ISO 27005: the information security risk management standard explained

Definition, what is new in the 2022 edition, the process step by step, and how it differs from ISO 27001, ISO 31000 and EBIOS RM.

· 11 min read
Illustration: concentric glass rings around an orange core

ISO 27005 is the international standard that provides guidance on managing information security risks. It describes how to establish the context, assess, treat and accept these risks, then monitor them over time, without imposing a method or a tool. The current version, ISO/IEC 27005:2022, serves as guidance for the risk assessment required by ISO 27001.

01

What is the ISO 27005 standard?

ISO 27005, in full ISO/IEC 27005:2022, belongs to the ISO/IEC 27000 family, which is dedicated to information security. Published jointly by ISO and IEC, it is titled “Information security, cybersecurity and privacy protection — Guidance on managing information security risks”. The key word is guidance: ISO 27005 is a set of guidelines, not a set of requirements.

In practice, the standard explains what an organisation must do to understand its information security risks, decide which ones to treat, choose controls and monitor the outcome. It sets no severity scale, no mandatory threat catalogue and no software. This flexibility is intentional: a 50-person SME and a banking group do not need the same level of detail. If you are new to the subject, our article What is a risk analysis? lays the groundwork before you dive into the standard.

Who is ISO 27005 for?

  • CISOs and risk managers who build or run an information security management system (ISMS).
  • Organisations preparing for ISO 27001 certification that must justify their risk assessment process.
  • Entities subject to NIS 2 or DORA, which must base their security measures on documented risk management.
  • Auditors and consultants, who use it as a shared frame of reference.
02

ISO 27005:2022: what changed compared with 2018

The fourth edition of ISO 27005 was published in October 2022, the same month as ISO 27001:2022. It replaces the 2018 edition, which has been withdrawn. ISO's official page shows no revision under way in 2026, so ISO/IEC 27005:2022 is the reference version. The main changes, described in detail by the certification body PECB among others, are as follows.

TopicISO 27005:2018ISO 27005:2022
AlignmentISO 27001:2013ISO 27001:2022 and ISO 31000:2018 vocabulary (“consequence” rather than “impact”)
ScenariosIncident scenariosRisk scenarios: a sequence of events from an initial cause to an unwanted consequence
IdentificationList of activities (assets, threats, controls, vulnerabilities, consequences)Two approaches: event-based (strategic) and asset-based (operational)
AcceptanceA stage in its own rightA decision taken at the end of treatment
AnalysisQualitative or quantitativeSemi-quantitative approach added
AnnexesSeveral annexes (threats, vulnerabilities…)A single Annex A: risk criteria, techniques, risk sources and target objectives, example scenarios

Two changes deserve attention. First, the standard now reasons in terms of risk scenarios, which brings the analysis closer to the language of business units and management. Second, Annex A refers to risk sources and target objectives, two core concepts of EBIOS Risk Manager: the convergence between the international standard and the French method is clear. If you built your approach on the 2018 edition, updating your risk assessment procedure is an opportunity to align it with these concepts.

03

The ISO 27005 risk management process, step by step

ISO 27005 takes the ISO 31000 process and applies it to information security. It consists of six steps, framed by two continuous activities: communication with stakeholders and monitoring. The diagram below shows how they fit together; we then go through them with a running example, a 60-person accounting firm.

  1. 01 Context Scope, stakes, interested parties, risk and acceptance criteria.
  2. 02 Identification Risk scenarios: sources, events, affected assets, consequences.
  3. 03 Analysis Estimating the likelihood and the severity of consequences.
  4. 04 Evaluation Comparison with criteria, prioritising the risks to treat.
  5. 05 Treatment Choosing options and controls, treatment plan, Statement of Applicability.
  6. 06 Acceptance Formal decision by risk owners on the residual risk.

Iteration: a new cycle if residual risk is not acceptable or if the context changes

The information security risk management process according to ISO/IEC 27005:2022, aligned with ISO 31000:2018. Acceptance of residual risk is a decision taken at the end of treatment.

1. Establish the context

Everything starts with scoping: which perimeter (the whole organisation, a business unit, an application), which stakes, which legal obligations, which stakeholders. This is also where you set the risk criteria: likelihood and severity scales, and the threshold above which a risk is no longer acceptable. For the firm, the chosen scope is the production of tax returns; scales run from 1 to 4, and any risk with a level above 6 (severity × likelihood) must be treated.

2. Identify the risks

You list the scenarios that could prevent the organisation from achieving its objectives: who or what causes them, what event occurs, which assets are affected and with what consequences. Example: “a cybercriminal group encrypts the file server in April, at the height of tax season”. Expressing the security needs of information first, for example with the DICP criteria, helps you spot what really matters. For this step, the standard offers two complementary approaches, described in the next section.

3. Analyse the risks

For each scenario, you estimate the severity of consequences and their likelihood, qualitatively, semi-quantitatively or quantitatively. The firm rates severity at 4 (late filings, penalties for its clients, reputational damage) and likelihood at 3 (VPN access without multi-factor authentication, backups connected to the network). Risk level: 12 out of 16.

4. Evaluate the risks

Evaluation compares each level with the criteria set at the outset and ranks risks by priority. This is often when you produce a risk matrix or a risk map for management. At 12, the ransomware scenario is well above the threshold of 6: it goes to the top of the list.

5. Treat the risks

For each risk to be treated, you choose one or more options: reduce the risk with controls, avoid it by giving up the activity that exposes you, share it (insurance, outsourcing) or retain it knowingly. The selected controls are compared with Annex A of ISO 27001, which feeds the Statement of Applicability, and then grouped into a treatment plan. The firm decides to enable multi-factor authentication on the VPN, set up an offline backup tested every quarter and take out cyber insurance. Estimated residual risk: severity 3, likelihood 2, giving 6.

6. Accept the residual risk

Since the 2022 edition, acceptance is no longer a separate stage but a formal decision taken by risk owners at the end of treatment. Here, the managing partner approves the plan and accepts the residual risk of level 6, which meets the criteria. If the residual risk remained too high, a new treatment cycle would begin. Our article Inherent risk and residual risk details this calculation and decision.

Continuously: communicate and monitor

Communication and consultation involve business units at every step: they are the ones who know the real consequences of an outage. Monitoring and review check that controls are applied and that the context has not changed. A new supplier, a merger or a wave of attacks targeting your sector should trigger an update without waiting for the annual review.

04

Event-based or asset-based: two ways to identify risks

This is the most practical contribution of the 2022 edition of ISO 27005. The standard distinguishes two starting points for identifying risks, which can be combined.

  • The event-based approach starts from feared events and their sources, at a high level, without a detailed inventory. It gives a strategic view that can be produced quickly with management, and is mainly used to assess consequences. Example: “production halted during tax season”.
  • The asset-based approach starts from the asset inventory (servers, applications, premises, people) and looks for threats and vulnerabilities for each one. It is more detailed and more operational, and helps estimate likelihood and choose controls. Example: “VPN exposed to the internet without multi-factor authentication”.

In practice, the two complement each other: the first sets priorities, the second shows where to act. An organisation that is just starting out benefits from beginning with events, to quickly build a view shared with business units, then going down to asset level for the most severe scenarios.

05

ISO 27005 and ISO 27001: which clauses are involved?

ISO/IEC 27001:2022 sets the requirements for an ISMS and can be certified. It requires documented risk assessment and treatment but does not impose any method. ISO 27005 explains how to meet these requirements. The table below links the two standards.

ISO 27001:2022 clauseWhat it requiresWhat ISO 27005 adds
6.1.2 Risk assessmentA defined process, with acceptance criteria, consistent and comparable results, identified risk ownersRisk criteria, identification, analysis and evaluation, example scales
6.1.3 Risk treatmentChoice of options, controls compared with Annex A, Statement of Applicability, approved plan, acceptance of residual riskTreatment options, building the plan, guidance on the Statement of Applicability
8.2 Risk assessment (operation)Perform the assessment at planned intervals and when significant changes occurUpdate triggers, monitoring of risk factors
8.3 Risk treatment (operation)Implement the treatment plan and keep recordsMonitoring of controls, documentation, review

A certification auditor will not ask whether you “applied ISO 27005”, but whether your process produces consistent, repeatable results that are followed up over time. Following the standard remains the simplest way to demonstrate this. To go further on running your ISMS, see our compliance campaigns module.

06

ISO 27005 vs EBIOS RM vs ISO 31000: which one to choose?

These three frameworks come up in every discussion of cyber risk management, and they are often presented as competitors. In reality, they sit at three different levels.

  • ISO 31000:2018 sets out the principles and process for managing all of an organisation's risks. It does not deal specifically with cybersecurity.
  • ISO 27005 applies this process to information security risks and links it to ISO 27001.
  • EBIOS Risk Manager, published by ANSSI, the French national cybersecurity agency, is an operational method that explains step by step how to carry out the analysis, starting from risk sources and their objectives. ANSSI's guide states that it conforms to ISO 27005:2022 and is compatible with ISO 31000.

Choose your need in the comparison to see the most suitable framework.

Your need

Best fit : ISO/IEC 27005 ISO 27005 was written for this: it follows the structure of ISO 27001:2022 and provides guidance for clauses 6.1.2, 6.1.3, 8.2 and 8.3. You can carry it out with EBIOS RM if you want a more guided method.

Criterion ISO/IEC 27005EBIOS RMISO 31000
Nature Guidance (international standard)Operational method, with workshops and deliverablesGuidelines (international standard)
Published by ISO and IECANSSI, with the Club EBIOSISO
Reference version 2022 (4th edition)ANSSI guide from 2018, version 1.5 in 20242018
Risks covered Information securityDigital risks, targeted threatsAll organisational risks
How prescriptive Medium: the “what”, little of the “how”High: detailed step-by-step approachLow: principles and framework
Link with ISO 27001 Direct: guidance for clauses 6.1 and 8Usable for an ISMS risk assessmentIndirect: general framework
Access Paid (ISO, national bodies)Free (ANSSI website)Paid (ISO, national bodies)
Certification People (e.g. Risk Manager), not organisationsNo organisational certification; ANSSI label for softwarePeople, not organisations
The three frameworks are not competing: ISO 31000 sets the principles, ISO 27005 applies them to information security, and EBIOS RM provides an operational method that ANSSI states conforms to ISO 27005:2022.

The most common combination in France is therefore: an ISO 27001 ISMS, a risk management process that conforms to ISO 27005, and EBIOS RM as the analysis method for sensitive scopes. You do not need one tool per framework: a single risk analysis module can host both ISO 27005 and EBIOS RM analyses, with shared scales.

07

ISO 27005 certification: people, not organisations

This is a common misconception: a company cannot be certified ISO 27005. The standard contains only recommendations, with no auditable requirements. An organisation that wants recognition for the quality of its security risk management aims for ISO 27001 certification, issued by an accredited body.

The “ISO 27005” certifications on the market are certifications of individuals. Bodies such as PECB, for example, award the ISO/IEC 27005 Risk Manager or Lead Risk Manager credentials after training and an exam. They attest that a professional can run the process; they are useful for a consultant or a risk manager, but say nothing about their employer's level of security.

08

Putting ISO 27005 into practice: practical advice

  • Start small. A clear scope and a first complete cycle are worth more than an exhaustive analysis that is never finished.
  • Write your criteria before analysing. Scales defined in advance make results comparable from one year to the next, as ISO 27001 requires.
  • Speak the language of the business. A scenario such as “unable to file tax returns in April” will be understood by management; “unpatched CVE on the VPN” will not.
  • Appoint risk owners. Without an owner, there is no formal acceptance and no follow-up.
  • Plan for updates. Risk assessment is a living process: define the events that trigger a review.

Run in spreadsheets, this approach quickly becomes hard to consolidate and keep up to date. The Phinasoft risk analysis module lets you carry out your analyses according to ISO 27005, according to EBIOS RM with a module labelled by ANSSI, or according to your own method, with your scales and your risk libraries. Each analysis is linked to your action plan, the risk level changes as controls progress, and the history of each scope is kept. To see what this looks like for your own case, you can request a demo.

Summary

01

Guidance, not a method

ISO 27005 provides guidance for managing information security risks. It says what to do at each step without imposing scales or tools: choosing your method is up to you.

02

The 2022 edition is the reference

The 4th edition, published in October 2022, is aligned with ISO 27001:2022 and ISO 31000:2018, and introduces risk scenarios and two identification approaches, event-based and asset-based.

03

The engine of an ISMS

ISO 27005 supports clauses 6.1.2, 6.1.3, 8.2 and 8.3 of ISO 27001. It works alongside EBIOS RM, which ANSSI states conforms to ISO 27005:2022. It certifies people, never organisations.

Frequently asked questions

What is the ISO 27005 standard?

ISO/IEC 27005 is an international standard that provides guidance on managing information security risks. It describes a complete process: context establishment, risk identification, analysis and evaluation, treatment, acceptance, communication and monitoring. It is mainly used to carry out the risk assessment required by ISO 27001.

What is the latest version of ISO 27005?

The current version is ISO/IEC 27005:2022, the fourth edition, published in October 2022. It replaces the withdrawn 2018 edition. It is aligned with ISO/IEC 27001:2022 and ISO 31000:2018 and notably introduces risk scenarios and event-based and asset-based approaches.

Is ISO 27005 mandatory for ISO 27001 certification?

No. ISO 27001 requires a documented risk assessment and treatment process that produces consistent, comparable results, but it does not impose a method. ISO 27005 is the reference guidance for achieving this. You can also use EBIOS RM or an in-house method, as long as it meets clauses 6.1.2 and 6.1.3.

What is the difference between ISO 27005 and EBIOS RM?

ISO 27005 is a guidance standard: it says what to do without detailing how. EBIOS Risk Manager is an operational method published by ANSSI, organised in workshops and focused on risk sources and attack scenarios. According to ANSSI, EBIOS RM conforms to ISO 27005:2022: the two complement each other.

Can a company be certified ISO 27005?

No. ISO 27005 contains no auditable requirements, so an organisation cannot be certified against it. ISO 27001 is the standard used to certify an information security management system. Existing ISO 27005 certifications, such as Risk Manager or Lead Risk Manager, apply to individuals and attest to their skills.

What is the difference between ISO 27005 and ISO 31000?

ISO 31000 sets out the principles and process for managing all of an organisation's risks: financial, legal, operational. ISO 27005 takes this process and its terminology and applies them to information security risks, with field-specific guidance such as risk scenarios and the link with ISO 27001.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.