International

ISO 27005:2022

42 controls. 58 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

42 controls 58 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ISO/IEC 27005:2022 Information Security Risk Evidence & Implementation Kit

42 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
10.1Context of the organization2
10.2Leadership and commitment33
10.3Communication and consultation33
10.4Documented information27
10.4.2Documented information about processes26
10.4.3Documented information about results26
10.5Monitoring and review7
10.5.2Monitoring and reviewing factors influencing risks0
10.6Management review31
10.7Corrective action3
10.8Continual improvement34
3.1Terms related to information security risk0
3.2Terms related to information security risk management0
5.1Information security risk management process4
5.2Information security risk management cycles4
6.1Organizational considerations0
6.2Identifying basic requirements of interested parties0
6.3Applying risk assessment0
6.4Establishing and maintaining information security risk criteria1
6.4.2Risk acceptance criteria2
6.4.3Criteria for performing information security risk assessments0
6.5Choosing an appropriate method1
7.2Identifying information security risks0
7.2.1Identifying and describing information security risks0
7.2.2Identifying risk owners0
7.3Analysing information security risks1
7.3.2Assessing potential consequences1
7.3.3Assessing likelihood2
7.3.4Determining the levels of risk1
7.4Evaluating the information security risks0
7.4.1Comparing the results of risk analysis with the risk criteria0
7.4.2Prioritizing the analysed risks for risk treatment0
8.2Selecting appropriate information security risk treatment options0
8.3Determining all controls that are necessary to implement the information security risk treatment options0
8.4Comparing the controls determined with those in ISO/IEC 27001:2022, Annex A0
8.5Producing a Statement of Applicability0
8.6Information security risk treatment plan6
8.6.1Formulation of the risk treatment plan0
8.6.2Approval by risk owners0
8.6.3Acceptance of the residual information security risks0
9.1Performing information security risk assessment process0
9.2Performing information security risk treatment process0

Tell me when ISO 27005:2022 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO 27005:2022, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition