ISO/IEC 27005
ISO/IEC 27005 is an international standard, jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), that provides guidance on managing information security risk. It supports organizations in identifying, analyzing, evaluating, and treating risks to their information and systems. Readers should verify the current edition and its specific scope against the official ISO/IEC text, as details may change across revisions.
ISO/IEC 27005 is a guidance standard within the ISO/IEC 27000 family that addresses information security risk management, generally intended to support the requirements for risk management defined in ISO/IEC 27001. It is guidance in nature rather than a certifiable requirements standard, and it does not prescribe a single mandated risk methodology, instead offering approaches to risk identification, analysis, evaluation, and treatment that organizations tailor to their context. This entry describes the concept only; it does not cover specific clause content, the current edition or revision year, or its relationship to any particular jurisdiction's compliance obligations, and it is distinct from U.S. federal frameworks such as the NIST Risk Management Framework or NIST SP 800-30. Practitioners should confirm the applicable edition, scope, and mapping to their own control baselines against the authoritative ISO/IEC publication.
Why it matters
Information security risk management is the discipline that connects an organization's security controls to the actual threats and business consequences those controls are meant to address. ISO/IEC 27005 matters because it provides internationally recognized guidance for performing that risk management in a structured way, supporting the risk management requirements set out in ISO/IEC 27001. For organizations pursuing or maintaining ISO/IEC 27001 certification, this guidance helps translate the standard's requirements into a repeatable process for identifying, analyzing, evaluating, and treating risk.
Because ISO/IEC 27005 is guidance rather than a certifiable requirements standard, it does not mandate a single methodology. This flexibility allows organizations to tailor risk activities to their own context, sector, and risk appetite, which is valuable for multinational operations that must reconcile diverse regulatory and operational environments. It also means that the rigor and consistency of any given risk program depend heavily on how the guidance is applied, so organizations should not treat adoption of the standard as evidence of a mature or effective risk posture on its own.
For practitioners working in defense and public sector environments, it is important to recognize that ISO/IEC 27005 is distinct from U.S. federal frameworks such as the NIST Risk Management Framework and NIST SP 800-30. Alignment with, or certification against, ISO/IEC standards does not automatically satisfy federal, defense, or CUI-related obligations, which are governed by separate authorities. Readers should confirm the current edition and scope against the official ISO/IEC text and map any risk activities to the specific control baselines and compliance obligations that apply to their systems.
Who it's relevant to
Inside ISO/IEC 27005
Common questions
Answers to the questions practitioners most commonly ask about ISO/IEC 27005.