ISO 27005:2022
Information security risk management – ISO 27005:2022

ISO 27005:2022 5.1: Information security risk management process

The process of Figure 1 follows the generic ISO 31000 model and can loop through assessment and treatment. Each pass of the assessment can go deeper, which balances the effort of finding controls against assessing risks properly. Context establishment gathers the internal and external context for the risk management or for a given assessment. At the first decision point, if the assessment yields enough to settle how risks can be brought within acceptable bounds, the organisation moves on to treatment; if not it runs another pass, perhaps with a changed scope, more specialist input or other ways of getting the missing information. Treatment itself loops: formulate and choose options, plan and implement, check how effective the treatment was, decide whether what remains is acceptable, and treat further if it is not. If residual risk is still unacceptable (the second decision point), the organisation looks for more treatment or reassesses in whole or part, using what it has learned about threats and vulnerabilities. Clauses 6, 7, 8 and 10 cover context, assessment, treatment and the supporting ISMS activities.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 5 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • IS.D.OR.220 Information Security Risk Management Process
  • IS.I.OR.220 Information Security Risk Management

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Information security risk management – ISO 27005:2022

Query this from an agent

The graph holds this control, the 5 it maps to, and the evidence behind each claim, over MCP and REST.