Skip to content
Cyber Horizon
All frameworks

// Information Security

ISO 27005 Compliance Software

Guidelines for information security risk management aligned with ISO 27001.

Framework at a glance

Short name

ISO 27005

Version

Category

Information Security

Controls

30

What ISO 27005 covers

30 controls across 25 domains — every one tracked, owned and evidenced in Cyber Horizon.

Scope

1 controls
  • 5.1 Risk management scope

Context

1 controls
  • 5.2 Organisational context for risk

Criteria

1 controls
  • 5.3 Risk criteria

Process

2 controls
  • 6.1 Risk assessment process
  • 7.1 Risk treatment process

Identification

1 controls
  • 6.2 Risk identification

Assets

1 controls
  • 6.2.1 Asset identification

Threats

1 controls
  • 6.2.2 Threat identification

Controls

3 controls
  • 6.2.3 Existing control identification
  • 7.2 Risk modification
  • 9.2 Control monitoring

Vulnerabilities

1 controls
  • 6.2.4 Vulnerability identification

Impact

2 controls
  • 6.2.5 Consequence identification
  • 6.3.1 Consequence assessment

Analysis

1 controls
  • 6.3 Risk analysis

Likelihood

1 controls
  • 6.3.2 Likelihood assessment

Risk Level

1 controls
  • 6.3.3 Level of risk determination

Evaluation

1 controls
  • 6.4 Risk evaluation

Acceptance

1 controls
  • 7.3 Risk retention

Avoidance

1 controls
  • 7.4 Risk avoidance

Transfer

1 controls
  • 7.5 Risk sharing

Stakeholders

1 controls
  • 8.1 Information security risk communication

Consultation

1 controls
  • 8.2 Information security risk consultation

Monitoring

1 controls
  • 9.1 Risk monitoring

Residual Risk

1 controls
  • 9.3 Residual risk monitoring

Change

1 controls
  • 9.4 Change monitoring

Records

2 controls
  • 10.1 Risk register maintenance
  • 10.2 Risk assessment documentation

Treatment Plan

1 controls
  • 10.3 Risk treatment plan

Planning

1 controls
  • 10.4 Risk review schedule

How Cyber Horizon automates ISO 27005

Every ISO 27005 control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is ISO 27005?

Guidelines for information security risk management aligned with ISO 27001.

How many controls does ISO 27005 have?

ISO 27005 has 30 controls in Cyber Horizon's catalogue, organised across 25 domains.

How does Cyber Horizon help with ISO 27005?

Cyber Horizon maps ISO 27005 into a shared control library alongside every other framework you run, so evidence collected once counts towards ISO 27005 and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See ISO 27005 mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of ISO 27005 in Cyber Horizon.