What is ISO/IEC 27005?
ISO/IEC 27005:2022 is the international standard providing guidance on managing information security risks. Published by the International Organization for Standardization, the 2022 fourth edition aligned the standard tightly to ISO 27001's clause 6 requirements — the risk assessment and risk treatment obligations every certified ISMS must satisfy.
Where ISO 27001 says an organisation shall define a risk assessment process, ISO 27005 explains how: establishing context and risk criteria, identifying risks against confidentiality, integrity, and availability, analysing consequence and likelihood, evaluating against the criteria, treating through modification, retention, avoidance, or sharing, and then recording, reporting, monitoring, and reviewing the whole cycle.
In practice, ISO 27005 is the standard behind the two artefacts auditors examine hardest in an ISO 27001 certification: the risk register and the Statement of Applicability. Most Stage 2 audit findings trace back to risk work that was undocumented, unmethodical, or untraceable — which is precisely the gap this credential closes.
Important: ISO 27005 certifies practitioners, not companies
Like ISO 31000, ISO/IEC 27005 is guidance — there is no Stage 1/Stage 2 audit and no certificate issued to organisations. “ISO 27005 certification” in Australia means individual practitioner credentials through PECB: Risk Manager and Lead Risk Manager. The organisational certificate in this domain is ISO 27001 — and your ISO 27005-based risk assessment is what the ISO 27001 auditor examines.
This distinction matters commercially. Organisations do not buy ISO 27005 certification; they hire or contract people who hold it. The credential attaches to the practitioner and travels with them across employers, engagements, and tenders — which is why it appears in job descriptions for GRC analysts, security risk managers, and ISMS leads rather than in supplier questionnaires.
The nearest organisational analogue is the ISO 27001 certificate itself, where the risk methodology is audited as part of the management system. For enterprise-wide risk outside information security, the parallel practitioner scheme is ISO 31000.
Who needs ISO 27005 in Australia?
The credential maps to the person who owns information security risk — in-house or advisory. The profiles who most commonly take ISO 27005 courses in Australia:
- ISMS implementers and coordinators — anyone standing up or maintaining an ISO 27001 management system owns a clause 6 risk assessment. ISO 27005 is the natural companion credential to ISO 27001 Lead Implementer, covering the half of the ISMS most Stage 2 audits fail on.
- GRC and security risk analysts at APRA-regulated entities, ASX-listed companies, and government agencies — where “information security risk management” is a named competency in role descriptions and CPS 234 self-assessments.
- ISO 27001 auditors — internal and certification-body — who must judge whether a risk methodology is sound, applied consistently, and traceable to the Statement of Applicability.
- Consultants and vCISOs who inherit a different risk method at every client — the courses cover OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA alongside ISO 27005, so you can work inside an established approach and explain its trade-offs.
- SOCI-captured critical infrastructure teams — energy, water, ports, data storage and processing — whose Risk Management Programs need a documented, repeatable cyber-hazard methodology underneath.
Where ISO 27005 sits in Australian regulation
ISO 27005 is voluntary guidance, but it supplies the risk method underneath most of the information security obligations Australian organisations actually face. The table summarises the relationships Aegentra is most often asked about.
| Australian regulation / framework | What it requires | How ISO 27005 helps |
|---|---|---|
| ISO 27001 clause 6 | A documented information security risk assessment and risk treatment process, with results traceable to the Statement of Applicability. | ISO 27005 is the guidance those assessments are most commonly built on — the risk methodology the Stage 2 auditor walks through line by line. |
| APRA CPS 234 | Information security capability commensurate with the size and extent of threats; controls testing; incident notification to APRA. | “Commensurate with threats” presumes a current, defensible information security risk assessment. ISO 27005 supplies the method that supports the board attestation. |
| ASD Essential Eight | Eight mitigation strategies with target maturity levels selected on a risk basis. | Choosing a maturity level target — and sequencing the uplift — is a risk-prioritisation exercise. ISO 27005 gives that decision an evidence trail instead of a preference. |
| SOCI Act — Risk Management Program rules | Captured critical-infrastructure entities must identify and mitigate hazards — cyber, personnel, supply-chain, physical — in a documented RMP. | ISO 27005 is the cyber-hazard methodology most commonly used inside the RMP, sitting under an ISO 31000 umbrella for the cross-hazard view. |
| Privacy Act / Notifiable Data Breaches | APP 11 reasonable-steps security of personal information; breach assessment and OAIC notification. | A documented risk assessment is the strongest evidence of “reasonable steps”. Pairs naturally with ISO 27701 for privacy-specific risk. |
| PSPF and government ISM | Risk-based decisions on information handling and system authorisation for Commonwealth and state entities. | A repeatable information security risk method is a standing requirement of the authorisation process, not a one-off deliverable. ISO 27005 is the common reference. |
The pattern across all six: Australian regulators rarely name ISO 27005, but they consistently require the thing it produces — a documented, defensible, repeatable information security risk assessment. Related reading: the NIST cybersecurity pathway covers the equivalent US-framework territory.
How much does ISO 27005 certification cost in Australia?
Because there is no organisational certification, the only direct costs are individual training and the official PECB exam. AUD pricing through Aegentra Academy (official PECB authorised training partner):
- ISO/IEC 27005 Risk Manager — from $849 + GST (Self-Study; eLearning $949 + GST). Practitioner level — for the person running the risk process. 21–30 hours, self-paced.
- ISO/IEC 27005 Lead Risk Manager — $989 + GST (Self-Study). Senior level — for the person who owns the framework. 35–45 hours, self-paced.
Every enrolment includes the official PECB exam voucher and a free resit within 12 months. The Lead Risk Manager package also includes the certification application fee and the first year of the PECB Annual Maintenance Fee. Tax invoices with GST and ABN are issued at checkout.
Risk Manager vs Lead Risk Manager
The two credentials divide along accountability, not seniority of title. Risk Manager is the process credential; Lead Risk Manager is the framework credential.
| Risk Manager | Lead Risk Manager | |
|---|---|---|
| Price (AUD + GST) | From $849 + GST (Self-Study) · $949 + GST (eLearning) | $989 + GST (Self-Study) |
| Effort | 21–30 hours · 3-day course equivalent | 35–45 hours · 5-day course equivalent |
| Materials | 350+ pages · 12 months myPECB access | 450+ pages · 12 months myPECB access |
| Exam | 2 hours · open-book · mixed multiple-choice and scenario questions · 4 competency domains | 3 hours · open-book · 80 multiple-choice questions · 6 competency domains |
| CPD credits | 21 | 31 |
| Credential ladder | Provisional Risk Manager → Risk Manager → Senior Risk Manager | Provisional Risk Manager → Lead Risk Manager → Senior Lead Risk Manager |
| Best for | Analysts, ISMS coordinators, consultants running the risk process and maintaining the register. | CISOs, heads of risk, ISMS owners, and consultants accountable for the framework and its results. |
Both courses survey the same six assessment methods — OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA — so either credential leaves you able to choose a method rather than inherit one. Enrol in Risk Manager or Lead Risk Manager.
The PECB exams
Both exams are open-book and remotely proctored — you sit them from home or the office, anywhere in Australia, on a schedule that suits you. The pass mark for each is 70%, and one free resit within 12 months is included.
Risk Manager — 2 hours, mixed multiple-choice and scenario-based questions across 4 competency domains. The scenarios test whether you can apply the process — context, identification, analysis, evaluation, treatment — to a described organisation, not recite the standard.
Lead Risk Manager — 3 hours, 80 multiple-choice questions (stand-alone and scenario-based, three options each) across 6 competency domains. Open-book: the standard, course materials, and personal notes are permitted. The additional domains cover framework ownership — communication and consultation planning, recording and reporting, monitoring and review, and continual improvement.
On passing, credentials issue through PECB's ladder based on attested professional experience: candidates without the experience threshold can apply for the Provisional Risk Manager credential and apply to upgrade as hours accrue. All credentials require signing the PECB Code of Ethics and are maintained through CPD.
The risk process and the six methods
The ISO 27005 process is the operational sequence an ISMS risk assessment follows:
- Context establishment — scope, risk criteria, and acceptance thresholds.
- Risk identification — assets, threats, vulnerabilities, existing controls, consequences.
- Risk analysis — consequence and likelihood, producing a level of risk.
- Risk evaluation — comparing analysed risk against the criteria to prioritise treatment.
- Risk treatment — modification, retention, avoidance, or sharing, with a treatment plan and residual-risk acceptance.
- Communication and consultation — continuous, with decision-makers and stakeholders.
- Recording, reporting, monitoring, and review — continuous, feeding management review.
The differentiator in the PECB courses is method fluency. Alongside ISO 27005 itself, both tiers survey the six established assessment methods — OCTAVE (including OCTAVE-S and Allegro), MEHARI, EBIOS, the NIST risk management framework, CRAMM, and Harmonized TRA. In consulting and in-house work alike you frequently inherit a method rather than choose one; being able to operate inside an established approach and explain its trade-offs is what separates a practitioner from a checklist follower.
Output traceability is the discipline the courses drill: every control in the ISO 27001 Statement of Applicability should trace back to an assessed risk, and every accepted residual risk to a named owner. That chain is what a certification auditor follows — and what regulators increasingly expect to see behind SOC 2 and ISO attestations alike.
ISO 27005 vs ISO 31000
The two standards are companions, not competitors — and the distinction decides which credential you should pursue first.
ISO 31000:2018 — enterprise-wide, principle-based risk management guidance applicable to any organisation and any risk domain: strategic, operational, financial, safety, cyber. Deliberately non-prescriptive, and not certifiable for organisations. It is the umbrella framework boards and audit committees speak. Full guide: ISO 31000 certification in Australia.
ISO/IEC 27005:2022 — information security specific. More prescriptive, aligned step-for-step with ISO 27001 clause 6, and audited in practice as part of every ISO 27001 Stage 2 audit. It shares ISO 31000's vocabulary and process shape, then adds the asset-threat-vulnerability machinery that information security risk requires.
In most Australian organisations the two coexist: ISO 31000 governs the enterprise risk register that the board sees; ISO 27005 governs the ISMS risk register that the auditor sees; and the ISMS register rolls up into the enterprise one. Practitioners who hold both credentials can move between the two registers without re-learning vocabulary — exactly the position integrated GRC roles recruit for.
If your work is anchored to an ISMS, start with ISO 27005. If you own risk across the whole organisation, start with ISO 31000 and add 27005 for the information security depth. Adjacent reading: ISO 27701 for privacy risk and ISO 42001 for AI risk, both of which import this same risk machinery.
FAQs
ISO 27001 is the certifiable management system standard — it defines what an ISMS must do, including risk assessment and treatment under clause 6. ISO/IEC 27005 is the companion guidance that defines how to actually run information security risk management: establishing context, identifying, analysing, evaluating, and treating risks, then recording, reporting, monitoring, and reviewing them. Organisations certify against ISO 27001; individuals certify against ISO 27005 through PECB as Risk Managers and Lead Risk Managers.
No. ISO/IEC 27005 is guidance, not a certifiable management system standard — there is no Stage 1/Stage 2 audit and no organisational certificate. What exists is individual practitioner certification through PECB: Risk Manager and Lead Risk Manager. The organisational credential in this space is ISO 27001, where the ISO 27005-based risk assessment is examined as part of the Stage 2 certification audit.
Risk Manager (from $849 + GST) suits practitioners who run the risk process — security analysts, ISMS coordinators, and consultants who build and maintain the risk register. Lead Risk Manager ($989 + GST) suits the person who owns the framework — defines the method, sets the risk criteria, reports to the executive, and answers for the programme in front of an auditor. Practitioners who already hold ISO 27001 Lead Implementer or Lead Auditor and want the senior risk credential typically go straight to Lead Risk Manager.
Both are open-book, remotely proctored PECB exams with a 70% pass mark, so you can sit them from anywhere in Australia. Risk Manager is a 2-hour exam with mixed multiple-choice and scenario-based questions across 4 competency domains. Lead Risk Manager is a 3-hour exam with 80 multiple-choice questions across 6 competency domains — the standard, course materials, and personal notes are permitted. Both include the official exam voucher and one free resit within 12 months.
It helps. Both courses assume a fundamental understanding of information security and risk assessment, and both teach risk management in the context of a working ISMS. Prior ISO 27001 exposure is recommended for Risk Manager and strongly recommended for Lead Risk Manager, because the framework is designed to sit inside an ISMS. If you are new to ISO 27001 entirely, an ISO 27001 course first is the more natural sequence.
Both are self-paced through myPECB with 12 months of access. Risk Manager is roughly 21–30 hours of study — a 3-day course equivalent. Lead Risk Manager is 35–45 hours — a 5-day equivalent. Most working professionals complete Risk Manager in 3–5 weeks and Lead Risk Manager in 4–8 weeks alongside their day job, then sit the exam remotely on a schedule that suits them.
Directly. APRA CPS 234 requires regulated entities to maintain information security capability commensurate with the size and extent of threats — which presumes a defensible information security risk assessment underneath. Essential Eight uplift decisions and maturity-level targets are risk-prioritisation exercises. SOCI Act Risk Management Programs require captured entities to identify and mitigate hazards, including cyber. ISO 27005 supplies the documented, repeatable method that makes each of those positions defensible.
Accreditation varies by credential. PECB publishes personnel-certification accreditation under applicable ISO/IEC 17024 scopes and ANAB certificate-program accreditation under ANSI/ASTM E2659-24 for specified programs. Verify the applicable published PECB scope. Risk Manager carries 21 CPD credits and Lead Risk Manager 31.