What changed in ISO/IEC 27005:2022 compared to 2018?

ISO/IEC 27005:2022 was published in October 2022 and supersedes the 2018 edition. The confirmed changes concern terminology alignment with ISO/IEC 27001:2022 and ISO 31000:2018, and an updated vocabulary around the concepts of risk, threat and vulnerability.

ISO/IEC 27005:2022 was published in October 2022 by technical committee ISO/IEC JTC 1/SC 27, succeeding ISO/IEC 27005:2018. Organisations using the 2018 edition are not automatically required to migrate immediately, but the 2022 version is progressively becoming the reference used in audits.

The main confirmed evolution is the alignment of terminology with ISO 27001:2022 and ISO 31000:2018. This covers the vocabulary around risk (the effect of uncertainty on objectives), threat (a potential cause of an incident) and vulnerability (a weakness that can be exploited).

The reference structure for risk treatment aligns with the new organisation of ISO 27002:2022: 93 controls grouped into four themes (Organisational, People, Physical, Technological). This makes it easier to keep the risk assessment consistent with the Statement of Applicability (SoA) of an ISO 27001:2022 ISMS.

For organisations transitioning from ISO 27001:2013 to ISO 27001:2022, the update to ISO 27005:2022 should be planned in step. The coexistence period for new ISO 27001 certifications ended on 31 October 2025. For the full list of changes, consult the official standard on iso.org.

Related Information

  • ISO 27005:2022 published: October 2022
  • Confirmed change: terminology aligned with ISO 27001:2022 and ISO 31000:2018
  • Control reference: ISO 27002:2022 (93 controls, 4 themes)
  • ISO 27001:2013 → 2022 transition: coexistence ended 31 October 2025
  • Full official source: iso.org

Expert Insight

If you are already migrating your ISMS to ISO 27001:2022, adopt ISO 27005:2022 at the same time — the shared vocabulary and the ISO 27002:2022 control themes keep your risk assessment and SoA in lockstep.

Explore related training

Browse all: Information Security

More from ISO 27005 Risk Manager

Browse all FAQs →

Full knowledge base

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.