Back to Frameworks

ISO 27005:2022

International
v2022
7 domains
45 controls
Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

Context establishment – ISO 27005:2022

8 controls
Controls in the Context establishment – ISO 27005:2022 domain of ISO 27005:20228 controls
CodeTitle
iso-27005-2022::6.1Organizational considerations
iso-27005-2022::6.2Identifying basic requirements of interested parties
iso-27005-2022::6.3Applying risk assessment
iso-27005-2022::6.4Establishing and maintaining information security risk criteria
iso-27005-2022::6.4.1General
iso-27005-2022::6.4.2Risk acceptance criteria
iso-27005-2022::6.4.3Criteria for performing information security risk assessments
iso-27005-2022::6.5Choosing an appropriate method

Information security risk assessment process – ISO 27005:2022

11 controls
Controls in the Information security risk assessment process – ISO 27005:2022 domain of ISO 27005:202211 controls
CodeTitle
iso-27005-2022::7.1General
iso-27005-2022::7.2Identifying information security risks
iso-27005-2022::7.2.2Identifying risk owners
iso-27005-2022::7.3Analysing information security risks
iso-27005-2022::7.3.1General
iso-27005-2022::7.3.2Assessing potential consequences
iso-27005-2022::7.3.3Assessing likelihood
iso-27005-2022::7.3.4Determining the levels of risk
iso-27005-2022::7.4Evaluating the information security risks
iso-27005-2022::7.4.1Comparing the results of risk analysis with the risk criteria
iso-27005-2022::7.4.2Prioritizing the analysed risks for risk treatment

Information security risk management – ISO 27005:2022

2 controls
Controls in the Information security risk management – ISO 27005:2022 domain of ISO 27005:20222 controls
CodeTitle
iso-27005-2022::5.1Information security risk management process
iso-27005-2022::5.2Information security risk management cycles

Information security risk treatment process – ISO 27005:2022

7 controls
Controls in the Information security risk treatment process – ISO 27005:2022 domain of ISO 27005:20227 controls
CodeTitle
iso-27005-2022::8.1General
iso-27005-2022::8.2Selecting appropriate information security risk treatment options
iso-27005-2022::8.5Producing a Statement of Applicability
iso-27005-2022::8.6Information security risk treatment plan
iso-27005-2022::8.6.1Formulation of the risk treatment plan
iso-27005-2022::8.6.2Approval by risk owners
iso-27005-2022::8.6.3Acceptance of the residual information security risks

Leveraging related ISMS processes – ISO 27005:2022

13 controls
Controls in the Leveraging related ISMS processes – ISO 27005:2022 domain of ISO 27005:202213 controls
CodeTitle
iso-27005-2022::10.1Context of the organization
iso-27005-2022::10.2Leadership and commitment
iso-27005-2022::10.3Communication and consultation
iso-27005-2022::10.4Documented information
iso-27005-2022::10.4.1General
iso-27005-2022::10.4.2Documented information about processes
iso-27005-2022::10.4.3Documented information about results
iso-27005-2022::10.5Monitoring and review
iso-27005-2022::10.5.1General
iso-27005-2022::10.5.2Monitoring and reviewing factors influencing risks
iso-27005-2022::10.6Management review
iso-27005-2022::10.7Corrective action
iso-27005-2022::10.8Continual improvement

Operation – ISO 27005:2022

2 controls
Controls in the Operation – ISO 27005:2022 domain of ISO 27005:20222 controls
CodeTitle
iso-27005-2022::9.1Performing information security risk assessment process
iso-27005-2022::9.2Performing information security risk treatment process

Terms and definitions – ISO 27005:2022

2 controls
Controls in the Terms and definitions – ISO 27005:2022 domain of ISO 27005:20222 controls
CodeTitle
iso-27005-2022::3.1Terms related to information security risk
iso-27005-2022::3.2Terms related to information security risk management

Your Compliance Coverage

If you comply with ISO 27005:2022, you already cover:

Maps to 60 other frameworks

45 total controls
ISO 14004:2016
13 source controls mapped|6 target controls covered
29%
ISO 31000:2018
10 source controls mapped|5 target controls covered
22%
ISO 13485:2016
9 source controls mapped|4 target controls covered
20%
ISO 27701:2019
9 source controls mapped|7 target controls covered
20%
ISO 19011:2018
8 source controls mapped|11 target controls covered
18%
ISO/IEC 27003:2017
8 source controls mapped|16 target controls covered
18%
AS9100D - Aerospace Quality Management System
8 source controls mapped|10 target controls covered
18%
ISO 55001:2014
7 source controls mapped|5 target controls covered
16%
ISO 45001:2018
7 source controls mapped|5 target controls covered
16%
ISO 14001:2015
7 source controls mapped|5 target controls covered
16%
ISO 9001:2015
7 source controls mapped|7 target controls covered
16%
ISO/IEC 42001:2023
7 source controls mapped|5 target controls covered
16%
ISO 22301:2019
7 source controls mapped|5 target controls covered
16%
ISO 22000:2018
7 source controls mapped|7 target controls covered
16%
ISO 50001:2018 - Energy Management Systems
7 source controls mapped|7 target controls covered
16%
ISO 37001:2016
7 source controls mapped|5 target controls covered
16%
ISO 37301:2021
7 source controls mapped|7 target controls covered
16%
ISO 39001:2012 - Road Traffic Safety Management
7 source controls mapped|34 target controls covered
16%
ISO 56002
7 source controls mapped|34 target controls covered
16%
ISO 41001:2018 - Facility Management Systems
7 source controls mapped|35 target controls covered
16%
ISO 37002:2021 - Whistleblowing Management Systems
7 source controls mapped|35 target controls covered
16%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
7 source controls mapped|30 target controls covered
16%
ISO 22000
7 source controls mapped|5 target controls covered
16%
ISO 30401
7 source controls mapped|5 target controls covered
16%
ISO 37301
7 source controls mapped|5 target controls covered
16%
ISO/IEC TR 24028:2020
6 source controls mapped|1 target controls covered
13%
ISO 9001
6 source controls mapped|4 target controls covered
13%
ISO 55001
6 source controls mapped|4 target controls covered
13%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
5 source controls mapped|5 target controls covered
11%
ISO/IEC 38500:2024
4 source controls mapped|3 target controls covered
9%
ISO/IEC 23894:2023
4 source controls mapped|10 target controls covered
9%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
4 source controls mapped|4 target controls covered
9%
ISO 45001
4 source controls mapped|4 target controls covered
9%
BS 65000:2014 - Guidance on Organizational Resilience
4 source controls mapped|4 target controls covered
9%
ISO/IEC 29100:2024
3 source controls mapped|2 target controls covered
7%
EASA Part-IS - Information Security in Aviation
3 source controls mapped|5 target controls covered
7%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
3 source controls mapped|1 target controls covered
7%
ISO 27018
3 source controls mapped|1 target controls covered
7%
ISO/IEC 27018:2019
3 source controls mapped|1 target controls covered
7%
ISO 31000
3 source controls mapped|3 target controls covered
7%
ISO 10007:2017
3 source controls mapped|1 target controls covered
7%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
2 source controls mapped|2 target controls covered
4%
ISO 28001:2007 Supply Chain Security Management
2 source controls mapped|2 target controls covered
4%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|2 target controls covered
4%
ISO/IEC 27031:2011
2 source controls mapped|2 target controls covered
4%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|1 target controls covered
2%
DORA
1 source controls mapped|1 target controls covered
2%
Authorised Economic Operator (AEO) Programmes - Global Standards
1 source controls mapped|1 target controls covered
2%
AICPA SOC 3
1 source controls mapped|1 target controls covered
2%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
1 source controls mapped|1 target controls covered
2%
ISO 10006:2003
1 source controls mapped|1 target controls covered
2%
ISO 22320:2018
1 source controls mapped|1 target controls covered
2%
ITIL 4
1 source controls mapped|1 target controls covered
2%
ISO/IEC 27701:2019
1 source controls mapped|1 target controls covered
2%
ISO 27001:2022
1 source controls mapped|2 target controls covered
2%
ISO 37001
1 source controls mapped|1 target controls covered
2%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
2%
Australia NHMRC National Statement on Ethical Conduct in Human Research
1 source controls mapped|1 target controls covered
2%
BIMCO Cyber Security
1 source controls mapped|1 target controls covered
2%

Frequently Asked Questions

What is ISO 27005:2022?

ISO 27005:2022 is a compliance framework from International with 7 domains and 45 controls. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ISO 27005:2022 have?

ISO 27005:2022 has 45 controls organised across 7 domains. The largest domains are Leveraging related ISMS processes – ISO 27005:2022 (13 controls), Information security risk assessment process – ISO 27005:2022 (11 controls), Context establishment – ISO 27005:2022 (8 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ISO 27005:2022 map to?

ISO 27005:2022 maps to 60 other compliance frameworks. The top mapping partners are ISO 14004:2016 (29% coverage), ISO 31000:2018 (22% coverage), ISO 13485:2016 (20% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ISO 27005:2022 compliance?

Start your ISO 27005:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 27005:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required