Skip to main content

ISO/IEC 27005.

ISO 27005 is the information-security risk methodology that bolts onto ISO 27001. Identification, analysis, evaluation, treatment, acceptance. The 2022 revision aligns with ISO 31000's principles and clarifies the relationship with ISO 27001's Clause 6. Less prescriptive than EBIOS RM but the canonical lingua franca with auditors.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyRisk managementAll entries

The Cyber Academy take

ISO 27005 is the information-security risk methodology that bolts onto ISO 27001. Identification, analysis, evaluation, treatment, acceptance. The 2022 revision aligns with ISO 31000's principles and clarifies the relationship with ISO 27001's Clause 6. Less prescriptive than EBIOS RM but the canonical lingua franca with auditors.

What ISO/IEC 27005 is for

ISO/IEC 27005 is the guidance standard for managing information security risk. It does not certify anything and it does not replace ISO/IEC 27001. Instead it gives you a method to perform the risk assessment and risk treatment that Clause 6 of ISO 27001 requires but deliberately leaves open. ISO 27001 tells you that you must identify, analyse, evaluate and treat information security risks; ISO 27005 shows you a defensible way to do it. That division of labour is the single most important thing to understand about the standard.

The method follows a recognisable arc: establish the context, identify the risks, analyse them, evaluate them against your criteria, and then treat them. Treatment ends in a decision and a record, not just a control list. Two outputs matter to auditors above all others. The first is your set of risk acceptance criteria, agreed before you start scoring so the results cannot be reverse-engineered to a convenient answer. The second is the documented sign-off when a residual risk is accepted by the right owner. Those artefacts are what turn a spreadsheet of scores into a managed process.

The current revision aligns the vocabulary and structure with ISO 31000, the organisation-wide risk management standard, so that information security risk speaks the same language as enterprise risk. It also sharpens the relationship with ISO 27001 by mapping its activities onto the 27001 clauses rather than describing a parallel universe. Where older thinking leaned heavily on enumerating assets, threats and vulnerabilities, the revision accommodates both that event-based view and a scenario-based view, giving teams room to assess risk in the way that actually fits their environment.

ISO 27005 next to EBIOS RM

Practitioners in France constantly weigh ISO 27005 against EBIOS Risk Manager, the method maintained by ANSSI. They are not rivals so much as different instruments. ISO 27005 is less prescriptive, internationally recognised and the lingua franca with certification auditors, which makes it the natural fit when your goal is an ISO 27001 certificate that travels. EBIOS RM is more structured and scenario-driven, built around strategic and operational attack scenarios and explicit risk origins, which suits high-stakes or regulated French contexts. Many organisations run EBIOS RM for the analysis and then express the results in ISO 27005 terms for the ISMS.

ISO/IEC 27005 compared with EBIOS Risk Manager
DimensionISO/IEC 27005EBIOS Risk Manager
NatureInternational guidance standardNational method maintained by ANSSI
StyleLess prescriptive, flexibleStructured, scenario and threat driven
Best fitISO 27001 certification, global recognitionHigh-stakes and regulated French contexts
AudienceCertification auditors worldwideFrench public sector and critical operators

What practitioners actually do

Using ISO 27005 well, rather than producing a one-time document, looks like this in practice:

  1. Set the context first: scope, the criteria for impact and likelihood, and the risk acceptance thresholds, all agreed before any scoring begins.
  2. Identify risks in the way that fits the environment, whether asset-threat-vulnerability chains or end-to-end scenarios, and avoid mixing methods inconsistently across the same assessment.
  3. Analyse and evaluate against the pre-agreed criteria so the priority list is reproducible, then choose a treatment option: modify, retain, avoid or share.
  4. Record residual risk and obtain explicit acceptance from the named risk owner, because that sign-off is what links the assessment back to ISO 27001 leadership accountability.
  5. Revisit the assessment on a defined cadence and after significant change, so the risk picture stays current rather than ageing quietly between certification cycles.

Frequently asked questions

01Can I get certified against ISO 27005?

No. ISO 27005 is guidance, not a requirements standard, so there is no certificate for it. You certify against ISO 27001 and use ISO 27005 as the method behind the risk assessment that ISO 27001 requires.

02What is the difference between ISO 27001 and ISO 27005?

ISO 27001 sets the requirement to assess and treat information security risk but leaves the method open. ISO 27005 supplies a recognised method for doing that work. One is certifiable, the other is the toolkit that helps you satisfy it.

03Should I use ISO 27005 or EBIOS Risk Manager?

Use ISO 27005 when you want the international standard that auditors expect for ISO 27001. Choose EBIOS RM when you need its structured, scenario-driven analysis, common in French regulated and high-stakes contexts. The two can be combined.

04How does ISO 27005 relate to ISO 31000?

ISO 31000 is the generic enterprise risk management standard. The current ISO 27005 revision aligns its principles and vocabulary with ISO 31000, so information security risk fits inside the wider risk management framework rather than standing apart from it.

05Does ISO 27005 tell me which controls to implement?

No. It helps you decide which risks to treat and how, but the control reference is ISO 27002 and the Annex A set in ISO 27001. ISO 27005 drives the selection logic, not the catalogue of controls itself.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.