FAQGlobalISO/IEC 27005

ISO/IEC 27005 FAQ

ISO/IEC 27005:2022 explains how to establish context and criteria, identify and assess information security risks, choose treatment, accept residual risk, and keep the process under review.

It supports the information security risk requirements in ISO/IEC 27001. ISO/IEC 27005 does not prescribe one scoring method and is not a standalone certification standard.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this FAQ to make and document ISO/IEC 27005:2022 risk decisions. Start each with its scope and purpose, apply approved consequence, likelihood, evaluation, and acceptance criteria, then record treatment, residual-risk acceptance, ownership, and review triggers.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items32
Focused FAQ modules
8
Showing 8 of 8
Question 1

What does ISO/IEC 27005 cover?

ISO/IEC 27005:2022 covers the full information security risk management cycle. An assessment identifies risk scenarios and owners, analyses consequence and likelihood, evaluates the result against risk criteria, and prioritizes treatment. Treatment then selects options and controls, plans implementation, evaluates the remaining risk, and obtains the required approvals.

The standard supports ISO/IEC 27001:2022 requirements. ISO/IEC 27001 sets the management-system requirements; ISO/IEC 27005 supplies guidance and examples for carrying them out. ISO/IEC 27002 provides control guidance and does not decide which controls are necessary for a particular risk.

  • Define the scope, purpose, internal and external context, interested-party requirements, and risk criteria before assessing scenarios.
  • Identify a risk owner with the accountability, authority, and knowledge needed to manage each risk.
  • Use a method that produces consistent, valid, comparable results, while tailoring scales and criteria to the organization's context.
  • Keep communication, documented information, monitoring, and review active across identification, assessment, treatment, and acceptance rather than adding them only at the end.
Question 2

Which records answer common review questions?

Keep enough documented information to reproduce the decision, not merely the final score. Separate the controlled process description from result records. The process description covers criteria, method, ownership, analysis, evaluation, control selection, Annex A comparison, treatment planning, and approval. Result records connect those rules to the scenario, risk owner, control evidence, analysis, evaluation, treatment, residual-risk decision, communications, and later review.

  • For consequence, record the affected objectives, confidentiality, integrity, or availability loss, units or scale used, assumptions, and possible cascading effects.
  • For likelihood, record relevant history or statistics, threat capability and motivation where applicable, vulnerabilities, exposure, existing-control effectiveness, dependencies between events, and uncertainty.
  • For treatment and acceptance, record the option, necessary controls, implementation owner, expected and actual residual risk, risk-owner approval, conditions, time limits, and review trigger.
Question 3

How should teams use this FAQ?

Begin with the decision that is blocked. Use the relevant topic page to collect the missing evidence, then apply the organization's approved context, method, and criteria. Route the result to risk evaluation, treatment, acceptance, or review rather than treating an FAQ answer as the decision itself.

  • Use asset and scenario modeling to describe the risk before estimating consequence and likelihood.
  • Separate the risk owner's approval of a treatment plan from the later decision to accept residual risk.
  • Set both a planned review date and event-driven triggers, then update the assessment and treatment when those triggers occur.
Question 4

Which common misunderstandings should teams avoid?

Do not treat an FAQ answer, template, or heat map as a substitute for the licensed standard or the organization's defined process. ISO/IEC 27005 permits qualitative, quantitative, and semiquantitative analysis and does not prescribe a universal scoring matrix.

  • Do not describe ISO/IEC 27005 guidance as legislation or as a standalone certification requirement.
  • Do not combine unrelated scenarios only to produce one corporate score when they require different controls.
  • Do not assume that sharing risk through insurance or a contract removes the organization's remaining exposure or legal duties.
  • Do not treat accepted risk as closed; accepted risks remain subject to monitoring and review.
Question 5

When should these answers be revisited?

Revisit the applicable decision when its assumptions or evidence change, not only when a calendar date arrives. Strategic reviews address changes in organizational context, objectives, business assets, risk sources, threats, and consequences. Operational reviews update detailed scenarios and treatment on a shorter cycle determined by the risks involved.

  • Schedule routine assessment early enough to support budget, procurement, and treatment implementation cycles.
  • Trigger review after major change, an incident, new threat or vulnerability information, unexpected control testing, changed ownership or criteria, or evidence that treatment is ineffective.
  • Preserve the previous decision, changed inputs, new result, owner, approval, and effect on treatment or acceptance.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO identifies ISO/IEC 27001 as the ISMS requirements standard.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 Clauses 5.2, 9, and 10.8 support regular and change-driven review, strategic and operational cycles, and monitoring of criteria and treatment.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.