FAQGlobalISO/IEC 27005

ISO/IEC 27005 FAQ Likelihood

Estimate the chance of each defined scenario and consequence using established likelihood criteria. Consider risk-source frequency, threat capability and motivation, exposure, vulnerabilities, event dependencies, existing-control effectiveness, history, and uncertainty.

The standard supplies guidance rather than a mandatory scoring model, legal rule, or standalone certification scheme.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

means the chance of something happening. ISO/IEC 27005:2022 allows objective or subjective, qualitative or quantitative estimates, including probability or frequency over a stated period. Define the scale first, assess a specific scenario, and record the evidence and uncertainty behind the result.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

How should teams approach likelihood under ISO/IEC 27005?

Assess the of the identified scenario and its consequence with the organization's established criteria. ISO/IEC 27005 permits qualitative, quantitative, and semiquantitative analysis and does not require one universal probability scale or formula.

For deliberate threats, consider capability, motivation, resources, attractiveness, and the cost or benefit of the attack. For accidental or environmental sources, consider human factors, equipment failure, geography, and natural hazards. In every case, consider known weaknesses, , and evidence of how effectively existing controls operate.

  • Anchor labels such as low or high to unambiguous ranges or reference points and a stated time period.
  • Use expressed in probabilistic terms when aggregating likelihoods; frequency-based terms can still be used for communication.
  • Model dependent events as a sequence; do not multiply or compare them as if each event were independent.
  • Example: for denial of service, assess the threat landscape and the server's accessibility and vulnerability. The fact that malicious packets are certain after an attack begins does not establish how likely the attack itself is.
  • Treat events outside the predictably manageable range as extreme cases when a more precise estimate would not change the decision.

What does mean in ISO/IEC 27005?

is the chance of something happening. ISO/IEC 27005:2022 allows objective or subjective and qualitative or quantitative estimates, including probability or frequency over a stated period. Assess the defined risk scenario and consequence using the organization's established , existing-control evidence, and an explicit statement of uncertainty.

Does ISO/IEC 27005 require a particular formula or scale?

No. The standard permits qualitative, semiquantitative, and quantitative analysis. The chosen scale should cover the relevant range, use unambiguous categories such as a frequency over a stated period, and support consistent, valid, and comparable results. Only expressed in probabilistic terms can be used when aggregating likelihoods.

How should dependent events affect a estimate?

Identify the dependency before combining estimates. A later event can become inevitable once an earlier event occurs, so assessing both as independent events can distort the result. Start with the independent contributory events, model the conditional sequence, and aggregate only with a method that matches those relationships.

Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 defines likelihood broadly, and Clauses 7.3.1 and 7.3.3 explain qualitative, quantitative, and semiquantitative analysis, threat factors, controls, dependencies, and uncertainty.

Question 2

What evidence should support the likelihood decision?

Keep the scenario, time horizon, scale, evidence, existing controls and effectiveness, dependencies, assumptions, estimate, uncertainty, assessor, and review trigger together. A score without its time period and scale definition is not comparable.

  • Use relevant incident and near-miss history, threat intelligence, exposure data, vulnerability and exploit evidence, control tests, audit results, supplier evidence, and environmental or equipment data.
  • Separate personal uncertainty in judgment, methodological uncertainty in the model, and systemic uncertainty from limited knowledge of the event.
  • Use team assessment, external evidence, suitable scale resolution, and concrete anchors such as 'once a year' where they improve reliability.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clause 7.3.3 identifies relevant evidence and the three main sources of uncertainty, and recommends team assessment, external sources, suitable scales, and unambiguous categories.

Question 3

Who owns and approves likelihood decisions?

The risk owner remains accountable for the risk decision. Analysts and specialists can estimate , while system owners, control owners, threat specialists, suppliers, and operational teams provide evidence about exposure, vulnerabilities, control effectiveness, and event frequency.

  • Record the assessor and reviewers so later teams can distinguish evidence from judgment.
  • Resolve material differences through a team assessment or record the range and uncertainty.
  • Escalate when a changed moves the risk beyond the owner's acceptance authority.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 7.2.2 and 7.3.3 support accountable risk ownership and team-based likelihood assessment where judgment differs.

Question 4

When should likelihood be reviewed?

Review whenever the scenario, time horizon, risk source, threat environment, exposure, vulnerability, control effectiveness, or changes. Review can be strategic, operational, scheduled, or triggered by an event.

  • Trigger reassessment after a newly discovered vulnerability, unexpected audit or control-test result, changed threat actor, incident, material architecture change, or new frequency data.
  • Recalibrate scales when categories no longer match the organization's planning horizon or risk profile.
  • Record the changed input, new estimate, uncertainty, and effect on treatment or acceptance.
Citations
ISO/IEC 27005:2022 standard page

ISO/IEC 27005:2022 Clauses 7.3.3 and 10.5.2 identify changed scope, context, vulnerabilities, control results, threats, and other risk factors as review inputs.

Primary sources

References and citations

iso.org
Referenced sections
  • Official listing for ISO/IEC 27001:2022, which requires organizations to assess realistic likelihood for identified information security risks.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO/IEC 27005:2022 Clauses 7.3.3 and 10.5.2 identify changed scope, context, vulnerabilities, control results, threats, and other risk factors as review inputs.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.