• Blog
  • ISO 27005: ISO 27005 vs ISO 27001 for Information Security Risk Management

    Use ISO 27001 to build and certify your information security management system, and use ISO 27005 to make your risk assessment and risk treatment process more rigorous. They are not competing standards. ISO 27001 tells you what your Information Security Management System must achieve. ISO 27005 gives deeper guidance on how to identify, assess, evaluate, and treat information security risks.

    TLDR: ISO 27001 is the certifiable standard for an Information Security Management System, while ISO 27005 is a risk management guidance standard that supports it. For example, a 200 person SaaS company preparing for ISO 27001 certification may use ISO 27005 to score 120 security risks, reduce 35 high risks to 9, and document treatment decisions. ISO 27001 gives the audit structure. ISO 27005 gives the risk thinking behind that structure.

    ISO 27001 and ISO 27005 serve different jobs

    ISO/IEC 27001 is the standard organizations use when they want a formal, auditable Information Security Management System, often called an ISMS. It sets requirements for governance, leadership, scope, policies, risk treatment, monitoring, continual improvement, and internal audits. Certification bodies audit against ISO 27001, not ISO 27005.

    ISO/IEC 27005 is not a certification standard. It is guidance for information security risk management. It helps teams define risk criteria, identify threats, estimate likelihood and impact, compare risk levels, choose treatment options, and record decisions. It supports ISO 27001 clause 6.1, where risk assessment and risk treatment are required.

    The catch is that many teams treat ISO 27001 as a checklist and then struggle when auditors ask why a control was selected. “Because Annex A says so” is not enough. ISO 27005 helps create the missing logic.

    The short version: certification versus method

    Area ISO 27001 ISO 27005
    Main purpose Build and maintain an ISMS Guide information security risk management
    Certification Yes, organizations can be certified No, it is guidance only
    Primary users CISOs, compliance teams, auditors, executives Risk managers, security architects, control owners
    Focus Management system requirements Risk assessment and treatment process
    Output ISMS scope, policies, risk treatment plan, Statement of Applicability Risk criteria, risk register, analysis method, treatment rationale

    How ISO 27001 treats risk

    ISO 27001 requires a repeatable risk management process. The organization must define how risks are assessed, decide how risk levels are accepted, assess information security risks, and create a risk treatment plan. It must also produce a Statement of Applicability, often called the SoA. This document explains which controls are included, which are excluded, and why.

    ISO 27001 does not force one scoring model. A company may use a simple 1 to 5 likelihood and impact scale. Another may use financial impact bands, threat scenarios, or quantitative analysis. The standard cares that the method is consistent, suitable, documented, and used in practice.

    This flexibility is useful, but it can also cause weak risk registers. Honestly, it feels like some templates were built to satisfy a file upload field, not to help anyone make a security decision. A risk entry such as “data breach, high risk, apply access control” tells very little. Auditors can spot that.

    How ISO 27005 strengthens the risk process

    ISO 27005 gives structure where ISO 27001 stays broad. It explains the information security risk management cycle in more detail. This includes context, risk identification, risk analysis, risk evaluation, risk treatment, risk acceptance, communication, monitoring, and review.

    A strong ISO 27005 based process usually includes:

    • Risk criteria: Clear rules for likelihood, impact, risk appetite, and acceptance.
    • Asset and process context: Data, systems, suppliers, business services, and owners.
    • Threat and vulnerability analysis: Practical scenarios, not vague labels.
    • Risk evaluation: A repeatable way to rank and compare risks.
    • Treatment options: Modify, retain, avoid, or share the risk.
    • Review cycle: Monitoring after controls are implemented.

    ISO 27005 also supports better conversations with management. Instead of saying, “We need multi factor authentication because it is a control,” the security team can say, “Credential theft is likely, remote access is exposed, and the current risk exceeds our acceptance criteria.” That is much stronger.

    Where Annex A fits

    ISO 27001 includes Annex A controls. These controls cover topics such as access control, asset management, supplier security, logging, cryptography, incident management, and business continuity. They are not meant to be copied blindly.

    The correct sequence is simple:

    1. Define the ISMS scope.
    2. Assess risks.
    3. Select treatment options.
    4. Choose suitable controls, including Annex A controls where relevant.
    5. Document inclusion and exclusion in the Statement of Applicability.
    6. Monitor whether treatments work.

    ISO 27005 helps at steps 2 and 3. ISO 27001 governs the full system.

    Which standard should your organization use?

    If your goal is certification, start with ISO 27001. It is the only one of the two that leads to accredited certification. It also gives the management framework needed for governance, audit, continual improvement, and accountability.

    If your risk process is immature, add ISO 27005 early. This is especially useful for organizations with complex technology, regulated data, cloud services, multiple suppliers, or board level reporting duties. It helps prevent shallow scoring and inconsistent treatment decisions.

    For a small company, ISO 27005 does not need to become a heavy project. A practical method may be enough. For example, use five likelihood levels, five impact levels, defined acceptance thresholds, named risk owners, and quarterly review. The point is not paperwork. The point is reliable decisions.

    Common mistakes when comparing ISO 27005 and ISO 27001

    • Assuming ISO 27005 replaces ISO 27001: It does not. It supports risk management but does not provide ISMS certification requirements.
    • Treating Annex A as the risk assessment: Controls are not risks. They are possible responses to risks.
    • Using vague risk statements: “Cyber attack” is too broad. “Phishing leads to unauthorized mailbox access and invoice fraud” is better.
    • Ignoring risk acceptance: Accepted risks need ownership, reasons, and review dates.
    • Failing to connect risks to controls: Every major control should trace back to a risk, obligation, or business requirement.

    A practical example

    Consider a healthcare software provider hosting patient data in a cloud platform. Under ISO 27001, the company defines the ISMS scope, assigns responsibilities, creates policies, performs internal audits, and prepares for certification. The risk assessment identifies unauthorized access to patient records as a high risk.

    Using ISO 27005 guidance, the company breaks the risk into clear scenarios. One scenario is stolen administrator credentials. Another is excessive user permissions. Another is weak supplier access control. Each scenario is scored against defined likelihood and impact criteria.

    The treatment plan includes multi factor authentication, privileged access reviews, supplier access restrictions, logging, and alerting. The Statement of Applicability then records the selected controls and explains why they apply. This creates a clean audit trail from risk to control to evidence.

    How to combine them well

    The best approach is to make ISO 27001 the governing framework and use ISO 27005 as the risk engine inside it. Keep the process lean. Risk management fails when it becomes a yearly spreadsheet ritual that nobody trusts.

    An effective combined model should include:

    • One approved risk methodology used across the ISMS.
    • Risk owners who understand the business impact.
    • Control owners who can provide evidence.
    • Risk acceptance rules approved by leadership.
    • Regular review after incidents, major changes, audits, and supplier changes.

    ISO 27001 answers the governance question: Do we have a controlled, auditable security management system? ISO 27005 answers the risk question: Are we assessing and treating information security risks in a structured and defensible way?

    The most reliable answer is to use both. ISO 27001 gives the formal ISMS and certification path. ISO 27005 gives depth to the risk process that supports it. Together, they help an organization move from checkbox compliance to security decisions that can stand up to audit, management review, and real incidents.

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    7 mins