.png)
.png)

ISO 27005
Framework Name
ISO/IEC 27005
Type
Voluntary
Region / Jurisdiction
Global
Enforcing Body / Certifying Party
International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) publish the standard. There is no certifying body and no certification possible against ISO 27005, it is explicitly a guidance document with no auditable requirements
Penalty / Consequence of Non-Compliance
No legal penalty, and nothing to be certified against directly. The practical consequence is indirect but real: ISO 27001 requires organizations to run a risk assessment process, and an ISO 27001 auditor will expect to see a structured methodology behind it, which is exactly what ISO 27005 provides
What It Is & Why It Matters
ISO 27005 provides guidance for managing information security risk, laying out a five-step process: establishing context, identifying risks, analyzing them, evaluating them, and deciding how to treat them. It doesn't set requirements an organization must meet, it's a how-to guide, deliberately structured to match ISO 27001's own clause layout and built on the same general risk principles as ISO 31000, the broader international risk management standard.
It matters because of a gap ISO 27001 leaves open on purpose. ISO 27001 requires organizations to have a risk assessment process as part of their certification, but it never specifies exactly how to run one, that's left for the organization to define. ISO 27005 is the standard way most organizations fill that gap, giving them a proven, auditor-recognized methodology instead of building a risk assessment process entirely from scratch. It's the same relationship COSO has with Sarbanes-Oxley: the law or certifiable standard requires an outcome, and this is the widely accepted answer for how to actually get there.
Who Needs It
- You are pursuing or maintaining ISO 27001 certification and need a structured, recognized risk assessment methodology
- Your ISO 27001 auditor has asked how you identify, analyze, and treat information security risks, and you want an approach they'll readily recognize
- You already use ISO 31000 for general organizational risk management and want a security-specific extension of it
- You want a repeatable risk process that stays consistent even as your threat landscape changes, rather than reassessing risk from a blank page each cycle