What is the difference between ISO/IEC 27005 and ISO 31000?

ISO 31000:2018 is the general-purpose international risk-management standard, applicable to any type of risk in any organisation. ISO/IEC 27005:2022 is aligned with the principles of ISO 31000 and built on its structure, but focuses specifically on information security risks.

ISO 31000:2018 Risk management — Guidelines is the general-purpose framework applicable to all types of risk: financial, operational, strategic, environmental, information security, HR and others. It is designed to apply to any organisation, regardless of size or sector.

ISO/IEC 27005:2022 is aligned with the principles and structure of ISO 31000:2018, with an operational focus on information security risks. It follows the same steps: context establishment, identification, analysis, evaluation, treatment, communication and consultation, and monitoring and review.

An organisation that has to manage several kinds of risk at once can adopt ISO 31000 as its governing framework and use ISO 27005 (or EBIOS RM) for the information scope. The two individual certifications, ISO 31000 Risk Manager and ISO 27005 Risk Manager, are recognised separately by PECB.

For a Chief Risk Officer or a generalist Risk Manager, ISO 31000 Risk Manager is the priority. For a CISO, DPO or Information Security Risk Officer, ISO 27005 Risk Manager is the priority, ideally complemented by ISO 31000 Foundation to share a common language with the other risk functions.

Related Information

  • ISO 31000:2018: general framework, all risk types
  • ISO 27005:2022: aligned with ISO 31000, information-security focus
  • Shared steps: context, identification, analysis, evaluation, treatment
  • ISO 31000 audience: Chief Risk Officer, generalist Risk Manager
  • ISO 27005 audience: CISO, DPO, Information Security Risk Officer

Expert Insight

Think framework versus focus: ISO 31000 gives the whole enterprise one risk language; ISO 27005 applies it to information security. Security leaders benefit from a little of both.

Explore related training

Browse all: Information Security

Browse all FAQs →

Full knowledge base

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.