Establish context
Scope, framing and – central to the 2022 edition – the criteria for risk acceptance and a leadership-approved risk appetite.
ISO/IEC 27005 is the recognised guidance for managing information security risks – the method behind risk assessment and risk treatment in your ISMS. We turn it into a robust, audit-ready process.
ISO/IEC 27005:2022 is the international guidance for information security risk management. It describes how organisations systematically identify, analyse, evaluate and treat risks – closing exactly the gap between the "what" of ISO/IEC 27001 and the "how" of everyday practice.
It is pure guidance and contains no certifiable requirements. Its value lies in the method: ISO/IEC 27005 provides the foundation for the risk assessment and the risk treatment plan from which your ISMS Statement of Applicability (SoA) is derived. The 4th edition of 2022 is closely aligned with ISO 31000 and ISO/IEC 27001:2022.
ISO/IEC 27005:2022 structures the risk process clearly along the risk management cycle.
Scope, framing and – central to the 2022 edition – the criteria for risk acceptance and a leadership-approved risk appetite.
Either asset-based (assets, threats, vulnerabilities) or event-based (scenarios and events) – the 2022 edition places both approaches on an equal footing.
Determining likelihood and impact (consequence) per risk – qualitative, quantitative or a hybrid, consistent with the defined criteria.
Prioritising the analysed risks against the acceptance criteria to decide on treatment or acceptance.
Selecting options (reduce, share, avoid, accept), deriving controls (including from ISO/IEC 27001 Annex A) and the risk treatment plan with owner and deadline.
Ongoing communication to stakeholders plus monitoring and review, so that risks and controls stay current.
ISO/IEC 27005 is the methodological anchor for several regulatory and normative requirements.
Provides the method for clause 6.1 (actions to address risks and opportunities) and 8.2/8.3 (risk assessment and treatment) – and thus the basis for SoA and risk treatment plan.
The required risk-based approach for technical and organisational measures can be substantiated and documented cleanly with an ISO 27005 process.
The financial sector's ICT risk management (DORA Chapter II) calls for a robust risk process – ISO/IEC 27005 supplies the fitting, recognised method.
The 2022 edition is closely aligned with the overarching risk management framework ISO 31000, so IT risks fit into an enterprise-wide ERM.
From a baseline assessment to a living, audit-ready risk process.
We review your existing risk process, criteria and register and identify gaps against ISO/IEC 27005 and your regulatory obligations.
Together we define risk criteria, scales and a leadership-approved risk appetite – asset- or event-based, tailored to your organisation.
We run the risk assessment, derive treatment options and produce the risk treatment plan with clear owners and deadlines.
We establish monitoring, review cycles and leadership reporting – tool-supported with VamiGRC – so the process stays current over time.
Four short questions show you in two minutes where your information security risk management stands.
1Is there a documented risk process with defined criteria and scales?
2Is a risk appetite formally approved by leadership?
3Are risks captured centrally, completely and up to date in a register?
4Do all treatment plans have a named owner and a binding deadline?
The self-check is an initial orientation and does not replace a formal gap analysis.
Primary source for the standard and matching VamiSec services.
The key answers around ISO/IEC 27005.
No. ISO/IEC 27005 is pure guidance and contains no auditable requirements. Certification is against the ISMS per ISO/IEC 27001; ISO/IEC 27005 provides the method behind it.
The 4th edition is more closely aligned with ISO 31000 and ISO/IEC 27001:2022, places the asset-based and event-based approaches on an equal footing, and separates risk assessment and risk treatment more clearly.
ISO/IEC 27001 requires a risk process in clauses 6.1 and 8.2/8.3 but prescribes no specific method. ISO/IEC 27005 fills that gap, providing the method for assessment, treatment and the risk treatment plan.
Yes. Both the risk-based approach of NIS2 (Art. 21) and ICT risk management under DORA can be substantiated and documented robustly with an ISO 27005-conformant process.
Both are valid. The asset-based approach starts from assets, threats and vulnerabilities; the event-based one from scenarios. We choose the approach – or a hybrid – that fits the scope and maturity of your organisation.
We set up an ISO/IEC 27005-conformant risk process with you that supports ISO 27001, NIS2 and DORA alike.