- ISO identifies ISO/IEC 27001 as the ISMS requirements standard.
"Information security management systems — Requirements"
ISO/IEC 27005:2022 explains how to establish context and criteria, identify and assess information security risks, choose treatment, accept residual risk, and keep the process under review.
It supports the information security risk requirements in ISO/IEC 27001. ISO/IEC 27005 does not prescribe one scoring method and is not a standalone certification standard.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use this FAQ to make and document ISO/IEC 27005:2022 risk decisions. Start each with its scope and purpose, apply approved consequence, likelihood, evaluation, and acceptance criteria, then record treatment, residual-risk acceptance, ownership, and review triggers.
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005:2022 covers the full information security risk management cycle. An assessment identifies risk scenarios and owners, analyses consequence and likelihood, evaluates the result against risk criteria, and prioritizes treatment. Treatment then selects options and controls, plans implementation, evaluates the remaining risk, and obtains the required approvals.
The standard supports ISO/IEC 27001:2022 requirements. ISO/IEC 27001 sets the management-system requirements; ISO/IEC 27005 supplies guidance and examples for carrying them out. ISO/IEC 27002 provides control guidance and does not decide which controls are necessary for a particular risk.
Keep enough documented information to reproduce the decision, not merely the final score. Separate the controlled process description from result records. The process description covers criteria, method, ownership, analysis, evaluation, control selection, Annex A comparison, treatment planning, and approval. Result records connect those rules to the scenario, risk owner, control evidence, analysis, evaluation, treatment, residual-risk decision, communications, and later review.
Define owner, evidence requirements, evidence requests, and the next review date before approval.
Create accountable tasks, evidence requests, and review checkpoints from the risk decisions.
Review your current scope, evidence gaps, and next implementation steps.
Begin with the decision that is blocked. Use the relevant topic page to collect the missing evidence, then apply the organization's approved context, method, and criteria. Route the result to risk evaluation, treatment, acceptance, or review rather than treating an FAQ answer as the decision itself.
Do not treat an FAQ answer, template, or heat map as a substitute for the licensed standard or the organization's defined process. ISO/IEC 27005 permits qualitative, quantitative, and semiquantitative analysis and does not prescribe a universal scoring matrix.
Revisit the applicable decision when its assumptions or evidence change, not only when a calendar date arrives. Strategic reviews address changes in organizational context, objectives, business assets, risk sources, threats, and consequences. Operational reviews update detailed scenarios and treatment on a shorter cycle determined by the risks involved.
"Information security management systems — Requirements"
"Guidance on managing information security risks"