ISO 27005:2022
Information security risk management – ISO 27005:2022

ISO 27005:2022 5.2: Information security risk management cycles

Assessment and treatment are refreshed regularly and whenever things change, organised in two cycles. The strategic cycle responds to shifts in the organisation's overall context (its business assets, the threats and sources of risk it faces, the objectives it targets, and what security events would cost it) and can prompt a broad update of assessments and treatments or wholly new assessments; it runs over longer intervals or on major change. The operational cycle uses those elements, or changed criteria, to review and update the scenarios of individual assessments together with their treatment, over shorter intervals set by the detailed risks involved. The strategic cycle concerns the environment in which objectives are pursued, the operational cycle every assessment within the risk management context, and either can contain many assessments with differing context and scope.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 3 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 29100:2024 · 2 controls

  • 29100-6.10 Information security
  • ISO29100-5.10.10 Information Security
  • IS.I.OR.220 Information Security Risk Management

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Information security risk management – ISO 27005:2022

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.