ISO 31000 vs MAGERIT: which risk analysis methodology to choose
By the QuantumSec team
Both ISO 27001 and the ENS require a risk assessment, but neither mandates a single methodology. In Spain, the choice almost always comes down to two options: ISO 31000, the generic international framework, or MAGERIT, Spain's public-sector-specific methodology. Choosing well avoids redoing the work if you need the other compliance framework later.
ISO 31000: principles, not a closed formula
ISO 31000 is a generic, principles-based risk management framework: it defines a process (establishing context, identifying, analyzing and evaluating risks, treating them, and monitoring and reviewing) but leaves the concrete valuation technique open. It applies to any kind of risk — not just information security — which is why it's common in organizations that already have a broader corporate risk management function beyond cybersecurity. In ISO 27001 practice, many companies complement ISO 31000's principles with ISO 27005's information-security-specific guidance, which does detail how to apply that process within an ISMS context.
MAGERIT: a closed methodology, with a tool and five fixed dimensions
MAGERIT is far more prescriptive: it defines exactly which dimensions to assess (confidentiality, integrity, availability, authenticity, traceability), how to calculate impact and risk, and comes with an official tool (PILAR) that automates the process and generates the reports submitted as evidence. That rigidity is an advantage in the ENS context, where MAGERIT's five dimensions are literally the same ones the scheme uses to classify the system.
Which one to choose based on your situation
If your project is exclusively ENS, MAGERIT is the natural choice: it fits directly with the BASIC/MEDIUM/HIGH classification and with the tools and evidence an ENS auditor expects to see. If your project is ISO 27001 with no public-sector relationship, ISO 31000 (with or without the ISO 27005 complement) tends to be more flexible and more recognizable to international auditors. If you need both frameworks — ENS and ISO 27001 — MAGERIT is, in practice, the option that lets you reuse a single risk assessment for both, because its rigor and five dimensions also satisfy ISO 27001's open requirement.
What doesn't change, whichever methodology you pick
Both methodologies fundamentally require the same thing: identify assets, value their importance, identify threats, calculate risk and decide a treatment. The methodology is the documented "how"; what a certifier actually audits is whether that analysis reflects your organization's reality or is a template-filling exercise. No methodology, however rigorous on paper, replaces an honest analysis.
FAQ
Can I use MAGERIT for an ISO 27001 project unrelated to the public sector?
Yes. ISO 27001 doesn't require a specific methodology, only a coherent and repeatable risk assessment process. MAGERIT satisfies that perfectly, although in purely private contexts it's less common than ISO 31000/27005 since it's less known outside Spain.
Is ISO 27005 mandatory if you choose ISO 31000?
No, but it's highly recommended: ISO 31000 is deliberately generic and doesn't go into information-security-specific detail, while ISO 27005 does, which makes practical application within an ISMS much easier.
Is switching methodology mid-project a problem?
It's avoidable with a good upfront decision, but not catastrophic: what an auditor reviews is the outcome (assets identified, risks valued, treatment decided), not the methodology itself. Switching methodology means redoing part of the exercise, not losing the validity of the whole project.