Drata Logo Dark (New)
  • Product
  • Resources
  • Alliances
  • Customers
  • Company
    Sign inGet Started
  • Sign in
  • Get Started
HomeCompliance GlossaryISO 27005:2022

ISO 27005:2022

ISO 27005:2022 is an international standard that provides information security risk management guidelines. It’s part of the ISO 27000 series of standards, which provide guidelines and best practices for information security management. The standard was published in September 2022 and replaces the previous version, ISO 27005:2011.


It provides updated guidance on identifying, assessing, and managing information security risks and integrating risk management into an organization's overall information security management system (ISMS). It also includes new sections on risk assessment methodologies, risk treatment, and risk reporting. ISO 27005:2022 is intended to help organizations effectively manage their information security risks and protect their sensitive information.

Join the Thousands of Companies that Trust Drata

See All Case Studies
Wiz logo 2
Airbase
TaskRabbit Logo
BambooHR Logo
Clearbit Logo
Superhuman
Alteryx logo
Lemonade Logo
Notion Logo
Vercel Logo
Wordpress VIP
Calendly Logo

View Drata Glossary

Learn more about other compliance and cybersecurity concepts in our glossary.

Read More

Solutions

StartupMid-MarketEnterpriseDrata PlatformIntegrations
Frameworks
SOC 2ISO 27001HIPAAGDPRNIST AI Risk ManagementFedRAMPNIS 2Custom FrameworksAll Frameworks
Resources
BlogEventsWebinarsReportsSOC 2 HubISO 27001 HubProduct UpdatesCompliance GlossaryAPI Documentation
Company
CareersCustomersAuditorsPartnersPressContact UsLegal
Trust
Security and ComplianceTrust CenterSystem StatusAccessibility

Drata Logo Light

© 2025 Drata Inc. All rights reserved.

|Privacy Notice|Legal