Start a free trial
Menu

ISO 27005

ISO 27005 information security risk management software

Teams doing the information-security risk assessment that ISO 27001 clauses 6.1.2 and 6.1.3 require.

ISO 27005 is the guidance for managing information security risk - the assessment and treatment that ISO 27001 requires but does not describe. ComplyTrain runs it as a living register, not an annual document.

ComplyTrain fully supports this standard

What ISO 27005 is

ISO 27001 requires you to assess information security risk and to treat it, in clauses 6.1.2 and 6.1.3. It does not tell you how. ISO/IEC 27005 is the guidance that does: how to establish criteria, identify risk, analyse and evaluate it, decide treatment, and keep the whole thing under review.

It sits inside the ISO 31000 risk process rather than beside it, applied specifically to information security. If you already run risk to ISO 31000, ISO 27005 is that process pointed at your information assets.

It is guidance, not a certification

There is no ISO 27005 certificate. The certificate is ISO 27001, and your risk assessment is one of the things the auditor examines to award it. What ISO 27005 gives you is a defensible method - which matters, because the most common finding against a risk assessment is not that the risks are wrong but that nobody can explain how they were arrived at.

Asset-based or scenario-based

There are two honest ways to start. The asset-based approach works from what you hold - systems, data, people - to the threats against each and the vulnerabilities that let a threat land. It is thorough and it is how most organisations begin, because the inventory already exists.

The scenario-based approach works from what could happen - a ransomware event, a supplier breach, an insider taking a customer list - back to what would have to be true. It produces fewer, larger risks that a board can actually discuss, and it tends to find the cross-cutting exposures an asset list misses.

Neither is more correct. What matters for an audit is that you chose one deliberately, applied it consistently, and can say why. A register that mixes both without a stated method is the one that struggles under questioning.

Criteria come first

The most common weakness in an information security risk assessment is that the acceptance criteria were written after the scoring. Decide what you will tolerate, on what scale, and who is entitled to accept a risk above it - before any risk is scored. Criteria set afterwards are criteria fitted to the answer.

How ComplyTrain helps you run it

An information security risk assessment fails an audit for one of two reasons: it was done once and never revisited, or two people scoring the same risk would not arrive at the same answer. ComplyTrain addresses both:

  • A methodology with calibrated scales, so likelihood and impact mean the same thing to different assessors. Each level carries a written guideline rather than a bare number.
  • Risks held in one register across your standards, so an information-security risk and a quality risk are not maintained in two places.
  • Treatment decisions recorded with an owner and a date, and the control that treats the risk linked to the requirement it satisfies.
  • Review built into the process rather than depending on someone remembering, so the register reflects the organisation as it is now.

See risk management for how the methodology and the register work, and ISO 31000 for the wider process it sits inside.

Questions

Is ISO 27005 a certifiable standard?

No. ISO 27005 is guidance. Your certificate is ISO 27001, and the risk assessment done to ISO 27005 is part of the evidence for it.

What is the difference between ISO 27005 and ISO 31000?

ISO 31000 is the general risk management process for any kind of risk. ISO 27005 applies that process specifically to information security, with the vocabulary of assets, threats and vulnerabilities. If you run both, they are the same process at different scopes rather than two systems.

Do we need a separate register for information security risk?

You do not, and separating them usually costs more than it saves. One register with the right scoping lets a board see the whole risk picture while a security team still works only its own view.

How often should the risk assessment be reviewed?

On a defined cadence and whenever something material changes - a new system, a new supplier, an incident, a change of scope. The standard does not set a frequency; what an auditor tests is whether your own stated cadence is being met.

Does ISO 27005 tell us which scoring scale to use?

No. It describes the process and leaves the scale to you, which is deliberate: a five-point scale that means something to your organisation is worth more than a seven-point one borrowed from a template. What it does expect is that the scale is defined, that the definitions are written down, and that they are applied consistently.

How does this relate to the Statement of Applicability?

Directly. The risk assessment identifies the risk, the treatment decision selects the control that addresses it, and the Statement of Applicability records that selection with its justification. An auditor reading the three together is checking that they tell one story.

The process

The ISO 27005 risk process

ISO 27005 gives information security risk management a repeatable shape. It is guidance, not a certifiable standard, and it is what makes the risk clauses of ISO 27001 workable in practice.

  1. Establish context and criteria

    Decide what the assessment covers, who owns it, and the criteria you will judge risks against. Criteria set before the assessment are the ones that survive contact with an uncomfortable result.

  2. Identify the risks

    Work from assets, threats and vulnerabilities, or from the events that would hurt you, or both. ISO 27005 supports either approach rather than insisting on one.

  3. Analyse and evaluate

    Understand consequence and likelihood, then compare each risk against your criteria to decide which need treatment. The comparison is the decision point, and it belongs on the record.

  4. Treat, accept and monitor

    Choose a treatment, name an owner, and record what residual risk was accepted and by whom. Then keep the register live, because a risk assessment with a date on it is a historical document.

Keep your information security risks in one register

See how ComplyTrain links risks to controls, owners and evidence on a 30-minute demo, using your own risk criteria. Or start a trial and we will set up a register to match how you assess risk.