ISO 27005
What is ISO 27005?
The international standard providing guidelines for information security risk management, supporting the requirements of ISO 27001.
Terms that appear alongside iso 27005
Each of these is named in at least one of the same controls as iso 27005. The number is how many controls name both.
- information security 14 shared controls
- risk assessment 11 shared controls
- risk treatment 10 shared controls
- governance 7 shared controls
- nist 5 shared controls
- risk framework 5 shared controls
- risk monitoring 5 shared controls
- risk register 3 shared controls
Frameworks that govern iso 27005
What the standards actually require on iso 27005
Requirements naming iso 27005 across 5 standards, quoted from the control text.
Requirement defined in ISO 27005:2022, clause 8.1 (General). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.
iso-27005-2022::8.1 · General →Identify is the first of five functional elements per MSC-FAL.1/Circ.3/Rev.2 (aligned with NIST CSF Identify). Activities include: (1) Asset Inventory of vulnerable systems organisationally + onboard ship - Operational Technology (OT) systems including Bridge...
IMO-MSC-FAL-Identify-AssetInventory-ThreatsVulnerabilities-CyberRiskAssessment-RolesResponsibilities · IMO MSC-FAL Identify Function - OT/IT Asset Inventory + Threats + Vulnerabilities + Cyber Risk Assessment + Roles and Responsibilities + Crew + CSO + DPA →Kuwait NCF Identify function. Asset Identification and Classification: comprehensive Configuration Management Database (CMDB) covering hardware + software + data + cloud assets + IoT + OT/ICS + virtual + container + identity + business processes + suppliers.
KNCF-Identify-Asset-Risk-Management-CMDB-Classification-Crown-Jewels-CNI-NCSC-Sector-Designation · Kuwait NCF Identify + Asset Management + Risk + CNI + Crown Jewels →Maintain the O-RAN threat model and risk management per O-RAN Alliance WG11 Security Threat Model and Risk Assessment specifications.
ORANWG11-1 · O-RAN Threat Model, Risk Management, and Security Architecture →Establish cybersecurity governance + policy + risk management per Oman National Cybersecurity Framework administered by the Ministry of Transport + Communications and Information Technology (MTCIT) and the Oman National Computer Emergency Readiness Team (OmanC...
OMANCS-1 · Cybersecurity Governance, Policy, and Risk Management →Questions people ask about iso 27005
What is ISO 27005?
Why is ISO 27005 important for compliance?
Which compliance frameworks address ISO 27005?
Where can I learn more about ISO 27005?
See how ISO 27005 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.