Contact Deutsch

ISiCO GmbH
Skip navigation
  • Privacy

    Get a head start with our optimal data protection consultancy

    Secure your competitive advantage with our business-focused data protection expertise.

    • Data Protection Consulting
      • Data Protection Impact Assessment (DPIA)
      • Threat Modelling
      • Data Breaches
      • Records of Processing Activities (ROPA)
      • Communication & Procedures with Authorities
      • Employee Data Protection
      • Data Protection Management System
      • Erasure and Archiving Policies
    • External Data Protection Officer
    • Data Protection Audits
    • EU Representative
    • Whistleblower Protection Act
  • IT Security

    Reliable protection for your company

    Make use of our expertise and customised IT security solutions to protect your digital assets.

    • External Information Security Officer (ISO)
    • ISMS
      • ISMS Service Package
      • ISMS Service Package NIS2
      • ISMS Service Package ISO 27001
      • ISMS Service Package TISAX
    • ISO 27001 Certification
    • Ransomware Protection
    • Risk Management
    • IT Compliance
    • NIS2
    • DORA
    • TISAX Certification
    • IT Forensics
    • Cyber Resilience Act
    • Aerospace & Defense
  • AI Consulting

    Gain a competitive edge with the best AI advice

    Secure your competitive advantage with our business-focused AI expertise.

    • ISO 42001 Certification
    • External AI Officer
  • Data Strategy

    Make the most of your data

    We will show you how to unlock the full potential of your company's data.

    • Develop Data Strategy
    • Maturity Assessment
    • Data Governance
    • Data Product
  • Solutions

    We create solutions for all challenges

    Whether you need advice on data protection management, its implementation, or employee training, we can provide the solution you need as part of a corporate network.

    • Downloads
    • Workshops
    • DPO Coaching
    • Privacy Solution Software caralegal
    • E-Learning from lawpilots
  • Company

    Customised, efficient and business-oriented

    ISiCO is one of the top addresses in Germany for management consultancy in data protection, information security, AI and data strategies.

    • About ISiCO
    • Team
    • Offices
    • News
    • Contact
  • Make an appointment

07.10.2026

Implementing risk management under ISO 27005 in 6 steps

Risk management is at the heart of an effective information security management system (ISMS). ISO/IEC 27005 provides a practical guide for this: flexible, scalable and directly compatible with ISO/IEC 27001. In this article, we show you how to take a structured approach and what benefits this brings to your organisation.

Schedule a no-obligation initial consultation now
Your ISiCO-Expert:
Dr Jan Scharfenberg
Partner Information Security, Managing Director

What is ISO 27005?

ISO/IEC 27005 is a guideline (not a certification standard) for managing information security risks. It describes how risks are systematically identified, analysed, evaluated, treated, monitored and communicated. The standard is tailored to an ISMS under ISO/IEC 27001 and is based on the general risk framework of ISO 31000. What makes it special: it gives you freedom of design when it comes to methods and scales. What matters is consistency and traceability.

Effective risk management is indispensable, particularly for companies subject to regulations such as NIS2 and DORA. This also applies to service providers and suppliers of companies that fall under NIS2.

What does risk management under ISO 27005 look like?

The standard deliberately leaves room for manoeuvre, but recommends a clear process in six steps. This makes the process easy to implement for organisations of any size.

1. Establish context and criteria

Before you assess risks, you set the ground rules. Essentially, these come down to five simple things:

  1. What are you looking at?
    The "area" (scope): e.g. "email system, CRM, cloud provider, customer data". Everything else is out of scope for now.
  2. What would hurt us?
    Impact on three levels: low, medium, high.
    Think about money, legal consequences, reputation and operational disruption (e.g. downtime).
  3. How likely is it?
    Likelihood on three levels: rare, occasional, frequent.
  4. At what point do we act?
    Your traffic-light rule (combination of impact × likelihood):
    • green = accept
    • amber = monitor/minor measures
    • red = action mandatory (with deadline and owner)
  5. Who decides and how often do we review?
    Roles (e.g. owner, CISO/head of IT) and review cycle (e.g. quarterly or whenever changes occur).

2. Identify risks

What it's about: Create a list of plausible scenarios. "What could happen, caused by what, in which area, and what would the consequence be?" ISO 27005 proposes two approaches for this, which you can also combine:

  • Event-based (top-down): Start from typical incidents (e.g. phishing, ransomware, misdirected emails).
  • Asset-based (bottom-up): For important assets/processes, ask: "What can go wrong here?"

Use this simple template:

Source/threat actor → event → affected area/asset → possible consequence

Example: External attacker → password spraying → Microsoft 365 account → data theft and notification to the supervisory authority.

Free expertise in your e-mail inbox

All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)

Please calculate 2 plus 6.

By clicking on the button, you consent to receiving our newsletter and to the aggregated usage analysis (opening rate and link clicks). You can revoke your consent at any time, e.g. via the unsubscribe link in the newsletter. More information: Privacy policy.

3. Analyse and evaluate

Analysis and evaluation can be broken down into two short questions:

A) How big is the risk?

For each scenario from step 2, you estimate:

  • Impact (e.g. on confidentiality/integrity/availability, money, legal position, reputation)
  • Likelihood (how often or how easily it happens within the chosen time horizon)

ISO 27005 does not prescribe a method. You can work qualitatively (low/medium/high), semi-quantitatively (1-to-5 scales) or quantitatively (e.g. expected loss). What matters is that you use consistent criteria from step 1 and take existing controls into account.

B) Is that good enough for us?

Now compare the risk level you have determined with your risk criteria from step 1 (acceptance thresholds, traffic-light rules). The result: accept, monitor or treat. More on this in the next step.

Example:

Taking the example from the previous step:

External attacker → password spraying → Microsoft 365 account → data theft and notification to the supervisory authority.

In this case, the evaluation could look like this:

  1. Impact: high (possible notification, fine, reputational damage)
  2. Likelihood: occasional
  3. Analysis result: high × occasional = the matrix shows red
  4. Evaluation: according to the criteria, "red" is not acceptable → treat (e.g. mandatory multi-factor authentication (MFA), anti-phishing training, mail filters) and reassess the residual risk after implementation.

4. Treatment and treatment plan

For each unacceptable risk, you choose one of four treatment options and implement it according to a plan, including controls, responsibilities and approvals. The options are:

  1. Avoid: eliminate the cause (e.g. stop using an insecure service).
  2. Modify/reduce: introduce or improve controls (e.g. MFA, hardening, training).
  3. Transfer/share: e.g. insurance, contractual liability of the service provider.
  4. Accept: formally agree, on record, that you will bear the residual risk.

Mini example:

  1. Option: modify
  2. Controls: mandatory MFA, phishing training, mail filter tuning, hardening of admin access
  3. Plan: IT rolls out MFA to 100% by 31 October, HR delivers training by 15 November, SecOps tests filters monthly
  4. KPI: click rate < 5%, compromised accounts = 0 per quarter
  5. Residual risk: target "low"; the risk owner (business unit) signs off

5. Monitor and improve

Check implementation progress and the effectiveness of controls using metrics. Respond to deviations with corrective actions and adjust assessments when the context changes.

Specifically, you monitor:

  • Implementation progress of your measures/treatment plans (deadlines, owners, status).
  • Effectiveness of controls (are the targets/KPIs being met?)
  • Events and near misses (learn and fine-tune)
  • Changes in context (technology, suppliers, legislation, threats): reassess risks where necessary.

This "monitoring and review" loop is part of ISO 27005 and builds on ISO 31000.

6. Communication and documentation

What it's about: Ensure transparent risk communication (management, business units, IT/SecOps, compliance) and audit-proof documentation.

Define what is communicated (risks, KPIs, incidents, changes), who should receive the information (management, IT, etc.), when it is communicated (ad hoc, monthly, annually) and how the information is shared (dashboards, reports, tickets, regular status meetings).

What are the benefits of risk management under ISO 27005?

  • Tailored to ISO 27001: 27005 provides implementation guidance for the risk-based requirements, which makes audits and certification preparation easier.
  • Proactive and prioritised: Relevant risks are identified early, assessed in a traceable way and treated with efficient use of resources.
  • Flexible and scalable: The standard allows a free choice of method, from a 3×3 approach to quantitative methods, making it suitable for start-ups and large corporations alike.
  • Transparency for stakeholders: Clean documentation and clear responsibilities build trust with management, customers and auditors.
  • Continuous improvement: Monitoring and review are firmly embedded, so assessments and controls stay up to date.
  • Compatible with enterprise risk management: Alignment with ISO 31000 makes it easier to connect to company-wide risk processes.

How ISiCO can support you in setting up risk management under ISO 27005

We support you holistically, from the initial assessment of where you stand to audit-proof operation:

  • Quick check and gap analysis for ISO 27005/27001, including recommendations for action (also with regard to regulations such as NIS2 and DORA)
  • Developing methodology and criteria
  • Risk workshops and scenario catalogue
  • Risk register and templates
  • Analysis and prioritisation
  • Treatment plans
  • Training and awareness (business units, IT/SecOps, management)
  • Supplier and third-party risk management
  • Integration into the ISMS
  • Support with management reviews and corrective actions

We are also happy to act as your external information security officer. Get in touch: we will be glad to develop a suitable approach for your organisation.

Information security that protects and thinks ahead

We don't just secure your systems; we also strengthen your structures. We provide well-thought-out IT security solutions that are tailored to your company and evolve alongside it.

Book your appointment now

Back to the news overview

Berlin
Köln
München

Ready for the next step?

+49 30 21300285-0
info@isico.de

Directly to get to know us

 

Outstanding work

ISiCO is also an active member of the German Association for Data Protection and Data Security (GDD) and the German Association for Information Technology, Telecommunications and New Media (Bitkom).

Top-Links
Skip navigation
  • External Data Protection Officer
  • Data Protection Management System
  • Data Strategy
  • Data Breaches
  • ISMS
Find out more
Skip navigation
  • About ISiCO
  • Contact

Language

DE EN

© ISiCO GmbH | Contact | Imprint | Privacy | Privacy Settings