Book an Appointment
GRC · Risk management

ISO/IEC 27005 master risk with method

ISO/IEC 27005 is the recognised guidance for managing information security risks – the method behind risk assessment and risk treatment in your ISMS. We turn it into a robust, audit-ready process.

2022 · 4th editionCurrent version (Oct 2022)
GuidanceGuidance – auditable requirements live in ISO 27001
Not certifiableSupports but does not replace ISO 27001 certification
NIS2 · DORABasis for Art. 21 NIS2 & DORA ICT risk management

What ISO/IEC 27005 delivers

ISO/IEC 27005:2022 is the international guidance for information security risk management. It describes how organisations systematically identify, analyse, evaluate and treat risks – closing exactly the gap between the "what" of ISO/IEC 27001 and the "how" of everyday practice.

It is pure guidance and contains no certifiable requirements. Its value lies in the method: ISO/IEC 27005 provides the foundation for the risk assessment and the risk treatment plan from which your ISMS Statement of Applicability (SoA) is derived. The 4th edition of 2022 is closely aligned with ISO 31000 and ISO/IEC 27001:2022.

The core building blocks

ISO/IEC 27005:2022 structures the risk process clearly along the risk management cycle.

01

Establish context

Scope, framing and – central to the 2022 edition – the criteria for risk acceptance and a leadership-approved risk appetite.

02

Risk identification

Either asset-based (assets, threats, vulnerabilities) or event-based (scenarios and events) – the 2022 edition places both approaches on an equal footing.

03

Risk analysis

Determining likelihood and impact (consequence) per risk – qualitative, quantitative or a hybrid, consistent with the defined criteria.

04

Risk evaluation

Prioritising the analysed risks against the acceptance criteria to decide on treatment or acceptance.

05

Risk treatment

Selecting options (reduce, share, avoid, accept), deriving controls (including from ISO/IEC 27001 Annex A) and the risk treatment plan with owner and deadline.

06

Communication & monitoring

Ongoing communication to stakeholders plus monitoring and review, so that risks and controls stay current.

The bridge to your obligations

ISO/IEC 27005 is the methodological anchor for several regulatory and normative requirements.

ISO/IEC 27001

Provides the method for clause 6.1 (actions to address risks and opportunities) and 8.2/8.3 (risk assessment and treatment) – and thus the basis for SoA and risk treatment plan.

NIS2 (Art. 21)

The required risk-based approach for technical and organisational measures can be substantiated and documented cleanly with an ISO 27005 process.

DORA

The financial sector's ICT risk management (DORA Chapter II) calls for a robust risk process – ISO/IEC 27005 supplies the fitting, recognised method.

ISO 31000

The 2022 edition is closely aligned with the overarching risk management framework ISO 31000, so IT risks fit into an enterprise-wide ERM.

How we work together

From a baseline assessment to a living, audit-ready risk process.

01

1 · Baseline

We review your existing risk process, criteria and register and identify gaps against ISO/IEC 27005 and your regulatory obligations.

02

2 · Method & criteria

Together we define risk criteria, scales and a leadership-approved risk appetite – asset- or event-based, tailored to your organisation.

03

3 · Assess & treat

We run the risk assessment, derive treatment options and produce the risk treatment plan with clear owners and deadlines.

04

4 · Embed & monitor

We establish monitoring, review cycles and leadership reporting – tool-supported with VamiGRC – so the process stays current over time.

How mature is your risk management?

Four short questions show you in two minutes where your information security risk management stands.

1Is there a documented risk process with defined criteria and scales?

2Is a risk appetite formally approved by leadership?

3Are risks captured centrally, completely and up to date in a register?

4Do all treatment plans have a named owner and a binding deadline?

The self-check is an initial orientation and does not replace a formal gap analysis.

Frequently asked questions

The key answers around ISO/IEC 27005.

Can you get certified against ISO/IEC 27005?

No. ISO/IEC 27005 is pure guidance and contains no auditable requirements. Certification is against the ISMS per ISO/IEC 27001; ISO/IEC 27005 provides the method behind it.

What is new in the 2022 edition?

The 4th edition is more closely aligned with ISO 31000 and ISO/IEC 27001:2022, places the asset-based and event-based approaches on an equal footing, and separates risk assessment and risk treatment more clearly.

How does ISO/IEC 27005 relate to ISO/IEC 27001?

ISO/IEC 27001 requires a risk process in clauses 6.1 and 8.2/8.3 but prescribes no specific method. ISO/IEC 27005 fills that gap, providing the method for assessment, treatment and the risk treatment plan.

Does ISO/IEC 27005 help with NIS2 and DORA?

Yes. Both the risk-based approach of NIS2 (Art. 21) and ICT risk management under DORA can be substantiated and documented robustly with an ISO 27005-conformant process.

Asset-based or event-based – which is right?

Both are valid. The asset-based approach starts from assets, threats and vulnerabilities; the event-based one from scenarios. We choose the approach – or a hybrid – that fits the scope and maturity of your organisation.

Make your risk management audit-ready

We set up an ISO/IEC 27005-conformant risk process with you that supports ISO 27001, NIS2 and DORA alike.