Risk & remediation

ISO 31000 vs ISO 27005: what each covers and how they fit together

ISO 31000 is the general risk management guideline; ISO/IEC 27005 applies it to information security for ISO 27001. Here is where they differ and how to use them together.

Expert reviewedChecked against ISO 31000:2018 Risk management — Guidelines · by Aishwarya ·

Short answer

ISO 31000 vs ISO 27005 is a matter of scope. ISO 31000:2018 gives general risk management guidelines for any risk in any organisation. ISO/IEC 27005:2022 applies that approach to information security risk, supporting the risk assessment and treatment required by ISO/IEC 27001. Neither is certifiable; ISO 27001 is the standard you certify against.

Key takeaways

  • ISO 31000 covers all risk types; ISO 27005 covers information security risk only.
  • ISO 27005:2022 follows the ISO 31000 process and maps it to ISO 27001 clauses 6.1 and 8.
  • ISO 27005 adds event-based and asset-based approaches to risk identification.
  • Use ISO 31000 for the enterprise method and ISO 27005 for the ISMS detail.

The short answer

ISO 31000:2018ISO/IEC 27005:2022
ScopeAny risk: strategic, operational, financial, safety, informationInformation security risk
PurposePrinciples, framework and process for managing riskGuidance for the ISO 27001 risk assessment and treatment
CertifiableNo (guideline)No (guidance); certify against ISO 27001
StructurePrinciples (4), framework (5), process (6)Process aligned with ISO 31000, mapped to ISO 27001
Risk identificationSources, events, causes and consequencesEvent-based and asset-based approaches
Typical ownerChief risk officer, enterprise risk functionCISO, ISMS manager

How ISO 27005 builds on ISO 31000

ISO/IEC 27005:2022, the fourth edition, uses the ISO 31000 process steps (context, assessment, treatment, monitoring, communication) and the same vocabulary, then applies them to information security. It also reorganised its content around the ISO/IEC 27001:2022 clauses, so each part of the guidance points to the requirement it supports, mainly clause 6.1.2 (risk assessment), 6.1.3 (risk treatment) and clauses 8.2 and 8.3 (performing them).

The 2022 edition describes two ways to identify risks. The event-based approach starts from strategic scenarios and risk sources, which suits high-level assessments. The asset-based approach starts from assets, threats and vulnerabilities, which suits detailed technical assessments. Many ISMS teams use event-based scenarios for the board and asset-based detail for system owners.

When to use which

If your organisation already runs enterprise risk management on ISO 31000, keep it as the method and use ISO 27005 to show how information security risks feed into it with the same criteria. If you only need an ISO 27001 risk assessment, ISO 27005 is enough on its own, and its alignment with ISO 31000 means the method will fit an enterprise process later.

Checklist

Running both without duplication

0 of 5 done

Put this into practice on QULDEX

Frequently asked questions

Is ISO 27005 required for ISO 27001 certification?

No. ISO 27001 requires a defined risk assessment and treatment process but does not mandate a method. ISO 27005 is guidance many organisations follow to meet that requirement.

Can ISO 31000 be used for an ISO 27001 risk assessment?

Yes. ISO 27001 clause 6.1 is consistent with ISO 31000, and an ISO 31000 process meets it if it covers confidentiality, integrity and availability risks and links treatments to Annex A controls.

What changed in ISO 27005:2022?

The 2022 edition aligned with ISO/IEC 27001:2022, reorganised guidance around its clauses, and introduced event-based and asset-based approaches to risk identification.

Sources

  1. ISO 31000:2018 Risk management — Guidelines, ISO
  2. ISO/IEC 27005:2022 Guidance on managing information security risks, ISO
  3. ISO/IEC 27001:2022 Information security management systems, ISO