What it is
What ISO 27005 is
ISO 27001 requires you to assess information security risk and to treat it, in clauses 6.1.2 and 6.1.3. It does not tell you how. ISO/IEC 27005 is the guidance that does: how to establish criteria, identify risk, analyse and evaluate it, decide treatment, and keep the whole thing under review.
It sits inside the ISO 31000 risk process rather than beside it, applied specifically to information security. If you already run risk to ISO 31000, ISO 27005 is that process pointed at your information assets.
It is guidance, not a certification
There is no ISO 27005 certificate. The certificate is ISO 27001, and your risk assessment is one of the things the auditor examines to award it. What ISO 27005 gives you is a defensible method - which matters, because the most common finding against a risk assessment is not that the risks are wrong but that nobody can explain how they were arrived at.
Asset-based or scenario-based
There are two honest ways to start. The asset-based approach works from what you hold - systems, data, people - to the threats against each and the vulnerabilities that let a threat land. It is thorough and it is how most organisations begin, because the inventory already exists.
The scenario-based approach works from what could happen - a ransomware event, a supplier breach, an insider taking a customer list - back to what would have to be true. It produces fewer, larger risks that a board can actually discuss, and it tends to find the cross-cutting exposures an asset list misses.
Neither is more correct. What matters for an audit is that you chose one deliberately, applied it consistently, and can say why. A register that mixes both without a stated method is the one that struggles under questioning.
Criteria come first
The most common weakness in an information security risk assessment is that the acceptance criteria were written after the scoring. Decide what you will tolerate, on what scale, and who is entitled to accept a risk above it - before any risk is scored. Criteria set afterwards are criteria fitted to the answer.