In this document, it announces the development of an information security risk management model for companies in the insurance sector, based on the risk management approach of the Colombian technical standard NTC-ISO / IEC 27005: 2008, which offers the guidelines to successfully implement a security model in any type of organization that wants to mitigate the risk in information security.