Side-by-sideGlobalISO/IEC 27005

ISO/IEC 27005 ISO/IEC 27005 vs ISO 31000

Use ISO 31000 to set organization-wide risk principles, governance, and a common process. Use ISO/IEC 27005 to apply that process to information-security risk and connect it to an ISO/IEC 27001 ISMS.

The standards are complementary guidelines. ISO 31000 cannot be used for certification, and ISO/IEC 27005 is not a standalone organizational certification.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

:2018 provides organization-wide principles, a framework, and a process for managing any type of risk. ISO/IEC 27005:2022 adapts that general process to information-security risk and supports an ISO/IEC 27001 information security management system. Most organizations should use them together: align governance, authority, appetite, terminology, reporting, and escalation under ISO 31000, then use ISO/IEC 27005 for security-specific criteria, scenarios, treatment, acceptance, records, and review.

Side-by-side comparison

ISO/IEC 27005 vs ISO 31000: practical differences

Compare purpose, scope, method, records, review, and reuse without treating voluntary guidance as a legal or standalone certification requirement.

Review all sources
First framework
ISO/IEC 27005

Guidance for managing information-security risk across context, assessment, treatment, acceptance, communication, recording, monitoring, and review.

Second framework
ISO 31000

Organization-wide principles, framework, and process guidance for managing any type of risk.

Comparison row 1

Purpose and scope

ISO/IEC 27005

Information-security risk management in support of an ISO/IEC 27001 ISMS, using a process based on .

ISO 31000

Any type of organizational risk, with principles, a framework, and a process that can be integrated into governance and decision-making.

Operational implication

Use for the common enterprise architecture and ISO/IEC 27005 for security-specific application.

Comparison row 2

Ownership and decision authority

ISO/IEC 27005

Each identified security risk should have an owner with enough accountability, authority, and knowledge to decide how the risk is managed.

ISO 31000

Leadership, accountability, authority, and resources are assigned through the organization's risk framework and integrated governance.

Operational implication

Map enterprise decision authority to security risk owners, treatment owners, approvers, and escalation paths.

Comparison row 3

When to use it

ISO/IEC 27005

Use for planned and change-driven information-security risk decisions, including ISMS planning, operations, treatment, and review.

ISO 31000

Use when designing, integrating, evaluating, or improving organization-wide risk governance and decision-making.

Operational implication

Apply the method when it improves a defined decision, not merely to produce another score or report.

Comparison row 4

Process

ISO/IEC 27005

Establish context and security risk criteria; identify owners and risks; analyse and evaluate risks; select treatment and controls; approve the plan and residual risk; communicate, record, monitor, and review.

ISO 31000

Apply principles through a framework that is integrated, designed, implemented, evaluated, and improved; run the process through communication, scope/context/criteria, assessment, treatment, monitoring/review, and recording/reporting.

Operational implication

Align the common process, then retain ISO/IEC 27005's security and ISMS detail.

Comparison row 5

Evidence and records

ISO/IEC 27005

Context, criteria, method, scenarios, owners, analysis rationale, evaluation, treatment, necessary controls, approvals, residual-risk acceptance, communication, monitoring, and review.

ISO 31000

Enterprise risk policy and framework, criteria, accountable roles, risk assessments, treatment decisions, reports, monitoring, and improvement records.

Operational implication

Reuse source evidence, but label the method, assumptions, criteria, and decision each record actually supports.

Comparison row 6

Review cycle

ISO/IEC 27005

Longer strategic cycles address context changes; shorter operational cycles update scenarios and treatment, with additional reviews after material change.

ISO 31000

Integrated into ongoing governance and decision-making, with monitoring and review responsive to organizational change.

Operational implication

Use planned and event-driven review rather than assuming one universal annual deadline.

Comparison row 7

Certification and assurance limits

ISO/IEC 27005

Guidance, not a standalone certification. ISO/IEC 27001 is the certifiable ISMS requirements standard; adopted 27005 practices can be examined as supporting evidence.

ISO 31000

ISO explicitly states that cannot be used for certification. It can guide internal or external audit programs and provide a benchmark.

Operational implication

State the source of any binding, contractual, or certification requirement separately.

Comparison row 8

What can be reused

ISO/IEC 27005

Context, risk statements, evidence, owners, criteria inputs, treatment records, and monitoring can be mapped where definitions remain clear.

ISO 31000

Reuse principles, context, criteria logic, ownership, communication, review, and reporting. Add information-security scenarios, treatment detail, and ISO/IEC 27001 records where needed.

Operational implication

Reuse facts and evidence; do not imply equivalence of methods, scores, or conformity claims without a documented mapping.

Comparison row 9

Decision rule

ISO/IEC 27005

Use ISO/IEC 27005 for information-security risk assessment, treatment, acceptance, records, and review within an ISMS.

ISO 31000

Use for organization-wide risk principles, governance, integration, and the common process.

Operational implication

Use both when an ISMS must connect cleanly to enterprise risk management; document the interface and any scale mapping.

Practical decision rule

How should teams choose between ISO/IEC 27005 and ISO 31000?

  • Adopt for common risk principles, authority, reporting, and integration across the organization.
  • Apply ISO/IEC 27005 to security-specific context, criteria, scenarios, treatment controls, residual-risk acceptance, and ISMS records.
  • Document how security results map into enterprise scales and escalation without losing their assumptions, uncertainty, or treatment status.
Section 1

How do ISO/IEC 27005 and ISO 31000 differ?

:2018 is broad guidance for integrating risk management into governance, strategy, planning, reporting, policies, values, and culture. It can be used by any organization and for any type of risk. ISO/IEC 27005:2022 has a narrower subject: managing risks to the confidentiality, integrity, and availability of information in an ISMS context.

ISO/IEC 27005 follows the general process but adds information-security implementation detail. It covers security risk criteria and assessment methods, risk owners, event- and asset-based identification, treatment controls, residual-risk acceptance, documented information, communication, monitoring, and review.

ISO lists :2018 as the current second edition, confirmed in 2023, and also shows it at the revision stage with a replacement under development. Until a replacement is published and adopted for the organization's use, mappings should name the 2018 edition rather than referring only to "ISO 31000."

  • Use to define the enterprise risk architecture and how risk informs organizational decisions.
  • Use ISO/IEC 27005 when the assessment and treatment must support an ISO/IEC 27001 ISMS.
  • Keep shared terminology and escalation rules, but do not force security risks into enterprise categories that hide scenarios, controls, or responsible owners.
Section 2

Which records make the chosen approach reviewable?

Maintain a short mapping between enterprise and information-security governance. It should identify the common risk vocabulary, objectives, appetite or acceptance criteria, decision authority, escalation thresholds, aggregation rules, reporting route, and review cycle. Record justified differences where information-security analysis needs more detail.

For each security risk, retain the scope, purpose, scenario, owner, assessment method, source evidence, uncertainty, evaluation, treatment decision, necessary controls, residual-risk acceptance, communication, and review trigger. A consolidated enterprise report should remain traceable to those underlying records.

  • Link conclusions to current source evidence and assumptions.
  • Keep approval, version, date, owner, and review trigger with the decision.
  • Record uncertainty and exceptions instead of hiding them in a score.
Section 3

How can the two standards work together?

Start with the organization's -aligned objectives, governance, authority, and reporting model. Translate those into information-security risk criteria and assessment rules that satisfy the ISMS context. ISO/IEC 27005 says the security approach should align with organizational risk management so security risks can be compared with other organizational risks rather than considered in isolation.

Escalate a security risk into enterprise reporting with its scenario, time horizon, assumptions, and uncertainty intact. If enterprise and security scales differ, document an equivalence or mapping; a label such as 'high' is not automatically comparable across domains.

  • Governance owner: document enterprise objectives, appetite, accountable bodies, authority, escalation, reporting, and the edition used.
  • ISMS owner: translate that governance into security consequence, likelihood, level, acceptance, and reassessment criteria without losing legal, contractual, or confidentiality-integrity-availability consequences.
  • Risk owner: retain the full security scenario, evidence, uncertainty, controls, treatment, and residual-risk decision behind any consolidated enterprise rating.
  • Review owner: test the mapping after criteria, reporting, organizational context, the ISMS, or either standard changes.
Section 4

Which comparison mistakes should teams avoid?

Do not present the standards as competing certifications. ISO states that cannot be used for certification. ISO/IEC 27005 is guidance supporting ISO/IEC 27001; following it can support an ISMS, but it does not by itself establish ISO/IEC 27001 conformity.

Do not copy an enterprise heat map into the ISMS without checking definitions, thresholds, consequence types, likelihood periods, and acceptance authority. Shared colors or numbers can conceal different meanings.

  • Do not present guidance as a legal mandate or standalone certification requirement.
  • Do not confuse a template, matrix, or register with evidence that the process operated.
  • Do not leave ownership, rationale, residual risk, or review conditions implicit.
Section 5

When should the chosen approach be reviewed?

Review the mapping on a planned cycle and when enterprise governance, objectives, ISMS scope, risk appetite, acceptance authority, criteria, reporting, or either standard changes. ISO/IEC 27005 also distinguishes longer strategic updates from shorter operational updates driven by changed scenarios, threats, controls, or treatment. There is no universal annual deadline; choose a cadence appropriate to the governance and ISMS cycles and add change-driven review.

  • Set a planned review date.
  • Define event-driven triggers and evidence owners.
  • Preserve change history so reviewers can understand why the decision changed.
Primary sources

References and citations

iso.org
Referenced sections
  • This ISO listing supports the comparator side by identifying ISO 31000 as organization-wide risk management guidance.
"Risk management — Guidelines"
iso.org
Referenced sections
  • ISO's official listing identifies ISO/IEC 27001 as the certifiable ISMS requirements standard that ISO/IEC 27005 supports.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • This ISO listing supports the ISO/IEC 27005 side of the comparison by identifying it as guidance for managing information security risks in an ISMS context.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
ISO/IEC 27005: Qualitative vs Quantitative Risk Analysis
Choose qualitative, quantitative, semiquantitative, or combined risk analysis under ISO/IEC 27005 based on the decision, data, uncertainty, and required comparability.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.