ISO/IEC 27005:2008
Information technology — Security techniques — Information security risk management
OVERVIEW
ISO/IEC 27005:2008 provides guidelines for information security risk management. It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach. Knowledge of the concepts, models, processes and terminologies described in ISO/IEC 27001 and ISO/IEC 27002 is important for a complete understanding of ISO/IEC 27005:2008. ISO/IEC 27005:2008 is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.
COMMENTS
-
PRODUCT DETAILS
| Status | Withdrawn - 06 Jan 2026 |
|---|---|
| Edition | 2008 |
| No. of Pages | 55 |
| ICS Classification | 03.100.70 Management systems 35.030 IT Security |
| Committee | ISO/IEC JTC 1/SC 27 |
| Available for Purchase | For sale in Singapore only |
| Adoption | ISO |