ISO 27005
What is ISO 27005?
Information security risk management guidelines. It comprises 26 controls organised across 11 domains, published by ISO/IEC, and applies in International.
Map this against the frameworks you already hold
The compliance knowledge graph holds cross-framework control mappings for hundreds of standards, including the ones you are likely to be certified against already.
Browse the framework graph →The 11 domains ISO 27005 groups its controls into
Frameworks that share controls with ISO 27005
Each of these has at least one control mapped to a control in ISO 27005. The number is how many ISO 27005 controls are shared, counted from the mapping graph.
NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security
7 shared controlsNIST Privacy Framework
7 shared controlsNew Zealand Information Security Manual (NZISM)
7 shared controlsMTCS (Singapore)
7 shared controlsNIST SP 800-53 Rev 5
7 shared controlsSOC for Cybersecurity - Cybersecurity Risk Management Examination
7 shared controlsNIST SP 800-39
7 shared controlsNIST SP 800-37
7 shared controlsImplementation guides for frameworks that overlap ISO 27005
Where ISO 27005 overlaps with the standards you already hold
Where to get trained on ISO 27005
4 courses in the catalogue cover ISO 27005 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
What ISO 27005 means in your sector
What ISO 27005 means for your job
Questions people ask about ISO 27005
What is ISO 27005?
How many controls does ISO 27005 have?
Where does ISO 27005 apply?
What frameworks does ISO 27005 map to?
How do I get started with ISO 27005 compliance?
Query ISO 27005 programmatically
ISO 27005, its 26 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO 27005 API reference and MCP config →How ready are you for ISO 27005?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.