ISO 31000 is the general standard for managing any kind of risk in any organization. ISO/IEC 27005 applies the same approach to one kind of risk: information security. ISO/IEC 27005 is built to support ISO/IEC 27001 and follows the risk management process that ISO 31000 describes.
The difference at a glance
| ISO 31000 | ISO/IEC 27005 | |
|---|---|---|
| Subject | Risk management in general | Information security risk management |
| Current edition | ISO 31000:2018 | ISO/IEC 27005:2022 |
| Applies to | Any risk: strategic, operational, financial, project, safety | Risks to the confidentiality, integrity and availability of information |
| Contains | Principles, a framework and a process | Guidance on running the risk process an ISMS needs |
| Linked standard | None; it stands on its own | ISO/IEC 27001 |
| Type | Guidance | Guidance |
| Typical users | Risk managers, executives, project and operations leads | Information security managers, ISMS implementers, security risk analysts |
What ISO 31000 says
ISO 31000 has three parts. The principles describe what good risk management looks like: integrated, structured, customized, inclusive, dynamic, based on the best available information, and aware of human and cultural factors. The framework covers how leadership sets up and supports risk management across the organization. The process is the working cycle: establish scope and context, identify risks, analyse them, evaluate them, treat them, and keep communicating, monitoring and recording throughout.
It does not tell you which risks matter or which controls to use. It is written to fit any organization and any type of risk.
What ISO/IEC 27005 adds
ISO/IEC 27005 takes that process and applies it to information security. It explains how to meet the risk requirements of ISO/IEC 27001: setting risk criteria, identifying risks, assessing likelihood and consequence, choosing treatment options, selecting controls and producing the records an auditor expects, such as the risk treatment plan.
The 2022 edition describes two ways to identify risk. The event-based approach starts from scenarios and their consequences for the business. The asset-based approach starts from assets, threats and vulnerabilities. You can use either or both.
How they work together
Many organizations use both. ISO 31000 sets the common language and the enterprise-level approach, so that information security risk is reported in the same terms as other business risks. ISO/IEC 27005 supplies the detail the security team needs. Because ISO/IEC 27005 follows the ISO 31000 process, the two fit without translation.
Which one to learn
- You manage risk across the organization: ISO 31000 Risk Manager or ISO 31000 Lead Risk Manager.
- You run or support an ISMS: ISO/IEC 27005 Risk Manager or ISO/IEC 27005 Lead Risk Manager.
- You are new to either: ISO 31000 Foundation or ISO/IEC 27005 Foundation.
- You implement ISO/IEC 27001: ISO/IEC 27005 pairs with ISO/IEC 27001 Lead Implementer.
These are personal certifications from PECB. You take the course, pass the exam and apply for the credential that matches your experience.
Sources: ISO 31000:2018, Risk management guidelines and ISO/IEC 27005:2022, Guidance on managing information security risks (ISO).
Frequently asked questions
Can an organization be certified to ISO 31000 or ISO/IEC 27005?
No. Both are guidance standards. They contain recommendations, not requirements, so there is no organizational certification for either. An organization is certified to ISO/IEC 27001, and ISO/IEC 27005 helps it meet the risk requirements of that standard.
Do I need ISO/IEC 27005 to comply with ISO/IEC 27001?
No. ISO/IEC 27001 requires an information security risk assessment and treatment process but does not prescribe a method. ISO/IEC 27005 is one well-recognized way to do it.
Which course should I take, ISO 31000 or ISO/IEC 27005?
Take ISO 31000 if you manage risk across an organization, such as enterprise, operational or project risk. Take ISO/IEC 27005 if your work is information security risk, especially inside an ISO/IEC 27001 management system.