Side-by-sideGlobalISO/IEC 27005

ISO/IEC 27005 Qualitative vs Quantitative Risk Analysis

Use a well-defined qualitative method for efficient screening and communication. Use a quantitative method when numeric ranges can improve a material decision and the inputs support them. Combine methods when different decisions need different depth.

ISO/IEC 27005:2022 allows qualitative, quantitative, and semiquantitative analysis. The chosen method must still support consistent, valid, and comparable results.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ISO/IEC 27005:2022 does not require one calculation model. A qualitative method uses defined nonnumeric categories such as low, medium, and high. A quantitative method uses numbers whose units and proportional meaning are maintained, such as annual frequency, probability, money, downtime, or lives affected. A assigns numbers to ordered bins or categories without making them true measurements. Choose the least complex method that can support the decision, document it, calibrate it against a shared reference scale, and make repeated assessments consistent, valid, and comparable.

Side-by-side comparison

Qualitative vs quantitative risk analysis: practical differences

Compare what each method measures, when it helps, what evidence it needs, and how to avoid false precision under ISO/IEC 27005:2022.

Review all sources
First framework
Qualitative method

Uses defined nonnumeric categories, such as low, medium, and high, with evidence and rationale for each assigned level.

Second framework
Quantitative method

Uses numeric estimates, often ranges or probability distributions, to express frequency, consequence, or risk.

Comparison row 1

Purpose and scope

Qualitative method

Screening, prioritization, and communication where well-defined categories are sufficient for the decision.

Quantitative method

Decisions needing meaningful numeric estimates, ranges, sensitivity analysis, or comparison of treatment costs and effects.

Operational implication

Choose from the decision and evidence needs, not from a belief that numbers are automatically more objective.

Comparison row 2

Ownership and decision authority

Qualitative method

Assessors apply defined categories with input from people who understand the scenario; the risk owner remains accountable for the decision.

Quantitative method

Analysts build and test estimates with data owners and subject-matter experts; the risk owner remains accountable for the decision.

Operational implication

Method complexity changes the evidence and skills needed, not the risk owner's authority.

Comparison row 3

When to use it

Qualitative method

Use when category boundaries clearly separate the available decisions and rapid, consistent coverage matters.

Quantitative method

Use when numeric ranges can change a material treatment, funding, insurance, acceptance, or prioritization decision.

Operational implication

Escalate selected scenarios from qualitative screening to quantitative analysis when added depth can change the decision.

Comparison row 4

Process

Qualitative method

Define non-overlapping categories and examples, assess likelihood and consequence with evidence, explain each rating, combine them under a defined rule, and compare the result with criteria.

Quantitative method

Define the scenario, time horizon, and units; gather data and elicited estimates; model uncertainty; calculate ranges; test sensitivity; validate; and compare with criteria.

Operational implication

Both methods need defined criteria, evidence, uncertainty, evaluation, treatment, acceptance, and review.

Comparison row 5

Evidence and records

Qualitative method

Category definitions, boundary examples, evidence, rating rationale, combination rule, scale mapping, owner, evaluation, treatment, acceptance, and review.

Quantitative method

Data provenance, units, distributions or ranges, assumptions, calculation or simulation logic, calibration, uncertainty, sensitivity, validation, and decision record.

Operational implication

Reuse source evidence, but label the method, assumptions, criteria, and decision each record actually supports.

Comparison row 6

Review cycle

Qualitative method

Refresh when category definitions, scenario evidence, assessor interpretation, controls, criteria, or the decision changes.

Quantitative method

Refresh when data, exposure, assumptions, model behavior, controls, uncertainty, time horizon, or the decision changes.

Operational implication

Use planned and event-driven review rather than assuming one universal annual deadline.

Comparison row 7

Certification and assurance limits

Qualitative method

A qualitative method can support ISO/IEC 27001 when it produces consistent, valid, and comparable results under the organization's criteria.

Quantitative method

A quantitative method is not automatically more conformant or reliable; its units, assumptions, data, uncertainty, and calculations must fit the decision.

Operational implication

State the source of any binding, contractual, or certification requirement separately.

Comparison row 8

What can be reused

Qualitative method

Reuse the scope, scenarios, owners, evidence, criteria, treatment records, and review triggers. Preserve the rationale for each category.

Quantitative method

Reuse the same governance and source evidence, adding measured units, data provenance, assumptions, ranges, model logic, and sensitivity where needed.

Operational implication

Reuse evidence and governance, but do not convert categories into quantities without a defensible measurement model.

Comparison row 9

Decision rule

Qualitative method

Choose qualitative analysis when defined categories can separate the available decisions consistently and efficiently.

Quantitative method

Choose quantitative analysis when meaningful numeric ranges can improve a decision enough to justify the data, skills, and effort.

Operational implication

Use the least complex method that supports a valid decision, and combine methods when selected scenarios need more depth.

Practical decision rule

How should teams choose between qualitative and quantitative analysis?

  • Define the decision, time horizon, consequence types, evidence quality, uncertainty, and required comparability.
  • Use calibrated qualitative categories for efficient coverage; quantify scenarios when numeric ranges can change a material decision.
  • Document the method, category or unit definitions, assumptions, rationale, owner decision, and review triggers.
Section 1

What does ISO/IEC 27005 say about qualitative and quantitative methods?

ISO/IEC 27005:2022 permits qualitative analysis using defined attributes, quantitative analysis using numerical values, and semiquantitative analysis using qualitative scales with assigned values. It does not make one approach inherently more conformant. The organization documents the chosen approach and uses criteria detailed enough to produce repeatable, valid, and comparable results.

Risk levels can be qualitative, such as very high, high, medium, and low, or quantitative, such as expected monetary loss, loss of life, or market share over a stated period. Both need a reference scale understood by interested parties and periodic calibration. Qualitative levels should be unambiguous, non-overlapping, and expressed in objective language.

ISO/IEC 27005 is guidance, while ISO/IEC 27001 contains the certifiable ISMS requirements. ISO/IEC 27001 requires consistent, valid, and comparable results but does not mandate a heat map, 1-to-5 matrix, Monte Carlo simulation, or financial risk model.

  • Define the decision, scope, time horizon, consequence types, likelihood criteria, and acceptance authority before choosing a scale.
  • Use qualitative categories only when each category and boundary has a clear meaning and supporting rationale.
  • Use quantitative units only when arithmetic on those units is meaningful; a numbered ordinal scale is still semiquantitative.
Section 2

Which records make the selected analysis method reviewable?

For any method, record the purpose, scope, scenario, owner, time horizon, risk criteria, source evidence, assumptions, uncertainty, result, treatment decision, approval, and review trigger. Define every category, threshold, unit, and combination rule so another competent assessor can reproduce the reasoning.

For quantitative work, also retain data provenance, elicited estimates, ranges or distributions, model logic, calculation or simulation settings, sensitivity, validation, and known limitations. For qualitative work, retain the rationale and evidence behind each rating, examples anchoring the categories, and any equivalence used across different scales.

  • Link conclusions to current source evidence and assumptions.
  • Keep approval, version, date, owner, and review trigger with the decision.
  • Record uncertainty and exceptions instead of hiding them in a score.
Section 3

How should teams select and apply an analysis method?

Start with the decision. Qualitative analysis is often enough for broad inventories, rapid screening, or communication where clear categories separate treatment priorities. Quantitative analysis is useful when the decision depends on the size and distribution of possible loss, a cost-benefit comparison, a treatment budget, or the difference between close options.

Use a combined approach when it reduces effort without hiding material risk. For example, screen a large inventory with calibrated qualitative criteria, then quantify the scenarios near an acceptance threshold or those tied to large investment decisions. Evaluate every result against approved criteria and keep the accountable risk owner separate from the analyst.

Apply an explicit branch. If well-defined categories clearly separate accept, treat, and escalate outcomes, use the qualitative method. If two options remain close, the exposure crosses a material threshold, or cost and benefit depend on the range of possible loss, quantify the selected scenario. If data are sparse, use ranges and record expert judgment and uncertainty instead of manufacturing a precise point estimate.

  • Qualitative example: define "major" operational consequence with observable downtime, affected services, and recovery limits; record why the scenario meets that band and which evidence supports it.
  • Semiquantitative example: assign 1 through 5 to ordered likelihood bands for prioritization, but do not claim that a rating of 4 is twice a rating of 2 unless the underlying scale establishes that relationship.
  • Quantitative example: estimate event frequency over a stated period and consequence in money, downtime, records, or another defined unit; use ranges or distributions when uncertainty affects the decision.
  • Combined example: screen all scenarios with calibrated categories, then quantify high-cost treatments, borderline acceptance decisions, or exposures whose cumulative effect a matrix hides.
Section 4

Which method-selection mistakes should teams avoid?

Numbers do not make weak evidence objective, and labels do not excuse vague reasoning. Do not multiply or average ordinal 1-to-5 ratings as if the intervals and ratios were measured quantities. Do not compare a 'high' rating from one scale with a 'high' rating from another until their definitions and thresholds are mapped.

Avoid a single-point estimate when a range would show material uncertainty. Do not buy extra precision that cannot change the decision. A rough but traceable estimate can be sufficient, while a detailed model can still be misleading when subjective judgments or unknown dependencies are hidden.

  • Do not present guidance as a legal mandate or standalone certification requirement.
  • Do not confuse a template, matrix, or register with evidence that the process operated.
  • Do not leave ownership, rationale, residual risk, or review conditions implicit.
Section 5

When should the selected method be reviewed?

Review the method and the affected assessments when the decision, scope, criteria, data, threat conditions, controls, assumptions, time horizon, or acceptance thresholds change. Also review it when independent assessors cannot reproduce the result, when similar risks produce incomparable results, or when the model's precision does not improve the decision. ISO/IEC 27005 sets no universal annual method-review deadline; use a planned cadence and change-driven triggers appropriate to the ISMS.

  • Set a planned review date.
  • Define event-driven triggers and evidence owners.
  • Preserve change history so reviewers can understand why the decision changed.
Primary sources

References and citations

iso.org
Referenced sections
  • ISO's official listing identifies ISO/IEC 27001 as the certifiable ISMS requirements standard that ISO/IEC 27005 supports.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • ISO's official listing identifies the fourth edition as guidance for managing information security risks; method details remain organization-specific.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27005 Asset and Scenario Modeling FAQ
How to use event-based and asset-based risk scenarios under ISO/IEC 27005:2022, including evidence, ownership, and review triggers.
ISO/IEC 27005 Impact FAQ
How to assess information security consequences under ISO/IEC 27005:2022, with criteria, evidence, ownership, and review triggers.
ISO/IEC 27005 Inherent vs Residual Risk FAQ
How ISO/IEC 27005:2022 distinguishes inherent, current, and residual risk, including control assumptions, evidence, and acceptance.
ISO/IEC 27005 Likelihood FAQ
How to estimate likelihood under ISO/IEC 27005:2022 using defined criteria, scenario evidence, control effectiveness, and uncertainty.
ISO/IEC 27005 Residual Risk Approval Guide
How ISO/IEC 27005 risk owners approve treatment plans and decide whether residual information security risk is acceptable, conditional, or needs more treatment.
ISO/IEC 27005 Residual Risk Approval Workflow
Decide whether residual information security risk can be accepted, who approves it, what evidence the decision needs, and when ISO/IEC 27005 calls for reassessment.
ISO/IEC 27005 Review Cadence FAQ
How to set ISO/IEC 27005:2022 risk review timing using strategic, operational, scheduled, and event-driven reviews.
ISO/IEC 27005 Risk Acceptance FAQ
How to accept information security risk under ISO/IEC 27005:2022 using approved criteria, delegated authority, conditions, and review.
ISO/IEC 27005 Risk Assessment Template and Workflow
Create an ISO/IEC 27005 risk assessment record with the scenario, owner, consequence, likelihood, risk level, criteria result, evidence, uncertainty, and treatment priority.
ISO/IEC 27005 Risk Criteria Guide
How to define ISO/IEC 27005 risk acceptance and assessment criteria, including consequence, likelihood, thresholds, authority, evidence, and review.
ISO/IEC 27005 Risk Criteria Setup Workflow
Set ISO/IEC 27005 risk assessment and acceptance criteria, define decision authority, calibrate the scales, approve the method, and control later changes.
ISO/IEC 27005 Risk Management FAQ
Answers to common ISO/IEC 27005:2022 questions about risk assessment, treatment, acceptance, ownership, records, and review.
ISO/IEC 27005 Risk Owners FAQ
How to assign ISO/IEC 27005:2022 risk owners with the accountability, authority, knowledge, approvals, and review evidence the role needs.
ISO/IEC 27005 Risk Register Workflow
Build a traceable ISO/IEC 27005 risk register that connects each scenario to its owner, assessment, treatment, residual-risk decision, evidence, and review status.
ISO/IEC 27005 Risk Treatment Plan Template
Create an ISO/IEC 27005 risk treatment plan with selected options, necessary controls, owners, resources, milestones, measures, residual risk, approval, and review.
ISO/IEC 27005 Scenario Library Guide
How to build and maintain an ISO/IEC 27005 risk scenario library using event-based and asset-based identification without turning generic prompts into assessed risks.
ISO/IEC 27005 Treatment Options FAQ
ISO/IEC 27005:2022 risk treatment options, how to choose controls, approve the plan, assess residual risk, and review effectiveness.
ISO/IEC 27005 vs FAIR Comparison
Use ISO/IEC 27005 for the information-security risk-management cycle and FAIR when a defined loss scenario needs quantitative, often financial, analysis.
ISO/IEC 27005 vs ISO 31000 Comparison
Use ISO 31000 for organization-wide risk principles and governance, and ISO/IEC 27005 for information-security risk decisions within an ISMS.
ISO/IEC 27005 vs NIST SP 800-30 Comparison
Compare ISO/IEC 27005:2022's full information-security risk cycle with NIST SP 800-30 Rev. 1's detailed risk-assessment guidance.
Using ISO/IEC 27005 in an ISO/IEC 27001 ISMS
How to use ISO/IEC 27005:2022 to operate the risk requirements of an ISO/IEC 27001 ISMS, including criteria, assessment, treatment, records, and review.