ISO 27005:2022
Leveraging related ISMS processes – ISO 27005:2022

ISO 27005:2022 10.3: Communication and consultation

Input: what the risk processes found about risks, why they arise, what they would do and how likely they are. Action: communicate information on risks and the controls treating them to, or gather it from, internal and external interested parties. Trigger: 27001 requires such communication (7.4 covers its communication part). Output: interested parties' perceptions and continuing understanding of the process and results. The aim is agreement on managing risks through exchanging information with risk owners and others, covering whether risks exist and their nature, form, likelihood, consequences, significance, treatment and acceptance. Ownership can be deliberately blurred and owners reluctant, so a defined procedure informs people of their ownership; owners approve plans and accept residual risk, so two-way communication between them and ISMS staff matters. Sensitive risk information is shared on a need-to-know basis in consultation with owners, avoiding publicity for sensitive risks and weaknesses. Perceptions differ with assumptions, needs and concerns, so they, and perceived benefits, are identified, documented and understood; involving parties in developing criteria and methods builds ownership and acceptance of findings, and commitment where they are managers. Communication aims to assure outcomes, collect risk information, share results and plans, reduce breaches arising from misunderstanding, support owners, gain new knowledge, coordinate responses to limit incident consequences, give owners and legitimately interested parties a sense of responsibility, and raise awareness. Plans cover normal operations and emergencies, the activity runs continually, a committee can coordinate major owners, communications may go voluntarily or by requirement to third parties such as regulators or partners, and the public relations or communications unit is involved, crucially in crisis communication.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 36 controls across 29 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 23894:2023 · 3 controls

  • 23894-5.5 Communication and Consultation
  • ISO23894-6.1 Communication and Consultation
  • 6.2 Communication and consultation
  • ISO-37002-7.4 Communication
  • ISO37002-7.4 Communication
  • ISO-41001-7.4 Communication
  • ISO41001-7.4 Communication
  • ISO-50001-7.4 Communication
  • 7.4 Communication

ISO/IEC 27003:2017 · 2 controls

AICPA SOC 3 · 1 control

  • SOC3-COMMS Communication
  • BS65000-7.4 Communication

DORA · 1 control

ISO 13485:2016 · 1 control

ISO 14001:2015 · 1 control

  • 7.4 Communication

ISO 14004:2016 · 1 control

  • 7.4 Communication

ISO 22000:2018 · 1 control

  • 7.4 Communication

ISO 22301:2019 · 1 control

  • 7.4 Communication

ISO 27701:2019 · 1 control

  • ISO28001-4.8 Communication and consultation

ISO 30401 · 1 control

  • ISO30401-7.4 Communication

ISO 31000:2018 · 1 control

  • 6.2 Communication and consultation

ISO 37001:2016 · 1 control

  • 7.4 7.4 Communication

ISO 37301:2021 · 1 control

  • 7.4 Communication
  • ISO-39001-7.4 Communication

ISO 45001:2018 · 1 control

  • 7.4 Communication

ISO 55001:2014 · 1 control

  • 7.4 Communication

ISO 56002 · 1 control

  • ISO-56002-7.4 Communication

ISO 9001:2015 · 1 control

  • 7.4 Communication
  • 27557-6.1 Communication and consultation

ISO/IEC 42001:2023 · 1 control

  • 7.4 Communication

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Leveraging related ISMS processes – ISO 27005:2022

Query this from an agent

The graph holds this control, the 36 it maps to, and the evidence behind each claim, over MCP and REST.