Short answer
ISO 31000 vs ISO 27005 is a matter of scope. ISO 31000:2018 gives general risk management guidelines for any risk in any organisation. ISO/IEC 27005:2022 applies that approach to information security risk, supporting the risk assessment and treatment required by ISO/IEC 27001. Neither is certifiable; ISO 27001 is the standard you certify against.
Key takeaways
- ISO 31000 covers all risk types; ISO 27005 covers information security risk only.
- ISO 27005:2022 follows the ISO 31000 process and maps it to ISO 27001 clauses 6.1 and 8.
- ISO 27005 adds event-based and asset-based approaches to risk identification.
- Use ISO 31000 for the enterprise method and ISO 27005 for the ISMS detail.
The short answer
| ISO 31000:2018 | ISO/IEC 27005:2022 | |
|---|---|---|
| Scope | Any risk: strategic, operational, financial, safety, information | Information security risk |
| Purpose | Principles, framework and process for managing risk | Guidance for the ISO 27001 risk assessment and treatment |
| Certifiable | No (guideline) | No (guidance); certify against ISO 27001 |
| Structure | Principles (4), framework (5), process (6) | Process aligned with ISO 31000, mapped to ISO 27001 |
| Risk identification | Sources, events, causes and consequences | Event-based and asset-based approaches |
| Typical owner | Chief risk officer, enterprise risk function | CISO, ISMS manager |
How ISO 27005 builds on ISO 31000
ISO/IEC 27005:2022, the fourth edition, uses the ISO 31000 process steps (context, assessment, treatment, monitoring, communication) and the same vocabulary, then applies them to information security. It also reorganised its content around the ISO/IEC 27001:2022 clauses, so each part of the guidance points to the requirement it supports, mainly clause 6.1.2 (risk assessment), 6.1.3 (risk treatment) and clauses 8.2 and 8.3 (performing them).
The 2022 edition describes two ways to identify risks. The event-based approach starts from strategic scenarios and risk sources, which suits high-level assessments. The asset-based approach starts from assets, threats and vulnerabilities, which suits detailed technical assessments. Many ISMS teams use event-based scenarios for the board and asset-based detail for system owners.
When to use which
If your organisation already runs enterprise risk management on ISO 31000, keep it as the method and use ISO 27005 to show how information security risks feed into it with the same criteria. If you only need an ISO 27001 risk assessment, ISO 27005 is enough on its own, and its alignment with ISO 31000 means the method will fit an enterprise process later.
Checklist
Running both without duplication
0 of 5 done
Put this into practice on QULDEX
Frequently asked questions
Is ISO 27005 required for ISO 27001 certification?
No. ISO 27001 requires a defined risk assessment and treatment process but does not mandate a method. ISO 27005 is guidance many organisations follow to meet that requirement.
Can ISO 31000 be used for an ISO 27001 risk assessment?
Yes. ISO 27001 clause 6.1 is consistent with ISO 31000, and an ISO 31000 process meets it if it covers confidentiality, integrity and availability risks and links treatments to Annex A controls.
What changed in ISO 27005:2022?
The 2022 edition aligned with ISO/IEC 27001:2022, reorganised guidance around its clauses, and introduced event-based and asset-based approaches to risk identification.