ISO 27005

ISO/IEC 27005 is the international standard providing guidance on information security risk management, supporting implementation of ISO 27001's risk-based requirements and aligning with the general risk management principles in ISO 31000.

What ISO 27005 Provides

ISO 27005 details the process of information security risk management: context establishment, risk identification, analysis, evaluation, treatment, acceptance, communication, and monitoring. Where ISO 27001 requires an organization to conduct risk assessment and treatment, ISO 27005 describes how to actually do it.

The standard is guidance rather than certifiable requirements. It supports both qualitative and quantitative risk management approaches, giving organizations flexibility to choose the approach that fits their context.

ISO 27005 and Quantified Risk

ISO 27005's process structure is compatible with quantified approaches. The framework does not prescribe a specific methodology, so CRQ methods can be applied within an ISO 27005-aligned process. Modern editions explicitly acknowledge quantitative approaches, including probabilistic modeling.

Organizations moving from qualitative to quantified cyber risk management often find ISO 27005 helpful as a stepping stone. The process structure carries forward while the underlying analysis becomes more rigorous.

Alignment with Other Standards

ISO 27005 sits inside a family. ISO 27001 provides the ISMS framework. ISO 27002 provides control implementation guidance. ISO 31000 provides general risk management principles. ISO 27005 sits between the general (31000) and the specific (27001) as information security risk management guidance.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.