What is ISO/IEC 27005?

ISO/IEC 27005:2022 is the international standard that provides guidelines for managing information security risks. Published in October 2022 by ISO and IEC, it helps organisations implement the risk-management requirements of clause 6.1 of ISO/IEC 27001. It is a non-certifiable standard: it provides guidance, not certifiable requirements.

ISO/IEC 27005:2022 was published in October 2022 by technical committee ISO/IEC JTC 1/SC 27, succeeding the 2018 edition. It provides guidelines for managing information security risks within an Information Security Management System (ISMS).

Unlike ISO/IEC 27001:2022, which defines the certifiable requirements of an ISMS, ISO 27005 describes the risk-management methodology. It helps organisations implement clause 6.1 of ISO 27001 — risk assessment and risk treatment.

The standard structures the process around five main steps: context establishment, risk identification, analysis, evaluation and treatment. Two cross-cutting activities support these steps: communication and consultation, and monitoring and review.

ISO 27005 is neutral with respect to operational methodologies. You can apply it with EBIOS Risk Manager (the ANSSI method), NIST SP 800-30, OCTAVE Allegro, or a proprietary method — as long as it respects the principles and steps described by the standard.

Related Information

  • Current edition: ISO/IEC 27005:2022, published October 2022
  • Status: non-certifiable standard (guidelines)
  • Aligned with: ISO 31000:2018 and ISO/IEC 27001:2022
  • PECB individual certifications: Foundation, Risk Manager, Lead Risk Manager
  • Compatible methods: EBIOS RM, NIST SP 800-30, OCTAVE Allegro

Expert Insight

Read ISO 27005 as the "how" behind ISO 27001’s "what": it does not certify you, but it is the methodology reviewers expect to see behind a credible clause 6.1 risk process.

Explore related training

Browse all: Information Security

Browse all FAQs →

Full knowledge base

We use cookies to improve your experience

Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.