How should teams set a review cadence under ISO/IEC 27005?
The covers changes in the overall context: business assets, objectives, risk sources, threats, and consequences. It should run on a longer time basis or when major changes occur and can lead to an overall update or a new assessment.
The updates detailed assessments, scenarios, criteria, and related treatment. Its interval should be shorter and should depend on how quickly the identified risks, controls, and treatment can change. Different assessments can therefore have different review intervals.
- Set a planned date for each assessment, accepted risk, treatment plan, and time-limited exception.
- Define event triggers for major change, incidents, new threats or vulnerabilities, unexpected control results, ineffective treatment, and changed criteria.
- Schedule routine assessments early enough to support budgeting, procurement, implementation, and later effectiveness testing.
- Example: if treatment funding must enter an annual budget and procurement cycle, assess before the funding request, reassess after allocation, and review again after implementation and effectiveness testing. This sequence does not make annual review the default for every risk.
- Review low and retained risks both individually and in aggregate where repeated minor events can produce a material cumulative consequence.
How often does ISO/IEC 27005 require risk reviews?
ISO/IEC 27005:2022 does not prescribe one monthly, quarterly, or annual interval. Perform risk assessments at planned intervals appropriate to the ISMS and when are proposed or occur. Use a longer for changes in organizational context and a shorter for detailed scenarios and treatment, then set the actual dates from the speed of change, decision timetable, and risk evidence.
What events should trigger an early ISO/IEC 27005 review?
Review before the next scheduled date when a change can alter the scenario, asset value, consequence, threat, vulnerability, likelihood, control effectiveness, treatment option, acceptance criteria, or business objective. Examples include incidents and near misses, new vulnerabilities, unexpected audit or control-test results, changed laws, new assets or technologies, ineffective treatment, and a material change in risk appetite.
Is an annual risk review enough for ISO/IEC 27005?
An annual review can be one planned interval, but it is not enough when material change occurs sooner. The organization should keep event triggers active between scheduled reviews and should be able to show either the associated reassessment or why a proposed or completed change was not significant.
ISO/IEC 27005:2022 Clauses 5.2 and 9 distinguish strategic and operational cycles and connect routine assessments to business, budget, procurement, and treatment timing.