ADOPTED_FROM:ISO/IEC 27005:2018 This document provides guidelines for information security risk management. This document supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach. Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of this document. This document is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that can compromise the organization\'s information security.
NS-ISO/IEC 27005:2018 history
2022NS-ISO/IEC 27005:2022 Information security, cybersecurity and privacy protection - Guidance on managing information security risks
2018NS-ISO/IEC 27005:2018 Information technology — Security techniques — Information security risk management
2012NS-ISO/IEC 27005:2011 Information technology — Security techniques — Information security risk management
2009NS-ISO/IEC 27005:2008 Information technology — Security techniques — Information security risk management