What is ISO/IEC 27005?
ISO/IEC 27005 provides guidance on managing information security risks to support the implementation of an information security management system (ISMS) based on ISO/IEC 27001. It offers a structured approach for identifying, assessing and treating information security risks across all types of organisations.
Why is ISO/IEC 27005 important?
In a world where cyber threats evolve daily, managing information security risks is essential for protecting assets and ensuring business continuity. ISO/IEC 27005 helps organisations embed effective risk thinking into their ISMS, aligning with ISO/IEC 27001 and ISO 31000, and ensuring that threats are managed proactively rather than reactively.
Benefits
- Supports effective implementation of ISO/IEC 27001
- Improves ability to identify and address security threats
- Helps prioritise security investments based on actual risk
- Increases resilience and informed decision-making
- Aligns risk management with global best practices
FAQ
Any organisation implementing or improving an ISMS, especially risk owners, ISMS professionals and stakeholders involved in information security.
ISO/IEC 27005 adapts the general principles of ISO 31000 to the specific context of information security.
It covers the full risk management cycle: assessment, treatment, communication, monitoring and review, all tailored to information security.
Buy together
The complete ISO 27000 information security bundle
Empower your organization with robust information security standards
- ISO/IEC 27000:2018
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- ISO/IEC 27005:2022
Общая информация
-
Текущий статус: ОпубликованоДата публикации: 2022-10Этап: Опубликование международного стандарта [60.60]
-
Версия: 4
-
Технический комитет :ISO/IEC JTC 1/SC 27ICS :35.030
- RSS обновления
Жизненный цикл
-
Ранее
ОтозваноISO/IEC 27005:2018
-
Сейчас
-
00
Предварительная стадия
-
10
Стадия, связанная с внесением предложения
-
20
Подготовительная стадия
-
30
Стадия, связанная с подготовкой проекта комитета
-
40
Стадия, связанная с рассмотрением проекта международного стандарта
-
50
Стадия, на которой осуществляется принятие стандарта
-
60
Стадия, на которой осуществляется публикация
-
90
Стадия пересмотра
-
95
Стадия, на которой осуществляется отмена стандарта
-
00