210-250 · Question #93
Which international standard is for general risk management, including the principles and guideline for managing risk?
The correct answer is A. ISO 31000. ISO 31000 is the international standard defining universal principles and guidelines for risk management applicable to any organization or industry sector.
Question
Which international standard is for general risk management, including the principles and guideline for managing risk?
Options
- AISO 31000
- BISO 27001
- CISO 27005
- DISO 27002
How the community answered
(33 responses)- A94% (31)
- B3% (1)
- D3% (1)
Why each option
ISO 31000 is the international standard defining universal principles and guidelines for risk management applicable to any organization or industry sector.
ISO 31000 establishes risk management principles, a framework, and a process at a broad organizational level, independent of any specific domain such as information security. It is designed to apply across all types of organizations and contexts, making it the correct answer for a general risk management standard covering principles and guidelines.
ISO 27001 specifies requirements for establishing, implementing, and maintaining an Information Security Management System and is scoped exclusively to information security, not general enterprise risk management.
ISO 27005 provides guidelines for information security risk management specifically and is a domain-specific subset of risk management, not a general-purpose risk standard.
ISO 27002 is a code of practice that provides best practice guidance on information security controls and does not address general organizational risk management principles.
Concept tested: ISO 31000 general risk management principles standard
Source: https://www.iso.org/iso-31000-risk-management.html
Topics
Community Discussion
No community discussion yet for this question.