ISO/IEC 27005:2011

Citation
ISO/IEC 27005:2011: Information Technology – Security Techniques – Information Security Risk Management Systems (2011) (full-text).

Overview
ISO/IEC 27005:2011 provides guidelines for information security risk management. It supports the general concepts specified in ISO/IEC 27001 and is designed to assist the satisfactory implementation of information security based on a risk management approach.

ISO/IEC 27005:2011 is applicable to all types of organizations (e.g. commercial enterprises, government agencies, non-profit organizations) which intend to manage risks that could compromise the organization's information security.