What is the difference between ISO/IEC 27001 and ISO/IEC 27005?

ISO/IEC 27001:2022 is the certifiable standard that defines the requirements of an Information Security Management System (ISMS). ISO/IEC 27005:2022 is a guidance standard, non-certifiable, that details how to manage information security risks. ISO 27001 says you must manage risk; ISO 27005 explains how.

ISO/IEC 27001:2022 defines the requirements of an ISMS: scope, policies, governance, risk treatment, controls (Annex A — 93 controls across four themes), monitoring and continual improvement. It is the standard an accredited body assesses your organisation against to issue a certificate.

ISO/IEC 27005:2022 does not define certifiable requirements. It provides methodological guidelines for carrying out the risk management required by clause 6.1 of ISO 27001: risk assessment (6.1.2) and risk treatment (6.1.3).

An organisation can be certified to ISO 27001 without explicitly citing ISO 27005 in its documentation, provided it can demonstrate a rigorous risk-management process. In practice, ISO 27005 is commonly used as the methodological reference, but it is not mandatory.

On the individual PECB certification side, the two families are distinct and complementary. ISO 27001 offers Foundation, Lead Implementer and Lead Auditor. ISO 27005 offers Foundation, Risk Manager and Lead Risk Manager.

Related Information

  • ISO 27001:2022: certifiable standard, ISMS requirements
  • ISO 27005:2022: non-certifiable, guidelines for risk management
  • Link: ISO 27005 helps implement clause 6.1 of ISO 27001
  • Recognised alternative method: EBIOS Risk Manager (ANSSI)
  • Typical PECB path: ISO 27001 Lead Implementer + ISO 27005 Risk Manager

Expert Insight

Pair the credential to the job: a Lead Implementer builds the ISMS, while a Risk Manager owns the clause 6.1 risk process that feeds it. Most mature security teams need both.

Explore related training

Browse all: Information Security

Browse all FAQs →

Full knowledge base

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.