Side-by-sideGlobalISO/IEC 27005

ISO/IEC 27005 ISO/IEC 27005 vs FAIR

Use ISO/IEC 27005 to govern the full information-security risk cycle. Use FAIR inside that cycle when a defined loss scenario needs factor-based quantitative analysis, usually in financial terms.

FAIR does not replace context, risk criteria, treatment, owner acceptance, communication, or review. Neither publication is itself a universal legal requirement or a standalone organizational certification.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27005:2022 and solve different parts of the problem. ISO/IEC 27005 governs context, assessment, treatment, acceptance, communication, recording, monitoring, and review. FAIR decomposes a defined loss scenario into factors so an analyst can estimate the probable frequency and magnitude of loss, commonly in financial terms. Most teams do not need to choose one exclusively: keep ISO/IEC 27005 as the governing process and use FAIR for decisions that benefit from quantified loss ranges.

Side-by-side comparison

ISO/IEC 27005 vs FAIR: practical differences

Compare purpose, scope, method, records, review, and reuse without treating voluntary guidance as a legal or standalone certification requirement.

Review all sources
First framework
ISO/IEC 27005

Guidance for managing information-security risk across context, assessment, treatment, acceptance, communication, recording, monitoring, and review.

Second framework
FAIR

A factor model and taxonomy commonly used to estimate the probable frequency and magnitude of loss, often in financial terms.

Comparison row 1

Purpose and scope

ISO/IEC 27005

Information-security risk management for organizations of any type or size, aligned with ISO/IEC 27001 and based on ISO 31000.

FAIR

A defined loss scenario that benefits from factor-based estimates of probable loss frequency and magnitude, commonly expressed in economic terms.

Operational implication

Use ISO/IEC 27005 for governance; add only where quantification improves a defined decision.

Comparison row 2

Ownership and decision authority

ISO/IEC 27005

Risk owners need accountability and authority; contributors can include management, process, functional, department, and asset owners plus business and technical specialists.

FAIR

Analysts build the model with people who understand the asset, threat, controls, operations, and loss exposure; the accountable risk owner uses the result.

Operational implication

Map analyst, treatment owner, risk owner, approver, and escalation roles instead of copying job titles between methods.

Comparison row 3

When to use it

ISO/IEC 27005

Use for planned and change-driven information-security risk decisions, including ISMS planning, operations, treatment, and review.

FAIR

Use where investment, prioritization, insurance, or acceptance decisions need defensible financial ranges rather than ordinal labels alone.

Operational implication

Apply the method when it improves a defined decision, not merely to produce another score or report.

Comparison row 4

Process

ISO/IEC 27005

Establish context and criteria; identify, analyse and evaluate risks; treat them; obtain owner approval and residual-risk acceptance; communicate, record, monitor, and review.

FAIR

Define the threat, asset, method, effect, stakeholder, and time horizon; estimate the factors that drive loss-event frequency and primary and secondary loss magnitude; calculate a range of outcomes; and test which inputs drive the result.

Operational implication

Place the analysis inside the ISO/IEC 27005 assessment step, then return the result to evaluation, treatment, acceptance, and review.

Comparison row 5

Evidence and records

ISO/IEC 27005

Context, criteria, method, scenarios, owners, analysis rationale, evaluation, treatment, necessary controls, approvals, residual-risk acceptance, communication, monitoring, and review.

FAIR

Scenario and time horizon, factor definitions, data sources, elicited estimates, ranges or distributions, assumptions, calculation settings, sensitivity, uncertainty, and decision use.

Operational implication

Reuse source evidence, but label the method, assumptions, criteria, and decision each record actually supports.

Comparison row 6

Review cycle

ISO/IEC 27005

Longer strategic cycles address context changes; shorter operational cycles update scenarios and treatment, with additional reviews after material change.

FAIR

Re-run when exposure, controls, threat frequency, loss data, business value, assumptions, or the decision materially changes.

Operational implication

Use planned and event-driven review rather than assuming one universal annual deadline.

Comparison row 7

Certification and assurance limits

ISO/IEC 27005

Guidance, not a standalone certification. ISO/IEC 27001 is the certifiable ISMS requirements standard; adopted 27005 practices can be examined as supporting evidence.

FAIR

A risk-analysis model, not an organizational certification or a universal legal compliance scheme. Confidence depends on scenario quality, transparent assumptions, suitable data, and review.

Operational implication

State the source of any binding, contractual, or certification requirement separately.

Comparison row 8

What can be reused

ISO/IEC 27005

Context, risk statements, evidence, owners, criteria inputs, treatment records, and monitoring can be mapped where definitions remain clear.

FAIR

Use results as one analysis method inside an ISO/IEC 27005-governed process, then evaluate them against criteria and route treatment and acceptance through risk owners.

Operational implication

Reuse facts and evidence; do not imply equivalence of methods, scores, or conformity claims without a documented mapping.

Comparison row 9

Decision rule

ISO/IEC 27005

Use ISO/IEC 27005 when the objective is a complete information-security risk cycle integrated with an ISMS.

FAIR

Use for a well-scoped loss scenario when quantified frequency and magnitude will change or clarify the decision.

Operational implication

Keep ISO/IEC 27005 as the governing cycle and use selectively for analysis; neither has to displace the other.

Practical decision rule

How should teams choose between ISO/IEC 27005 and FAIR?

  • Identify the governance or assurance context, the risk owner, and the decision the analysis must support.
  • Use when quantified loss ranges can change treatment, funding, insurance, prioritization, or acceptance; otherwise use a simpler method that remains valid and comparable.
  • Map the result to approved risk criteria, treatment records, residual-risk acceptance, and review triggers.
Section 1

How do ISO/IEC 27005 and FAIR differ?

ISO/IEC 27005:2022 is guidance for managing information-security risk in support of an ISO/IEC 27001 information security management system. Its process covers more than analysis: the organization establishes context and criteria, identifies owners, assesses and treats risks, decides whether residual risk is acceptable, records and communicates results, and monitors change.

is a risk-analysis model and taxonomy. It breaks a scoped loss scenario into related frequency and magnitude factors and is commonly used to express results in economic terms. The Open FAIR body of knowledge currently identifies Risk Analysis (O-RA) Version 2.0.1 and Risk Taxonomy (O-RT) Version 3.0.1 as its two standards. It can strengthen an ISO/IEC 27005 analysis, but it does not supply the surrounding ISMS governance or establish ISO/IEC 27001 conformity.

  • Choose ISO/IEC 27005 as the governing cycle when the work must connect assessment to treatment, acceptance, records, and review.
  • Add when a decision such as treatment funding, option comparison, insurance, or risk acceptance needs a quantified loss range.
  • Use a qualitative or semiquantitative method when it can produce a valid and comparable decision without the added data and analysis effort.
Section 2

Which records make the chosen approach reviewable?

Keep one decision record that connects the ISO/IEC 27005 process to the analysis. Record the scope, purpose, risk criteria, owner, scenario, time horizon, treatment options, approval, residual-risk decision, and review trigger. For FAIR, also retain factor definitions, source data, elicited estimates, ranges or distributions, assumptions, calculation or simulation settings, sensitivity results, and uncertainty.

A financial output is not self-validating. Reviewers need to see why the scenario was scoped as it was, which inputs came from data or expert judgment, how controls affected the factors, and whether the result is precise enough for the stated decision.

  • Link conclusions to current source evidence and assumptions.
  • Keep approval, version, date, owner, and review trigger with the decision.
  • Record uncertainty and exceptions instead of hiding them in a score.
Section 3

How can the two approaches work together?

Start with the ISO/IEC 27005 context, scope, risk criteria, and named risk owner. Define a specific loss scenario with the threat, asset, method, and effect that can produce loss, then apply to estimate loss-event frequency and loss magnitude over a stated period. Compare the resulting range with the organization's risk criteria and the cost and effect of treatment options.

Return the result to the ISO/IEC 27005 process. The risk owner decides whether to treat, avoid, share, or retain the risk under the organization's authority rules. Record the selected controls, treatment plan, residual-risk acceptance, communication, and monitoring conditions.

  • Scope: the analyst states the asset or process at risk, threat community, loss event, affected stakeholder, loss forms, and time horizon; broad labels such as "ransomware risk" are not enough.
  • Estimate: source data and calibrated expert judgment support ranges for the frequency and magnitude factors, with dependencies and uncertainty recorded rather than hidden in a point estimate.
  • Test: sensitivity analysis identifies which inputs drive the result and which treatment option changes those inputs.
  • Decide: the risk owner compares the range with approved criteria and treatment costs, then records treatment, acceptance, escalation, and review conditions in the ISO/IEC 27005 process.
Section 4

Which comparison mistakes should teams avoid?

Do not treat a estimate as the complete risk-management process or as evidence of ISO/IEC 27001 conformity. Do not turn ordinal labels such as 1-to-5 ratings into money by arithmetic alone. Quantification needs defined units, a time horizon, defensible inputs, and an explicit account of uncertainty.

Financial estimates can make unlike treatment options comparable, but some consequences may need separate non-financial measures or decision constraints. Record what the model excludes instead of forcing every effect into an unsupported monetary value.

  • Do not present guidance as a legal mandate or standalone certification requirement.
  • Do not confuse a template, matrix, or register with evidence that the process operated.
  • Do not leave ownership, rationale, residual risk, or review conditions implicit.
Section 5

When should the chosen approach be reviewed?

ISO/IEC 27005 calls for regular and change-driven updates rather than one universal annual deadline. Re-scope or re-run the analysis when the asset, threat community, control effectiveness, loss data, business value, assumptions, decision threshold, time horizon, or treatment option changes enough to affect the decision. Review the standards mapping when either the ISO/IEC 27005 edition or the O-RA or O-RT version changes.

  • Set a planned review date.
  • Define event-driven triggers and evidence owners.
  • Preserve change history so reviewers can understand why the decision changed.
Primary sources

References and citations

fairinstitute.org
Referenced sections
  • FAIR source for quantitative risk analysis comparison.
"Factor Analysis of Information Risk"
iso.org
Referenced sections
  • ISO's official listing identifies ISO/IEC 27001 as the certifiable ISMS requirements standard that ISO/IEC 27005 supports.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • Primary ISO listing for current ISO/IEC 27005 risk-management guidance.
"Guidance on managing information security risks"
opengroup.org
Referenced sections
  • The standards-owner overview explains how Open FAIR supports quantitative risk analysis and can be used with other risk standards.
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.