ISO 27005 Risk Assessment: A Practical Guide
Every ISO 27001 information security management system (ISMS) rests on one activity: understanding and treating information security risk. ISO 27005 is the international guidance on how to do that well. It does not certify anything, but it gives you a tested, structured method that auditors recognise.
This guide explains what ISO/IEC 27005:2022 covers, how it supports the risk clauses of ISO 27001, the two approaches to identifying risk, and each step from setting criteria to monitoring. It includes a short worked example and the most common mistakes to avoid.
What ISO/IEC 27005:2022 is and who it is for
The current edition, ISO/IEC 27005:2022, was published in October 2022 as the fourth edition of the standard. Its full title is “Information security, cybersecurity and privacy protection — Guidance on managing information security risks”.
It is useful for any organisation that manages information security risk, and especially for those that:
- operate, or are building, an ISMS based on ISO 27001;
- need a defensible risk methodology for regulators, customers or auditors;
- want to align information security risk with enterprise risk management based on ISO 31000.
Because it is a guidance document, you cannot be certified against it. Its value lies in helping you meet the mandatory risk requirements of ISO 27001 consistently.
What changed from the 2018 edition
- The structure and terminology were aligned with ISO/IEC 27001:2022 and ISO 31000:2018.
- “Impact” was largely replaced by “consequence”, and the concept of a “risk scenario” was introduced: a sequence or combination of events leading from the initial cause to the unwanted consequence.
- Two risk identification approaches, event-based and asset-based, were described explicitly.
- The six annexes of the 2018 edition were consolidated into a single informative annex with examples of techniques and criteria.
How ISO 27005 relates to ISO 27001
ISO/IEC 27001:2022 sets out what you must do. The guidance standard explains how to do it. The key links are:
- Clause 6.1.2 (information security risk assessment): requires you to define and apply a risk assessment process that establishes risk acceptance criteria and criteria for performing assessments, produces consistent, valid and comparable results, identifies risks and risk owners, and analyses and evaluates those risks.
- Clause 6.1.3 (information security risk treatment): requires you to select treatment options, determine necessary controls, compare them with Annex A, produce a Statement of Applicability and obtain risk owners’ approval of the treatment plan and acceptance of residual risk.
- Clause 8.2 (information security risk assessment): requires you to perform risk assessments at planned intervals, or when significant changes are proposed or occur, and to retain documented results.
- Clause 8.3 (information security risk treatment): requires you to implement the treatment plan and retain the results.
In short, clause 6 defines your methodology and clause 8 proves you run it. The 2022 guidance fills in the detail for both.
The risk management process
ISO/IEC 27005:2022 describes an iterative process: establish the context, assess the risk (identify, analyse, evaluate), treat it, and then communicate, monitor and review throughout.
1. Establish context and risk criteria
Start with the scope of the ISMS, the requirements of interested parties and your organisation’s risk appetite. Then define two sets of criteria:
- Risk acceptance criteria: the level of risk the organisation is willing to accept, and who can accept it. These may vary by risk type or business area.
- Criteria for performing risk assessments: scales for likelihood and consequence, the method (qualitative, semi-quantitative or quantitative) and the risk matrix or formula used to combine them.
Keep the scales simple and describe each level in business terms, such as financial loss, regulatory exposure, service downtime or harm to individuals. That is what makes results comparable across assessors.
2. Identify risks
The standard describes two complementary approaches.
- Event-based approach: a higher-level, strategic view. You consider risk sources, the events they could cause and the consequences for your objectives, often expressed as risk scenarios. It works well early on, for leadership discussions and in fast-changing environments.
- Asset-based approach: a more detailed, operational view. You identify assets, the threats to them and the vulnerabilities those threats could exploit. It suits environments where assets are well documented and gives a precise basis for selecting controls.
Many organisations combine them: event-based scenarios to capture what matters most, and asset-based analysis to go deeper where needed. Whichever you choose, assign a risk owner to every risk, meaning the person with the accountability and authority to manage it.
3. Analyse risks
For each risk, assess the likelihood of the scenario and the severity of its consequences, taking existing controls into account. The result is a level of risk expressed on the scale you defined. Record your reasoning, not just the score, so that later reviews can see why a rating was chosen.
4. Evaluate risks
Compare each level of risk with your acceptance criteria and prioritise. Risks above the threshold need treatment; risks within it may be retained, but the decision should still be recorded.
5. Treat risks
The guidance describes four broad treatment options:
- Modify: apply controls to reduce likelihood or consequence.
- Retain: accept the risk based on an informed decision.
- Avoid: stop or change the activity that creates the risk.
- Share: transfer part of the risk to another party, for example through insurance or outsourcing. Accountability stays with you.
Document the chosen controls in a risk treatment plan, check them against ISO 27001 Annex A to make sure nothing necessary is missed, and update your Statement of Applicability. Risk owners then approve the plan and formally accept the residual risk.
6. Communicate, monitor and review
Risk changes as your business, technology and threats change. Review risks at planned intervals and whenever something significant happens, such as a new system, a merger, a major incident or new regulation. Track treatment actions to completion and report the risk position to top management as input to management review.
A worked mini example
Consider a mid-sized online retailer using a simple 1 to 5 scale for likelihood and consequence, with risk scored as likelihood multiplied by consequence. Its acceptance criterion says that scores of 8 or below may be retained by the risk owner, while higher scores need treatment.
| Step | Result |
|---|---|
| Risk scenario (event-based) | A phishing email captures an administrator’s credentials, leading to ransomware on the order management system and several days of lost sales. |
| Risk owner | Head of e-commerce operations |
| Existing controls | Email filtering, daily backups (not regularly tested), password-only admin access |
| Analysis | Likelihood 4, consequence 5, score 20 |
| Evaluation | Above the acceptance threshold; treatment required |
| Treatment (modify) | Multi-factor authentication for admin accounts, quarterly restore tests, phishing awareness training, endpoint detection and response |
| Residual risk | Likelihood 2, consequence 4, score 8; accepted by the risk owner and reviewed in six months |
The same risk could then be refined with an asset-based view of the order system, its servers and admin accounts to confirm that no vulnerability has been overlooked.
Common ISO 27005 mistakes
- Vague criteria. Scales such as “low, medium, high” without definitions produce inconsistent results that auditors will question.
- Endless asset lists. Cataloguing every laptop before assessing any risk wastes months. Group assets and focus on what supports critical processes.
- No real risk owners. Assigning every risk to the IT or security team leaves business leaders unaware of the risks they are accepting.
- Controls first, risks second. Working backwards from Annex A to justify controls you already have undermines the whole process.
- A one-off exercise. A risk register that is never updated fails clause 8.2 and quickly becomes irrelevant.
- Undocumented residual risk acceptance. Without recorded approval by risk owners, you cannot show that clause 6.1.3 is met.
How Enactia helps
Enactia is a governance, risk and compliance (GRC) platform that helps you run your risk process in one place rather than across spreadsheets.
- Risk registers and treatment. Enterprise Risk Management lets you record risks, owners, likelihood and consequence scores, treatment plans and residual risk, and track actions to completion.
- Asset context. Asset Management helps you maintain the inventory that supports asset-based risk identification.
- Link risk to controls. Compliance Universe cross-maps controls across ISO 27001 and more than 50 other frameworks and laws, so treatment controls can support several obligations at once.
Frequently asked questions
Is ISO 27005 mandatory for ISO 27001 certification?
No. ISO 27001 requires a risk assessment and treatment process but does not require any particular method. The standard is guidance that many organisations use to design that process.
What is the current edition of the standard?
ISO/IEC 27005:2022, the fourth edition, published in October 2022 and aligned with ISO/IEC 27001:2022.
Should I use an event-based or asset-based approach?
Either is acceptable. Event-based identification gives a strategic view quickly, while asset-based identification gives more detail. Many organisations use both.
Who should be a risk owner?
The person with the accountability and authority to manage the risk, usually a business leader rather than a member of the security team.
How often should risk assessments be performed?
At planned intervals you define, commonly at least annually, and whenever significant changes are proposed or occur, as ISO 27001 clause 8.2 requires.
Conclusion: build a risk process people can use
A good ISO 27005-based process is clear, repeatable and owned by the business. Define meaningful criteria, identify risks in the way that suits your organisation, record decisions and keep the register alive. That gives you a solid foundation for ISO 27001 and for every other framework you need to meet.
Want to see how Enactia can help you run information security risk management in one platform? Contact us or book a demo with our team.
