Who uses it
Risk and security teams use it to build the risk process that ISO/IEC 27001 requires.
How it is applied
- Current practice is compared with the guidance.
- Management agrees which parts apply and who owns them.
- Practices are adopted in policies, procedures and training.
- Results are reviewed after a set period and adjusted.
Cost drivers
Cost is mainly staff time and any outside support. The number of processes and teams involved decides the effort. No certification fees apply, as no certificate is issued.
Timeline
Most organisations adopt it in phases over several months. It can run alongside work on a certifiable standard.
Certification
ISO/IEC 27005 is guidance, so accredited certificates are not issued against it. Certification is sought against ISO/IEC 27001, which it supports.


