Skip to main content
Category: Risk Assessment & Analysis

ISO/IEC 27005

Simply put

ISO/IEC 27005 is an international standard, jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), that provides guidance on managing information security risk. It supports organizations in identifying, analyzing, evaluating, and treating risks to their information and systems. Readers should verify the current edition and its specific scope against the official ISO/IEC text, as details may change across revisions.

Formal definition

ISO/IEC 27005 is a guidance standard within the ISO/IEC 27000 family that addresses information security risk management, generally intended to support the requirements for risk management defined in ISO/IEC 27001. It is guidance in nature rather than a certifiable requirements standard, and it does not prescribe a single mandated risk methodology, instead offering approaches to risk identification, analysis, evaluation, and treatment that organizations tailor to their context. This entry describes the concept only; it does not cover specific clause content, the current edition or revision year, or its relationship to any particular jurisdiction's compliance obligations, and it is distinct from U.S. federal frameworks such as the NIST Risk Management Framework or NIST SP 800-30. Practitioners should confirm the applicable edition, scope, and mapping to their own control baselines against the authoritative ISO/IEC publication.

Why it matters

Information security risk management is the discipline that connects an organization's security controls to the actual threats and business consequences those controls are meant to address. ISO/IEC 27005 matters because it provides internationally recognized guidance for performing that risk management in a structured way, supporting the risk management requirements set out in ISO/IEC 27001. For organizations pursuing or maintaining ISO/IEC 27001 certification, this guidance helps translate the standard's requirements into a repeatable process for identifying, analyzing, evaluating, and treating risk.

Because ISO/IEC 27005 is guidance rather than a certifiable requirements standard, it does not mandate a single methodology. This flexibility allows organizations to tailor risk activities to their own context, sector, and risk appetite, which is valuable for multinational operations that must reconcile diverse regulatory and operational environments. It also means that the rigor and consistency of any given risk program depend heavily on how the guidance is applied, so organizations should not treat adoption of the standard as evidence of a mature or effective risk posture on its own.

For practitioners working in defense and public sector environments, it is important to recognize that ISO/IEC 27005 is distinct from U.S. federal frameworks such as the NIST Risk Management Framework and NIST SP 800-30. Alignment with, or certification against, ISO/IEC standards does not automatically satisfy federal, defense, or CUI-related obligations, which are governed by separate authorities. Readers should confirm the current edition and scope against the official ISO/IEC text and map any risk activities to the specific control baselines and compliance obligations that apply to their systems.

Who it's relevant to

ISO/IEC 27001 implementers and certification candidates
Organizations building or maintaining an information security management system under ISO/IEC 27001 can use ISO/IEC 27005 as supporting guidance for the risk management activities the requirements standard expects. Because it is guidance rather than a certifiable requirement, teams should treat it as an aid to designing their risk process and verify the current edition and scope against the official ISO/IEC text.
Risk managers and information security officers
Practitioners responsible for identifying, analyzing, evaluating, and treating information security risk can draw on ISO/IEC 27005's approaches while tailoring them to their organizational context, since the standard does not prescribe a single mandated methodology. They should document how their chosen methods satisfy applicable requirements and confirm details against the authoritative publication.
Government contractors and public sector organizations operating across frameworks
Entities that operate under both international standards and U.S. federal or defense requirements should note that ISO/IEC 27005 is distinct from the NIST Risk Management Framework and NIST SP 800-30. Alignment with ISO/IEC guidance does not automatically satisfy FISMA, DoD RMF, or CUI-related obligations, so these should be assessed separately against the governing authorities.
Auditors and assessors
Auditors evaluating an organization's risk management practices may reference ISO/IEC 27005 to understand the guidance an organization has adopted, while recognizing it is non-certifiable guidance rather than a requirements standard. Assessment against this guidance is distinct from certification under ISO/IEC 27001, and its scope and edition should be verified against the official text.

Inside ISO/IEC 27005

Information Security Risk Management Guidance
ISO/IEC 27005 is an international standard, issued by the ISO/IEC joint technical committee, that provides guidance on information security risk management. It supports the risk-based requirements of the ISO/IEC 27001 information security management system (ISMS) framework but does not itself specify a certifiable set of controls.
Risk Management Process Elements
The standard generally describes the core activities of a risk management process, which in most versions include context establishment, risk identification, risk analysis, risk evaluation (together often referred to as risk assessment), risk treatment, risk acceptance, and ongoing risk communication and monitoring. The exact structure and terminology have shifted across revisions, so readers should verify against the current published edition.
Relationship to the ISO/IEC 27000 Family
ISO/IEC 27005 is intended to be used alongside ISO/IEC 27001 and ISO/IEC 27002, providing methodology-level guidance rather than a management system specification (27001) or a control catalog (27002). It is designed to be broadly compatible with the general risk management principles found in ISO 31000.
Methodology-Neutral Approach
The standard generally does not mandate a single specific risk assessment methodology. It offers guidance and illustrative approaches while leaving organizations to select or tailor techniques appropriate to their context, sector, and risk appetite.
Voluntary, Non-Regulatory Character
As an ISO/IEC standard, 27005 is a voluntary consensus document rather than a law or regulation. It is not itself a U.S. federal control baseline and does not, on its own, satisfy FISMA, FedRAMP, RMF, or DFARS/CMMC obligations, which are governed by their own authorities.

Common questions

Answers to the questions practitioners most commonly ask about ISO/IEC 27005.

Is ISO/IEC 27005 a certifiable standard that an organization can be audited against?
No. ISO/IEC 27005 is a guidance document that provides support for the information security risk management process within an information security management system (ISMS). Unlike ISO/IEC 27001, which specifies certifiable requirements, ISO/IEC 27005 is not a standard against which an organization is certified. It offers non-binding recommendations that organizations may adapt to their own context, and readers should confirm the scope and status of the applicable edition against the official ISO/IEC text.
Does following ISO/IEC 27005 mean an organization automatically meets NIST SP 800-30 or NIST SP 800-53 risk management expectations?
Not necessarily. ISO/IEC 27005 is maintained by ISO/IEC and addresses risk management in the context of an ISO/IEC 27001 ISMS, whereas NIST SP 800-30 (risk assessment guidance) and NIST SP 800-53 (control catalog) are issued by NIST and are generally applied to U.S. federal systems under frameworks such as the RMF and FISMA. These publications reflect broadly compatible risk concepts but are distinct in authority, terminology, and structure. Alignment with one does not automatically satisfy the other, and organizations subject to federal or defense requirements should verify obligations against the governing NIST publications and applicable agency tailoring.
How does ISO/IEC 27005 relate to the ISO/IEC 27001 ISMS in practice?
ISO/IEC 27005 is generally used to support the risk management activities that ISO/IEC 27001 requires an organization to perform, such as identifying, analyzing, evaluating, and treating information security risks. In most implementations it serves as guidance to help operationalize those requirements, but it does not replace the certifiable requirements set out in ISO/IEC 27001. Organizations should confirm how the current editions of both documents reference one another.
Does ISO/IEC 27005 prescribe a single required risk assessment methodology?
As a guidance document, ISO/IEC 27005 generally describes concepts and approaches for information security risk management rather than mandating one specific methodology. Organizations typically retain flexibility to select or tailor a method suited to their context, provided it satisfies any applicable ISMS requirements. Readers should verify the specific approaches described in the applicable edition against the official text.
Can ISO/IEC 27005 be used alongside frameworks intended for CUI or DoD systems?
ISO/IEC 27005 can inform an organization's internal risk management practices, but it is not a substitute for the requirements that apply to Controlled Unclassified Information, DoD systems under the RMF, or defense contract obligations. Requirements for those environments derive from separate authorities and publications. Organizations operating in federal, defense, or CUI contexts should confirm their obligations against the governing regulations and agency-specific guidance rather than relying on ISO/IEC 27005 alone.
How should an organization account for revisions when relying on ISO/IEC 27005?
Because ISO/IEC periodically revises its standards, the structure, terminology, and recommendations of ISO/IEC 27005 can change across editions. Organizations should reference the edition applicable to their program and verify its current status and content against the official ISO/IEC publication rather than assuming continuity across versions.

Common misconceptions

ISO/IEC 27005 is a certifiable standard against which organizations are audited.
Certification in the ISO/IEC 27000 family is generally issued against ISO/IEC 27001, the ISMS requirements standard. ISO/IEC 27005 provides supporting risk management guidance and is not typically the basis for a certification audit.
Following ISO/IEC 27005 satisfies U.S. federal or defense compliance requirements.
ISO/IEC 27005 is a voluntary international standard and does not by itself meet obligations under FISMA (NIST-based, for civilian agencies), the DoD RMF, FedRAMP (maintained by the FedRAMP PMO), or DFARS/CMMC requirements. Those regimes are anchored to their own governing publications and authorities, and readers should confirm applicability against current official sources.
ISO/IEC 27005 prescribes a fixed, mandatory risk assessment methodology.
The standard is generally methodology-neutral, offering guidance and examples rather than dictating one required technique. Organizations are expected to select and tailor an approach suited to their context.

Best practices

Verify which edition of ISO/IEC 27005 you are working from, since the process structure and terminology have changed across revisions, and align your documentation to the current published text.
Use ISO/IEC 27005 as risk management guidance in support of an ISO/IEC 27001 ISMS rather than as a standalone certification target, and pair it with ISO/IEC 27002 for control selection.
Do not assume ISO/IEC 27005 conformance satisfies FISMA, RMF, FedRAMP, or DFARS/CMMC obligations; map any overlaps explicitly and confirm each requirement against its own governing authority.
Select and document a risk assessment methodology appropriate to your organizational context, since the standard is generally methodology-neutral and leaves the choice to the organization.
Treat risk management as an ongoing cycle by maintaining continuous risk communication, monitoring, and periodic reassessment rather than a one-time exercise.
For defense and public sector systems, coordinate any ISO/IEC 27005-based risk practices with the applicable RMF, CUI, or classified-system requirements and consult current official sources before relying on them for compliance.