ISO/IEC 27005:2008
Withdrawn
View Superseded by
Information technology — Security techniques — Information security risk management
06-04-2008
04-09-2025
ISO/IEC 27005:2008 provides guidelines for information security risk management. It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach. Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of ISO/IEC 27005:2008. ISO/IEC 27005:2008 is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.
| Committee |
ISO/IEC JTC 1/SC 27
|
| DocumentType |
Standard
|
| PublisherName |
International Organization for Standardization
|
| Status |
Withdrawn
|
| SupersededBy | |
| Supersedes |
| Standards | Relationship |
| BS ISO/IEC 27005:2008 | Equivalent |
| BS ISO/IEC 27005:2008 | Identical |