Skip to main content
Category: Compliance Frameworks & Standards

ISO/IEC 27005

Also known as: ISO 27005, ISO/IEC 27005 Information Security Risk Management
Simply put

ISO/IEC 27005 is an international standard that offers guidance on how organizations can manage risks to their information security. It helps organizations identify what could go wrong with their information, assess how serious those risks are, and decide how to address them. It is designed to support, rather than replace, the broader information security management system defined in ISO/IEC 27001.

Formal definition

ISO/IEC 27005 is a guidance standard within the ISO/IEC 27000 family that provides direction on managing information security risks in support of the requirements specified in ISO/IEC 27001 and the implementation of an information security management system (ISMS). It offers guidelines covering the identification, analysis, and treatment of information security risks, complementing the general risk management concepts referenced in ISO/IEC 27001. As a guidance document, it is descriptive rather than certifiable in its own right; organizations are certified against ISO/IEC 27001, and ISO/IEC 27005 supports the risk management activities that underpin that certification. In a virtual CISO engagement, this standard is typically used to help structure and inform an organization's risk management process, but the standard itself does not guarantee certification or compliance outcomes, which depend on organizational maturity, scope, and how the guidance is applied.

Why it matters

Effective information security leadership depends on making risk decisions in a structured, defensible way rather than reacting to threats ad hoc. ISO/IEC 27005 matters because it provides organizations with recognized guidance for identifying what could go wrong with their information, analyzing how serious those risks are, and deciding how to treat them. This gives security programs a consistent language and process for risk that can be communicated to executives, boards, and auditors, which is often where informal or purely technical approaches to risk break down.

Who it's relevant to

Organizations pursuing or maintaining ISO/IEC 27001 certification
For organizations working toward or sustaining an ISO/IEC 27001 ISMS, ISO/IEC 27005 supports the information security risk management activities that underpin certification. It helps operationalize the risk requirements referenced in ISO/IEC 27001. These organizations should understand that certification is achieved against ISO/IEC 27001, not ISO/IEC 27005, and that using the guidance supports readiness without guaranteeing a certification outcome.
Security and risk leaders, including virtual and fractional CISOs
Security leaders can use ISO/IEC 27005 as a reference to establish a consistent, defensible process for identifying, analyzing, and treating information security risks. In a virtual or fractional CISO engagement, this often means helping structure the organization's risk process and communicating risk to executives. The leader typically advises and directs, while accountability for risk decisions usually remains with the client organization.
Executives and boards accountable for information security risk
Organizational officers who hold accountability for security decisions benefit from the structured risk view that ISO/IEC 27005 supports, because it frames security as a business risk and governance matter rather than a purely technical one. The realized value depends on their engagement, the scope defined, and the organization's maturity in applying the guidance.
Practitioners implementing or refining a risk management process
Teams responsible for building or improving how information security risks are managed can use ISO/IEC 27005 as guidance on identifying, analyzing, and treating those risks in support of an ISMS. Because the standard is descriptive rather than a prescriptive checklist, practitioners must interpret and adapt it to their context, drawing on business input and defined scope to make it effective.

Inside ISO/IEC 27005

Context establishment
The activity of defining the scope, boundaries, risk criteria, and organizational context for the risk management process, including how the organization sets its risk acceptance criteria and evaluation criteria.
Risk identification
The process of finding, recognizing, and describing risks, including identifying assets, threats, existing controls, vulnerabilities, and potential consequences relevant to information security.
Risk analysis
The step of understanding the nature of identified risks and determining their level, typically by considering likelihood and potential consequences using qualitative, quantitative, or hybrid approaches.
Risk evaluation
The comparison of analyzed risk levels against the organization's defined risk criteria to determine which risks require treatment and to support prioritization.
Risk treatment
The selection and application of options to modify risk, which may include reducing, retaining, avoiding, or sharing risk, along with defining the associated controls and residual risk.
Risk acceptance
The formal decision to accept a risk and its residual level, a decision that typically rests with the accountable client organization and its officers rather than with an advising security leader.
Risk communication and consultation
The ongoing exchange of risk information among stakeholders and decision-makers to support informed decisions throughout the process.
Risk monitoring and review
The continual tracking of risks, controls, and the risk environment to keep the risk picture current and adapt treatment as circumstances change.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27005.

Does implementing ISO/IEC 27005 mean my organization is ISO 27001 certified?
No. ISO/IEC 27005 is a guidance standard focused specifically on information security risk management, providing structured approaches and considerations for risk identification, analysis, evaluation, and treatment. It is not itself a certifiable standard. ISO/IEC 27001 is the certifiable management system standard, and while ISO/IEC 27005 supports the risk management requirements within an ISO 27001 information security management system, following its guidance does not by itself result in or guarantee certification. Certification depends on meeting the requirements of ISO/IEC 27001 and passing an audit by an accredited certification body. A virtual CISO may help align risk management practices with ISO/IEC 27005 as part of supporting ISO 27001 readiness, but readiness and certification are distinct.
Is ISO/IEC 27005 a prescriptive checklist that tells us exactly which risk method to use?
Not in the rigid sense many expect. ISO/IEC 27005 provides guidance and considerations rather than a single mandatory methodology or fixed checklist. It is designed to support a range of risk management approaches and can accommodate different qualitative or quantitative techniques, allowing organizations to adapt the guidance to their context, maturity, and risk appetite. Expecting it to dictate one prescribed method or a definitive list of controls is a common misconception. A virtual CISO typically helps a client select and tailor an approach consistent with the standard's guidance rather than applying it as an off-the-shelf template, and the resulting value depends heavily on organizational context and stakeholder input.
How does a virtual CISO typically use ISO/IEC 27005 within an engagement?
In many engagements, a virtual CISO uses ISO/IEC 27005 as a reference framework to structure and mature the client's information security risk management process, including how risks are identified, analyzed, evaluated, treated, and monitored over time. This is generally a strategy, governance, and program-development activity rather than a hands-on operational one. The vCISO advises and directs the risk management approach, but accountability for accepting or treating risks usually remains with the client organization and its officers. The depth of application varies by provider, scope, and the client's existing maturity.
Can ISO/IEC 27005 be applied without an existing ISO 27001 management system?
Often, yes. While ISO/IEC 27005 is designed to support the risk management activities within an ISO/IEC 27001 information security management system, its guidance on information security risk management can be applied more broadly to help an organization establish or improve risk practices independently. In practice, a virtual CISO may draw on its guidance to build foundational risk processes for organizations not pursuing certification, or to prepare those that intend to pursue ISO 27001 later. The value of this depends on client cooperation, access to stakeholders, and the maturity of existing security processes.
How does ISO/IEC 27005 relate to other frameworks like NIST CSF?
ISO/IEC 27005 focuses specifically on information security risk management processes and considerations, whereas frameworks such as NIST CSF provide a broader outcome-oriented structure across functions like identify, protect, detect, respond, and recover. They are not mutually exclusive and are frequently used together, with ISO/IEC 27005 informing the risk management component of a wider program. A virtual CISO may help a client reconcile multiple references so that risk management is consistent across whichever frameworks, regulations, or standards apply to their environment, rather than treating any single one as complete on its own.
What limits the value of ISO/IEC 27005 in an engagement?
Its value depends on several factors. Because it provides guidance rather than mandatory requirements, outcomes vary with how well the approach is tailored to the organization's context, risk appetite, and maturity. Effective application also relies on access to stakeholders, quality of asset and threat information, defined scope, and ongoing client cooperation to maintain the risk process over time. It supports better-informed risk decisions but does not by itself guarantee specific outcomes such as breach prevention or compliance. A virtual CISO advises and directs the process, but responsibility for implementing controls and accountability for risk decisions typically remain with the client organization.

Common misconceptions

An organization can be certified against ISO/IEC 27005.
ISO/IEC 27005 is guidance for information security risk management and is not itself a certifiable standard. Organizations certify against ISO/IEC 27001, and ISO/IEC 27005 informs how the risk management aspects of that standard may be approached.
ISO/IEC 27005 prescribes a single mandatory risk methodology that must be followed exactly.
The standard is methodology-agnostic. It presents concepts and process steps that organizations adapt to their own context, risk criteria, and appetite rather than mandating one fixed technique.
Engaging a virtual CISO to run an ISO/IEC 27005-aligned process transfers accountability for accepting risk to the vCISO.
A virtual CISO typically advises on and helps operate the risk management process, but legal and organizational accountability for risk acceptance and treatment decisions generally remains with the client organization and its officers unless a contract specifies otherwise.

Best practices

Establish context first by documenting scope, boundaries, and risk acceptance and evaluation criteria before beginning risk identification, so results are consistent and defensible.
Align the ISO/IEC 27005 process with the risk management requirements of ISO/IEC 27001 if certification readiness is a goal, while being clear that following the guidance supports readiness rather than conferring certification.
Adapt the process to organizational maturity and available stakeholder access, recognizing that the value of the engagement depends on client cooperation and defined scope.
Keep risk acceptance decisions with the accountable client officers, ensuring a virtual or fractional CISO documents advice and options rather than unilaterally accepting risk on the organization's behalf.
Choose an analysis approach (qualitative, quantitative, or hybrid) suited to the organization's needs and data availability, and translate results into business risk terms for executive and board decision-making.
Treat risk monitoring and review as ongoing, revisiting risks, controls, and residual risk as the environment changes rather than treating the assessment as a one-time exercise.