ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection — Guidance on managing information security risks

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ISO/IEC 27005:2022 provides guidance on managing information security risks. It describes how to establish the context, identify, analyze, evaluate, and treat risks to information, and how to monitor, review, record, and communicate the results, in support of an information security management system (ISMS) built on ISO/IEC 27001. It is a guidance standard, not a set of certifiable requirements.
The standard is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) and developed by ISO/IEC JTC 1/SC 27, the subcommittee responsible for the ISO/IEC 27000 family. The fourth edition was published in October 2022, replacing ISO/IEC 27005:2018, and is aligned with the risk clauses of ISO/IEC 27001:2022 and the risk management principles of ISO 31000:2018. It applies to organizations of all types and sizes that manage information security risks, whether or not they pursue ISO/IEC 27001 certification.
Organizations use ISO/IEC 27005 to design the risk assessment and risk treatment process that ISO/IEC 27001 requires: defining risk criteria, choosing an event-based or asset-based approach to identify risks, analyzing likelihood and consequence, comparing results against acceptance criteria, selecting treatment options and ISO/IEC 27002 controls, producing a risk treatment plan and Statement of Applicability, and repeating the cycle on a planned schedule and when significant change occurs.
Why it Matters
ISO/IEC 27005:2022 turns the risk requirements of ISO/IEC 27001 into a repeatable method, so security investment follows actual risk rather than assumption.
Key benefits include:
- Direct support for ISO/IEC 27001
The guidance maps to the risk assessment and treatment requirements that auditors test during ISMS certification.
- Better threat identification
Event-based and asset-based approaches help organizations find risks they would otherwise miss.
- Prioritized security investment
Risk analysis and evaluation against defined criteria show which risks justify treatment first.
- Informed, defensible decisions
Recorded risk criteria, results, and acceptance decisions give management and auditors a clear rationale.
- Alignment with enterprise risk management
Its concepts follow ISO 31000, so information security risk can feed the organization's wider risk register.
How it Works
ISO/IEC 27005:2022 is organized around the ISO 31000 process. After clauses on scope, references, terms, and structure, it covers context establishment, the information security risk assessment process of identification, analysis, and evaluation, the risk treatment process, and the operational activities of performing assessments and treatments, monitoring and review, communication and consultation, and documenting results. Annexes give examples of techniques for the assessment steps, including scales for likelihood and consequence and both event-based and asset-based identification.
In practice, an organization first sets its risk criteria: how consequences and likelihood are rated, how risk levels are calculated, and what level is acceptable. It then identifies risks and their owners, analyzes them, evaluates them against the criteria, and decides for each whether to modify, retain, avoid, or share the risk. Treatment produces a plan with controls drawn from ISO/IEC 27002 or elsewhere, approval of residual risk by risk owners, and the Statement of Applicability. The cycle repeats at planned intervals and after significant change, with results recorded as ISMS evidence.
Within SmartSuite, teams can operationalize ISO/IEC 27005 by maintaining the risk register with defined scales and criteria, linking each risk to its owner, treatment plan, and ISO/IEC 27002 controls, and scheduling reassessments and reviews. Approvals of residual risk, the Statement of Applicability, and the history of every change are kept together so ISO/IEC 27001 auditors can trace how each decision was made.
Key Elements
- Context establishment
Defines the scope, the organization's internal and external context, and the risk criteria for consequence, likelihood, risk level, and acceptance.
- Risk identification
Finds information security risks using an event-based approach (risk sources and events), an asset-based approach (assets, threats, and vulnerabilities), or both, and assigns risk owners.
- Risk analysis
Assesses potential consequences and realistic likelihood to determine the level of each risk, using qualitative or quantitative scales.
- Risk evaluation
Compares analyzed risks with the criteria to prioritize them and decide which require treatment.
- Risk treatment
Selects options to modify, retain, avoid, or share risk, determines the necessary controls, and produces the risk treatment plan and Statement of Applicability.
- Monitoring, review, and communication
Keeps risk factors under review, consults stakeholders, and reports results to decision makers.
- Documented information
Records the process, assessment results, and treatment decisions as evidence for the ISMS.
Framework Scope
ISO/IEC 27005:2022 applies to all organizations, regardless of type, size, or sector, that intend to manage risks to the confidentiality, integrity, and availability of information. It supports the requirements of ISO/IEC 27001 but can be used with any ISMS or as a stand-alone method for information security risk management. It does not prescribe a specific technique or tool; organizations choose methods appropriate to their context and document them.
Framework Objectives
ISO/IEC 27005:2022 is intended to help organizations achieve the following outcomes.
Establish and maintain an information security risk management process that meets the requirements of ISO/IEC 27001.
Identify, analyze, and evaluate information security risks consistently against defined criteria.
Select and justify risk treatment options and the controls needed to bring risk to an acceptable level.
Assign risk ownership and obtain approval of residual risk from accountable owners.
Keep risk information current through monitoring, review, and communication with stakeholders.
Provide documented evidence of risk decisions for management, auditors, and interested parties.
Framework in Context
ISO/IEC 27005:2022 is the risk management member of the ISO/IEC 27000 family: ISO/IEC 27000 supplies the vocabulary, ISO/IEC 27001:2022 sets the certifiable ISMS requirements, and ISO/IEC 27002:2022 catalogs the controls that treatment plans draw on, with ISO/IEC 27017, ISO/IEC 27018, and ISO/IEC 27701 extending them for cloud services and privacy. Its process and terminology follow ISO 31000:2018, so it can run as part of an enterprise risk program alongside COSO ERM, and its steps correspond to the risk assessment and response activities in NIST SP 800-39, NIST SP 800-30, and the NIST Risk Management Framework, and to the Govern and Identify functions of NIST CSF 2.0.
Common Framework Mappings
ISO/IEC 27005:2022 is commonly mapped to ISMS, risk management, and control frameworks so that one risk assessment can satisfy multiple certification and regulatory expectations.
Mapped frameworks include:
ISO 27001:2022
ISO 27002:2022
ISO 27000
ISO 31000:2018
ISO 31010:2009
NIST SP 800-39
NIST 800-37 Rev. 2
NIST CSF 2.0
NIST 800-53 Rev. 5
ISO 27017
ISO 27018
ISO 27701
COSO ERM 2017
CIS Controls v8.1
NIST SP 800-30 Rev. 1
FAIR
- ClassificationCategoryInformation Security Risk ManagementDomainRisk ManagementFramework FamilyISO 27000 Series
- Regulatory ContextTypeGuidanceLegal InstrumentGuidance standardSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionGlobalRegion DetailInternationalPublisherInternational Organization for Standardization (ISO) and International Electrotechnical Commission (IEC), ISO/IEC JTC 1/SC 27
- VersioningVersion2022 (Edition 4)Effective DateOctober 2022Issue DateOctober 2022
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: No
ISO/IEC 27005:2022 is sold by ISO and national standards bodies and is not included with the platform; a read-only sample is available on ISO's Online Browsing Platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports ISO 27005
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For ISO/IEC 27005, SmartSuite keeps the risk register, risk criteria, treatment plans, and Statement of Applicability linked to ISO/IEC 27001 requirements and ISO/IEC 27002 controls, with reassessments scheduled and every decision recorded.
Information Security Risk Register
Record risks with sources, events, assets, owners, and scores using the likelihood and consequence scales you define.
Risk Owners and Reassessment Cadence
Assign owners and schedule periodic and change-triggered reassessments with reminders and escalation.
Risk Decisions and Audit Trail
Capture evaluation results, treatment choices, and residual risk approvals with timestamps and approvers.
Treatment Plans and Control Testing
Link treatments to ISO/IEC 27002 controls, track implementation, and test that controls operate as intended.
ISMS and Vendor Risk Alignment
Connect risks to ISO/IEC 27001 clauses, the Statement of Applicability, and third-party assessments.
Risk Reporting
Report risk levels, treatment progress, and acceptance status to management and certification auditors.
Related frameworks

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

ISO/IEC 27002:2022 provides best-practice information security controls to help organizations select, implement, and manage protections for information assets.

ISO/IEC 27000 provides foundational concepts and terminology for establishing and operating an information security management system.

ISO 31000 provides guidelines for identifying, assessing, and managing organizational risks to improve resilience and decision-making.

ISO 31010:2009 provides guidance on selecting and applying risk assessment techniques to identify, evaluate, and manage organizational risks.

NIST SP 800-39 guides organizations to identify, assess, and manage information security risk at all enterprise levels.
Frequently Asked Questions For ISO 27005
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
