Use ISO 31000 to set organization-wide risk principles, governance, and a common process. Use ISO/IEC 27005 to apply that process to information-security risk and connect it to an ISO/IEC 27001 ISMS.
The standards are complementary guidelines. ISO 31000 cannot be used for certification, and ISO/IEC 27005 is not a standalone organizational certification.
:2018 provides organization-wide principles, a framework, and a process for managing any type of risk. ISO/IEC 27005:2022 adapts that general process to information-security risk and supports an ISO/IEC 27001 information security management system. Most organizations should use them together: align governance, authority, appetite, terminology, reporting, and escalation under ISO 31000, then use ISO/IEC 27005 for security-specific criteria, scenarios, treatment, acceptance, records, and review.
Side-by-side comparison
ISO/IEC 27005 vs ISO 31000: practical differences
Compare purpose, scope, method, records, review, and reuse without treating voluntary guidance as a legal or standalone certification requirement.
Establish context and security risk criteria; identify owners and risks; analyse and evaluate risks; select treatment and controls; approve the plan and residual risk; communicate, record, monitor, and review.
Apply principles through a framework that is integrated, designed, implemented, evaluated, and improved; run the process through communication, scope/context/criteria, assessment, treatment, monitoring/review, and recording/reporting.
Longer strategic cycles address context changes; shorter operational cycles update scenarios and treatment, with additional reviews after material change.
Guidance, not a standalone certification. ISO/IEC 27001 is the certifiable ISMS requirements standard; adopted 27005 practices can be examined as supporting evidence.
Establish context and security risk criteria; identify owners and risks; analyse and evaluate risks; select treatment and controls; approve the plan and residual risk; communicate, record, monitor, and review.
Apply principles through a framework that is integrated, designed, implemented, evaluated, and improved; run the process through communication, scope/context/criteria, assessment, treatment, monitoring/review, and recording/reporting.
Longer strategic cycles address context changes; shorter operational cycles update scenarios and treatment, with additional reviews after material change.
Guidance, not a standalone certification. ISO/IEC 27001 is the certifiable ISMS requirements standard; adopted 27005 practices can be examined as supporting evidence.
:2018 is broad guidance for integrating risk management into governance, strategy, planning, reporting, policies, values, and culture. It can be used by any organization and for any type of risk. ISO/IEC 27005:2022 has a narrower subject: managing risks to the confidentiality, integrity, and availability of information in an ISMS context.
ISO/IEC 27005 follows the general process but adds information-security implementation detail. It covers security risk criteria and assessment methods, risk owners, event- and asset-based identification, treatment controls, residual-risk acceptance, documented information, communication, monitoring, and review.
ISO lists :2018 as the current second edition, confirmed in 2023, and also shows it at the revision stage with a replacement under development. Until a replacement is published and adopted for the organization's use, mappings should name the 2018 edition rather than referring only to "ISO 31000."
Use to define the enterprise risk architecture and how risk informs organizational decisions.
Use ISO/IEC 27005 when the assessment and treatment must support an ISO/IEC 27001 ISMS.
Keep shared terminology and escalation rules, but do not force security risks into enterprise categories that hide scenarios, controls, or responsible owners.
Which records make the chosen approach reviewable?
Maintain a short mapping between enterprise and information-security governance. It should identify the common risk vocabulary, objectives, appetite or acceptance criteria, decision authority, escalation thresholds, aggregation rules, reporting route, and review cycle. Record justified differences where information-security analysis needs more detail.
For each security risk, retain the scope, purpose, scenario, owner, assessment method, source evidence, uncertainty, evaluation, treatment decision, necessary controls, residual-risk acceptance, communication, and review trigger. A consolidated enterprise report should remain traceable to those underlying records.
Link conclusions to current source evidence and assumptions.
Keep approval, version, date, owner, and review trigger with the decision.
Record uncertainty and exceptions instead of hiding them in a score.
Start with the organization's -aligned objectives, governance, authority, and reporting model. Translate those into information-security risk criteria and assessment rules that satisfy the ISMS context. ISO/IEC 27005 says the security approach should align with organizational risk management so security risks can be compared with other organizational risks rather than considered in isolation.
Escalate a security risk into enterprise reporting with its scenario, time horizon, assumptions, and uncertainty intact. If enterprise and security scales differ, document an equivalence or mapping; a label such as 'high' is not automatically comparable across domains.
Governance owner: document enterprise objectives, appetite, accountable bodies, authority, escalation, reporting, and the edition used.
ISMS owner: translate that governance into security consequence, likelihood, level, acceptance, and reassessment criteria without losing legal, contractual, or confidentiality-integrity-availability consequences.
Risk owner: retain the full security scenario, evidence, uncertainty, controls, treatment, and residual-risk decision behind any consolidated enterprise rating.
Review owner: test the mapping after criteria, reporting, organizational context, the ISMS, or either standard changes.
Do not present the standards as competing certifications. ISO states that cannot be used for certification. ISO/IEC 27005 is guidance supporting ISO/IEC 27001; following it can support an ISMS, but it does not by itself establish ISO/IEC 27001 conformity.
Do not copy an enterprise heat map into the ISMS without checking definitions, thresholds, consequence types, likelihood periods, and acceptance authority. Shared colors or numbers can conceal different meanings.
Do not present guidance as a legal mandate or standalone certification requirement.
Do not confuse a template, matrix, or register with evidence that the process operated.
Do not leave ownership, rationale, residual risk, or review conditions implicit.
Review the mapping on a planned cycle and when enterprise governance, objectives, ISMS scope, risk appetite, acceptance authority, criteria, reporting, or either standard changes. ISO/IEC 27005 also distinguishes longer strategic updates from shorter operational updates driven by changed scenarios, threats, controls, or treatment. There is no universal annual deadline; choose a cadence appropriate to the governance and ISMS cycles and add change-driven review.
Set a planned review date.
Define event-driven triggers and evidence owners.
Preserve change history so reviewers can understand why the decision changed.
This ISO listing supports the ISO/IEC 27005 side of the comparison by identifying it as guidance for managing information security risks in an ISMS context.