| Purpose and scope | The full information-security risk-management cycle in support of an ISO/IEC 27001 ISMS, using a process based on ISO 31000. | Preparing for, conducting, communicating, and maintaining risk assessments at organization, mission/business-process, and information-system levels. | Choose the governing context first; scope determines criteria, roles, records, and the meaning of results. |
|---|
| Ownership and decision authority | Each security risk should have an owner with enough accountability, authority, and knowledge to decide how the risk is managed. | Stakeholders depend on the assessment tier and purpose and can include senior leaders, risk executives, authorizing officials, mission or business owners, system owners, assessors, and security staff. | Map authority by function; NIST role names do not automatically equal an ISO risk owner or residual-risk approver. |
|---|
| When to use it | Use for planned and change-driven information-security risk decisions, including ISMS planning, operations, treatment, and review. | Use for initial or updated assessments that inform risk-management, authorization, and monitoring decisions at the relevant tier. | Apply the method when it improves a defined decision, not merely to produce another score or report. |
|---|
| Process | Establish context and criteria; identify owners and risks; analyse and evaluate risks; select treatment and controls; approve the plan and residual risk; communicate, record, monitor, and review. | Prepare; identify threat sources and events, vulnerabilities, and predisposing conditions; determine likelihood, impact, and risk; communicate results; and maintain the assessment. | Use NIST's assessment detail where useful, then complete treatment, acceptance, and ISMS records in the ISO process. |
|---|
| Evidence and records | Context, criteria, method, scenarios, owners, analysis rationale, evaluation, treatment, necessary controls, approvals, residual-risk acceptance, communication, monitoring, and review. | Assessment purpose and scope, assumptions and constraints, information sources, threat and vulnerability analysis, likelihood, impact, risk determination, results, and maintenance records. | Reuse source evidence, but label the method, assumptions, criteria, and decision each record actually supports. |
|---|
| Review cycle | Longer strategic cycles address context changes; shorter operational cycles update scenarios and treatment, with additional reviews after material change. | Maintain assessments in response to monitoring and change; cadence follows the organization's risk-management and authorization strategy. | Use planned and event-driven review rather than assuming one universal annual deadline. |
|---|
| Certification and assurance limits | Guidance, not a standalone certification. ISO/IEC 27001 is the certifiable ISMS requirements standard; adopted 27005 practices can be examined as supporting evidence. | A NIST Special Publication, not a certification. It is federal guidance and becomes mandatory only when an applicable law, FIPS, OMB policy, agency rule, contract, or other requirement invokes it. | State the source of any binding, contractual, or certification requirement separately. |
|---|
| What can be reused | Context, risk statements, evidence, owners, criteria inputs, treatment records, and monitoring can be mapped where definitions remain clear. | Reuse inventories, scenarios, threats, vulnerabilities, control evidence, consequence/impact data, likelihood rationale, and risk results after mapping terminology and criteria. | Reuse facts and evidence; do not imply equivalence of methods, scores, or conformity claims without a documented mapping. |
|---|
| Decision rule | Use ISO/IEC 27005 for a complete information-security risk cycle integrated with an ISMS. | Use NIST SP 800-30 when federal or contractual context expects it, or when its assessment model fits the decision. | When both apply, map NIST assessment outputs into ISO evaluation, treatment, acceptance, communication, and review. |
|---|