used, method or scale version, date, accountable owner, delegated approval authority, treatment status, acceptance conditions, and review trigger. A completed template without evidence that these decisions occurred does not show that the process operated.

  • Separate process documents, such as the method and criteria, from result records, such as assessments, plans, approvals, and reassessments.
  • Keep the links between a risk, its treatment controls, the Statement of Applicability, the treatment plan, and the residual-risk decision.
  • Protect sensitive risk information and control access according to the audience's need to know.
  • Keep evidence that planned assessments occurred. When a significant change is proposed or occurs, retain the assessment or the documented reason why the organization determined that no additional assessment was needed.
Section 3

How does the risk-management cycle operate?

Establish context and risk criteria first. Identify risks and owners, analyse consequence and likelihood, determine each level of risk, and compare the result with the criteria. For risks that need treatment, choose avoidance, modification, sharing, or informed retention as applicable; determine the necessary controls; compare them with Annex A; prepare the Statement of Applicability and treatment plan; and obtain the risk owner's approval and residual-risk decision. Information security treatment does not use the general-risk option of increasing risk to pursue an opportunity.

Assessment and treatment can iterate. If information is insufficient, return to assessment. If proposed treatment does not reduce risk to an acceptable level, revise treatment or reassess the relevant scope. Communication, documented information, monitoring, and review continue across the cycle rather than occurring only at the end.

  • Assessment output: evaluated risks, named owners, analysis rationale, and treatment priorities.
  • Treatment output: necessary controls, Statement of Applicability, treatment plan, named implementers, resources, dates, monitoring measures, implementation evidence, and residual-risk assessment.
  • Decision output: risk-owner approval, acceptance or rejection, any higher-authority endorsement, conditions, and the next review trigger.
Section 4

Which boundary mistakes should teams avoid?

Do not describe an organization as certified to ISO/IEC 27005. ISO identifies ISO/IEC 27001 as the requirements standard used for certification, while ISO/IEC 27005 is implementation guidance. Also avoid treating an ISO standard as law by itself; check the organization's legislation, regulator instructions, contracts, and policies for any separate obligation to use it.

  • Do not start with Annex A controls and work backward without first determining what treatment is necessary.
  • Do not claim that a risk matrix alone satisfies the process; criteria, evidence, owners, decisions, and treatment records still matter.
  • Do not use a low combined score to bypass extreme-consequence, high-likelihood, legal, contractual, or other criteria that the organization evaluates separately.
Section 5

When should the ISMS risk process be reviewed?

Perform risk assessments at planned intervals and when significant changes are proposed or occur. ISO/IEC 27005 sets no universal annual deadline. The organization chooses intervals appropriate to its and should schedule routine work early enough to support funding, procurement, implementation, and effectiveness testing. Review can also be triggered by changes to the ISMS scope or context, objectives, interested-party requirements, business processes, assets, suppliers, threat landscape, vulnerabilities, incidents, controls, criteria, or delegated authority.

Monitor whether assumptions remain valid, controls were implemented and work as intended, treatment deadlines are being met, and accepted risks remain within their approval conditions. A changed factor does not automatically change the rating, but it should prompt the owner to decide whether reassessment is needed.

  • Set planned intervals that fit the and the organization's business, procurement, and budget cycles.
  • Name the person who monitors each trigger and the evidence that starts a reassessment.
  • Retain the prior decision, changed inputs, new result, approval, and effective date.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO's official ISO/IEC 27001 page identifies that standard as ISMS requirements and uses the wording 'certified to ISO/IEC 27001:2022.'
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO identifies ISO/IEC 27002:2022 as information security control guidance, distinct from the ISMS requirements in ISO/IEC 27001 and risk guidance in ISO/IEC 27005.
"Information security controls"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 Clauses 9 and 10.5 call for planned or event-driven assessment and monitoring of context, assets, threats, vulnerabilities, consequences, likelihood, controls, and acceptance criteria.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.