Skip to content

ISO 27005

What is ISO 27005?

The international standard providing guidelines for information security risk management, supporting the requirements of ISO 27001.

Compliance and Regulatory

Each of these is named in at least one of the same controls as iso 27005. The number is how many controls name both.

What the standards actually require on iso 27005

Requirements naming iso 27005 across 5 standards, quoted from the control text.

ISO 27005:202245 controls

Requirement defined in ISO 27005:2022, clause 8.1 (General). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-27005-2022::8.1 · General

Identify is the first of five functional elements per MSC-FAL.1/Circ.3/Rev.2 (aligned with NIST CSF Identify). Activities include: (1) Asset Inventory of vulnerable systems organisationally + onboard ship - Operational Technology (OT) systems including Bridge...

IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities · IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA

Kuwait NCF Identify function. Asset Identification and Classification: comprehensive Configuration Management Database (CMDB) covering hardware + software + data + cloud assets + IoT + OT/ICS + virtual + container + identity + business processes + suppliers.

KNCF-Identify-Asset-Risk-Management-CMDB-Classification-Crown-Jewels-CNI-NCSC-Sector-Designation · Kuwait NCF Identify + Asset Management + Risk + CNI + Crown Jewels

Maintain the O-RAN threat model and risk management per O-RAN Alliance WG11 Security Threat Model and Risk Assessment specifications.

ORANWG11-1 · O-RAN Threat Model, Risk Management, and Security Architecture

Establish cybersecurity governance + policy + risk management per Oman National Cybersecurity Framework administered by the Ministry of Transport + Communications and Information Technology (MTCIT) and the Oman National Computer Emergency Readiness Team (OmanC...

OMANCS-1 · Cybersecurity Governance, Policy, and Risk Management

Questions people ask about iso 27005

What is ISO 27005?
The international standard providing guidelines for information security risk management, supporting the requirements of ISO 27001.
Why is ISO 27005 important for compliance?
ISO 27005 is a key concept in Compliance and Regulatory. Understanding iso 27005 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address ISO 27005?
ISO 27005 appears in the requirement text of ISO 27005:2022, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), Kuwait National Cybersecurity Framework, O-RAN WG11 Security Specification, Oman National Cybersecurity Framework. Across these standards we have identified 50 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about ISO 27005?
Explore our compliance framework pages to see how iso 27005 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how ISO 27005 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.