ISO/IEC 27005 is a guideline (not a certification standard) for managing information security risks. It describes how risks are systematically identified, analysed, evaluated, treated, monitored and communicated. The standard is tailored to an ISMS under ISO/IEC 27001 and is based on the general risk framework of ISO 31000. What makes it special: it gives you freedom of design when it comes to methods and scales. What matters is consistency and traceability.
Effective risk management is indispensable, particularly for companies subject to regulations such as NIS2 and DORA. This also applies to service providers and suppliers of companies that fall under NIS2.
What does risk management under ISO 27005 look like?
The standard deliberately leaves room for manoeuvre, but recommends a clear process in six steps. This makes the process easy to implement for organisations of any size.
1. Establish context and criteria
Before you assess risks, you set the ground rules. Essentially, these come down to five simple things:
- What are you looking at?
The "area" (scope): e.g. "email system, CRM, cloud provider, customer data". Everything else is out of scope for now. - What would hurt us?
Impact on three levels: low, medium, high.
Think about money, legal consequences, reputation and operational disruption (e.g. downtime). - How likely is it?
Likelihood on three levels: rare, occasional, frequent. - At what point do we act?
Your traffic-light rule (combination of impact × likelihood):- green = accept
- amber = monitor/minor measures
- red = action mandatory (with deadline and owner)
- Who decides and how often do we review?
Roles (e.g. owner, CISO/head of IT) and review cycle (e.g. quarterly or whenever changes occur).
2. Identify risks
What it's about: Create a list of plausible scenarios. "What could happen, caused by what, in which area, and what would the consequence be?" ISO 27005 proposes two approaches for this, which you can also combine:
- Event-based (top-down): Start from typical incidents (e.g. phishing, ransomware, misdirected emails).
- Asset-based (bottom-up): For important assets/processes, ask: "What can go wrong here?"
Use this simple template:
Source/threat actor → event → affected area/asset → possible consequence
Example: External attacker → password spraying → Microsoft 365 account → data theft and notification to the supervisory authority.
Free expertise in your e-mail inbox
All the important news on data protection, information security, AI and data strategy conveniently delivered to your e-mail inbox once a month - free of charge, of course. (Currently only available in German)
3. Analyse and evaluate
Analysis and evaluation can be broken down into two short questions:
A) How big is the risk?
For each scenario from step 2, you estimate:
- Impact (e.g. on confidentiality/integrity/availability, money, legal position, reputation)
- Likelihood (how often or how easily it happens within the chosen time horizon)
ISO 27005 does not prescribe a method. You can work qualitatively (low/medium/high), semi-quantitatively (1-to-5 scales) or quantitatively (e.g. expected loss). What matters is that you use consistent criteria from step 1 and take existing controls into account.
B) Is that good enough for us?
Now compare the risk level you have determined with your risk criteria from step 1 (acceptance thresholds, traffic-light rules). The result: accept, monitor or treat. More on this in the next step.
Example:
Taking the example from the previous step:
External attacker → password spraying → Microsoft 365 account → data theft and notification to the supervisory authority.
In this case, the evaluation could look like this:
- Impact: high (possible notification, fine, reputational damage)
- Likelihood: occasional
- Analysis result: high × occasional = the matrix shows red
- Evaluation: according to the criteria, "red" is not acceptable → treat (e.g. mandatory multi-factor authentication (MFA), anti-phishing training, mail filters) and reassess the residual risk after implementation.
4. Treatment and treatment plan
For each unacceptable risk, you choose one of four treatment options and implement it according to a plan, including controls, responsibilities and approvals. The options are:
- Avoid: eliminate the cause (e.g. stop using an insecure service).
- Modify/reduce: introduce or improve controls (e.g. MFA, hardening, training).
- Transfer/share: e.g. insurance, contractual liability of the service provider.
- Accept: formally agree, on record, that you will bear the residual risk.
Mini example:
- Option: modify
- Controls: mandatory MFA, phishing training, mail filter tuning, hardening of admin access
- Plan: IT rolls out MFA to 100% by 31 October, HR delivers training by 15 November, SecOps tests filters monthly
- KPI: click rate < 5%, compromised accounts = 0 per quarter
- Residual risk: target "low"; the risk owner (business unit) signs off
5. Monitor and improve
Check implementation progress and the effectiveness of controls using metrics. Respond to deviations with corrective actions and adjust assessments when the context changes.
Specifically, you monitor:
- Implementation progress of your measures/treatment plans (deadlines, owners, status).
- Effectiveness of controls (are the targets/KPIs being met?)
- Events and near misses (learn and fine-tune)
- Changes in context (technology, suppliers, legislation, threats): reassess risks where necessary.
This "monitoring and review" loop is part of ISO 27005 and builds on ISO 31000.
6. Communication and documentation
What it's about: Ensure transparent risk communication (management, business units, IT/SecOps, compliance) and audit-proof documentation.
Define what is communicated (risks, KPIs, incidents, changes), who should receive the information (management, IT, etc.), when it is communicated (ad hoc, monthly, annually) and how the information is shared (dashboards, reports, tickets, regular status meetings).
What are the benefits of risk management under ISO 27005?
- Tailored to ISO 27001: 27005 provides implementation guidance for the risk-based requirements, which makes audits and certification preparation easier.
- Proactive and prioritised: Relevant risks are identified early, assessed in a traceable way and treated with efficient use of resources.
- Flexible and scalable: The standard allows a free choice of method, from a 3×3 approach to quantitative methods, making it suitable for start-ups and large corporations alike.
- Transparency for stakeholders: Clean documentation and clear responsibilities build trust with management, customers and auditors.
- Continuous improvement: Monitoring and review are firmly embedded, so assessments and controls stay up to date.
- Compatible with enterprise risk management: Alignment with ISO 31000 makes it easier to connect to company-wide risk processes.
How ISiCO can support you in setting up risk management under ISO 27005
We support you holistically, from the initial assessment of where you stand to audit-proof operation:
- Quick check and gap analysis for ISO 27005/27001, including recommendations for action (also with regard to regulations such as NIS2 and DORA)
- Developing methodology and criteria
- Risk workshops and scenario catalogue
- Risk register and templates
- Analysis and prioritisation
- Treatment plans
- Training and awareness (business units, IT/SecOps, management)
- Supplier and third-party risk management
- Integration into the ISMS
- Support with management reviews and corrective actions
We are also happy to act as your external information security officer. Get in touch: we will be glad to develop a suitable approach for your organisation.
Information security that protects and thinks ahead
We don't just secure your systems; we also strengthen your structures. We provide well-thought-out IT security solutions that are tailored to your company and evolve alongside it.