ISO/IEC 27005:2022 was published in October 2022 and supersedes the 2018 edition. The confirmed changes concern terminology alignment with ISO/IEC 27001:2022 and ISO 31000:2018, and an updated vocabulary around the concepts of risk, threat and vulnerability.
ISO/IEC 27005:2022 was published in October 2022 by technical committee ISO/IEC JTC 1/SC 27, succeeding ISO/IEC 27005:2018. Organisations using the 2018 edition are not automatically required to migrate immediately, but the 2022 version is progressively becoming the reference used in audits.
The main confirmed evolution is the alignment of terminology with ISO 27001:2022 and ISO 31000:2018. This covers the vocabulary around risk (the effect of uncertainty on objectives), threat (a potential cause of an incident) and vulnerability (a weakness that can be exploited).
The reference structure for risk treatment aligns with the new organisation of ISO 27002:2022: 93 controls grouped into four themes (Organisational, People, Physical, Technological). This makes it easier to keep the risk assessment consistent with the Statement of Applicability (SoA) of an ISO 27001:2022 ISMS.
For organisations transitioning from ISO 27001:2013 to ISO 27001:2022, the update to ISO 27005:2022 should be planned in step. The coexistence period for new ISO 27001 certifications ended on 31 October 2025. For the full list of changes, consult the official standard on iso.org.
If you are already migrating your ISMS to ISO 27001:2022, adopt ISO 27005:2022 at the same time — the shared vocabulary and the ISO 27002:2022 control themes keep your risk assessment and SoA in lockstep.
This training prepares professionals to lead risk management as a decision-making discipline, not a compliance exercise. Grounded in ISO 31000, the course focuses on how organizations actually identify uncertainty, evaluate trade-offs, and protect value in complex environments.
View courseThis training develops the practical capability to conduct information security risk assessments using the EBIOS Risk Manager method as required by ANSSI and aligned with ISO 27001. Participants work through a complete EBIOS RM study, from scoping to risk treatment, using realistic scenarios and s.
View courseThis ISO/IEC 27002 Lead Manager training is designed for professionals responsible for selecting, implementing, and managing information security controls within an ISO/IEC 27001 context.
View courseISO/IEC 27001:2022 is the certifiable standard that defines the requirements of an Information Security Management System (ISMS). ISO/IEC 27005:2022 is a guidance standard, non-certifiable, that details how to manage information security risks. ISO 27001 says you must manage risk; ISO 27005 explains how.
The cost of ISO/IEC 27005 Risk Manager training depends on the format (in-person, remote, in-house) and the available sessions. Abilene Academy provides a tailored quote on the course page. The total price usually covers the training, official PECB materials and the certification exam.
The ISO/IEC 27005 Risk Manager certification qualifies professionals to design, operate, and maintain an information security risk management process aligned with ISO/IEC 27005:2022. It validates the ability to identify, analyze, evaluate, treat, and communicate information security risks in support of ISO/IEC 27001 compliance.
ISO/IEC 27005 defines a risk management framework rather than a single assessment method, while EBIOS, NIST, and similar approaches provide specific analysis techniques. ISO 27005 allows organizations to select and justify methods within a standardized lifecycle.
ISO 31000:2018 for Swiss practitioners: 8 principles, 6-element process, 7 treatment options, cross-mapped to FINMA 2023/01, ISA, revFADP, DORA and the EU AI Act. Henri Haenni's expert guide.
ISO 27001 in a Swiss FinTech reads through six regulatory layers: FINMA, ISG, FADP, DORA, EU AI Act. The 2026 expert guide to scope, supplier risk, and incident reporting.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.