📥 Free download · The heart of every ISMS

Your ISO 27005 risk assessment step by step, ready for the audit.

Download the free guide ↓

A complete practical guide (22 pages) written by a consultant and certified trainer: the full risk management process, with example scales, a 5x5 matrix, a filled risk register, a practical case and the mistakes auditors find again and again.

  • The full process: context, identification, analysis, evaluation and treatment
  • A 5x5 matrix template and a risk register with a filled example
  • The most frequent audit mistakes (and how to avoid them)

Download it free

We send it instantly. No spam, only useful content on risk and compliance.

📩 You'll receive the download link instantly.

Who is this guide for?

Designed for those whose next risk assessment must stand up to an audit.

📊Risk owners and analystsWho want to structure the process with defensible scales and criteria.
🧑‍💻ISO 27001 implementers and auditorsWho need the hinge between clause 6.1, the SoA and the treatment plan.
🎓Future certificate holdersPreparing the official PECB ISO/IEC 27005 Risk Manager certification.

And if you want to measure yourself before deciding, the sample of our practice exam for ISO/IEC 27005 Risk Manager is free and asks for no sign-up.

What ISO/IEC 27005 actually is

ISO/IEC 27005 is the international standard that gives guidelines for information security risk management. It does not replace ISO/IEC 27001: it explains how to carry out the risk assessment and risk treatment that Clause 6.1 of ISO/IEC 27001 requires. In practice, ISO/IEC 27001 tells you that you must manage information security risk, and ISO/IEC 27005 shows you a defensible way to do it. The 2022 edition aligns its vocabulary with ISO/IEC 27001:2022 and with the general risk management principles of ISO 31000, so the terms below are the ones an auditor will expect to hear.

The ISO 27005 risk management process, step by step

The process is a cycle, not a one-off exercise. These are the stages, in the order you should run them.

1. Establish the context

Before you assess anything, you set the rules of the exercise: the scope, the internal and external issues, the people involved, and above all the risk criteria. Risk criteria are the yardstick you will use to decide how big a risk is and, crucially, which risks you are willing to accept. Defining acceptance criteria at the end, once you already know the results, is the single most common way to bias an assessment. Decide them first, in writing.

2. Identify the risks

ISO/IEC 27005:2022 allows two complementary approaches. The asset-based approach starts from what you are protecting (information, systems, processes) and asks what threats and vulnerabilities apply to each. The event-based approach starts from the scenarios you fear (a ransomware outbreak, a supplier breach, a lost laptop) and works back to the assets they would affect. Most mature programmes combine the two. The output of this step is a list of risk scenarios, each expressed as a threat exploiting a vulnerability with a consequence.

3. Analyse the risks

For every scenario you estimate two things: the likelihood that it happens and the consequence if it does. You can do this qualitatively (a scale such as 1 to 5) or quantitatively (in money or time). The combination gives you a level of risk. Keep the scale you choose written down and applied the same way to every scenario, or the results will not be comparable.

4. Evaluate the risks

Now you compare each risk level against the criteria you set in step 1 and put the risks in order of priority. Evaluation is where you decide what needs treatment and what is already inside your appetite. This is a decision step, not a calculation step, and it belongs to the risk owners, not to whoever ran the spreadsheet.

5. Treat the risks

For each risk that exceeds your criteria you choose one of four options: modify it by adding or strengthening controls (the controls of ISO/IEC 27002 and Annex A of ISO/IEC 27001 are the usual catalogue), retain it knowingly because it is within appetite, avoid the activity that creates it, or share it, for example through insurance or a contract. The result is a risk treatment plan, and the controls you decide to apply are what populate your Statement of Applicability.

6. Accept, monitor and communicate

Whatever risk remains after treatment is the residual risk, and it must be accepted explicitly by the risk owner, not left implicit. From there the cycle continues: monitor whether likelihoods and consequences are changing, review the assessment on a defined schedule and after any significant change, and communicate the results to the people who make decisions. An assessment that is done once and filed is an assessment that is already out of date.

The 5x5 risk matrix

The 5x5 matrix is the most common way to turn likelihood and consequence into a single risk level. Read it by finding the row for likelihood and the column for consequence: the cell where they meet is the risk level.

Likelihood (rows) against Consequence (columns). Cell = risk level.
 1 Negligible2 Minor3 Moderate4 Major5 Severe
5 Almost certainMediumHighHighCriticalCritical
4 LikelyMediumMediumHighHighCritical
3 PossibleLowMediumMediumHighHigh
2 UnlikelyLowLowMediumMediumHigh
1 RareLowLowLowMediumMedium

The labels matter less than the discipline behind them. Two rules keep a matrix honest. First, define what each number means before you score, so that "3 Moderate" is the same thing for every scenario and every assessor. Second, decide in advance which levels you will accept (for example, Low is accepted, Medium is monitored, High and Critical require treatment) so that the matrix drives decisions instead of just colouring them.

A worked risk register

A risk register is where the process becomes a working document. It does not need special software: a well-structured spreadsheet is enough, and it is how we recommend you start. Below are two rows filled in the way an assessor would keep them.

IDAsset / processRisk scenarioVulnerabilityExisting controlsL (1-5)C (1-5)LevelTreatmentOwnerTarget
R-01Customer database (CRM)Ransomware encrypts production dataBackups are taken but restores are never testedDaily backup, endpoint detection35HighModify: quarterly restore tests, one offline copyHead of IT2026-Q4
R-02Employee laptopsA stolen laptop exposes personal dataDisk encryption not enforced on every deviceDevice enrolment in MDM24MediumModify: enforce full-disk encryption via MDMCISO2026-11-30

Notice what each row makes explicit: a named owner, a treatment option (not just a comment), and a target date. Those three columns are what turn a list of worries into something an auditor accepts as evidence.

The mistakes auditors find again and again

  • Acceptance criteria decided too late. If you only decide what is acceptable after you have seen the scores, the criteria bend to fit the answer you wanted.
  • A method that is not repeatable. No written scales means two assessors produce two different numbers for the same risk, and next year's assessment cannot be compared with this one.
  • No risk owners. If no one is named, no one accepts the residual risk, and acceptance is a requirement, not a courtesy.
  • The Statement of Applicability does not match the treatment plan. Controls marked applicable that appear nowhere in the plan, or planned controls missing from the SoA, are among the most frequent nonconformities.
  • Residual risk never formally accepted. Treatment is planned, but the risk that remains afterwards is never evaluated again or signed off.
  • Assessed once, never reviewed. A register with a single date on it, months after the last major change, tells an auditor the process is not alive.
  • Generic risks copied from a template. A register that could belong to any organisation belongs to none. The scenarios have to reflect your real context.

Where certification fits

Running this process well is a skill, and there are recognised certifications for it. The ISO/IEC 27005 Foundation covers the concepts and vocabulary. The ISO/IEC 27005 Risk Manager certification validates that you can run the full assessment and treatment process, and the ISO/IEC 27005 Lead Risk Manager is for those who lead the risk management programme. Every course is available in Self-Study and in Self-Study with individual coaching. If your context is French public sector or an ANSSI requirement, the EBIOS Risk Manager method is the usual choice, and our EBIOS RM guide explains when to prefer it over ISO/IEC 27005. The risk learning path shows the full sequence.

Frequently asked questions

What is the difference between ISO 27005 and ISO 27001?

ISO/IEC 27001 is the certifiable standard for an information security management system, and it requires you to assess and treat risk. ISO/IEC 27005 is the guidance that tells you how to do that assessment and treatment. You certify against 27001; you follow 27005 to get there.

ISO 27005 or ISO 31000: which one do I use?

ISO 31000 is the general framework for risk management across any discipline. ISO/IEC 27005 applies those same principles specifically to information security and connects them to ISO/IEC 27001. If your subject is information security, 27005 is the one that speaks your language.

Do I need software to apply ISO 27005?

No. Neither ISO/IEC 27005 nor any auditor prescribes a tool. A structured spreadsheet is enough for a complete assessment, and it is the right way to begin. Dedicated software becomes useful once you maintain many assessments over time, not for your first one.

Is the risk register template really free?

Yes, without any condition and without a card. The whole process above is on this page to read. The form only adds the option of the laid-out PDF version with the template inside.

Which certification should I start with?

If you are new to risk work, begin with the Foundation to fix the vocabulary, then the Risk Manager to practise the full process. If you already run assessments and need to lead the programme, go straight to the Lead Risk Manager.

Ricardo Coronel Lemus
Signed by Ricardo Coronel Lemus
GRC Consultant / vCISO in practice · PECB Certified Trainer

This is not a generic marketing PDF. It is the practical summary of a consultant who builds and audits risk assessments in real organisations. Template included so you can start today.