712-50 · Question #107
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology?
The correct answer is D. ISO 27005. ISO 27005 is the ISO standard specifically dedicated to information security risk management, and it defines a structured five-stage risk management process: context establishment, risk assessment, risk treatment, risk acceptance, and risk communication/monitoring. It is the…
Question
Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology?
Options
- AISO 27001
- BISO 27002
- CISO 27004
- DISO 27005
How the community answered
(23 responses)- A4% (1)
- B4% (1)
- C9% (2)
- D83% (19)
Explanation
ISO 27005 is the ISO standard specifically dedicated to information security risk management, and it defines a structured five-stage risk management process: context establishment, risk assessment, risk treatment, risk acceptance, and risk communication/monitoring. It is the only standard in the 27000 series that focuses exclusively on the performance of risk management as a process.
Why the distractors are wrong:
- A. ISO 27001 establishes the requirements for an Information Security Management System (ISMS) - it references risk management as a component but doesn't define the methodology itself.
- B. ISO 27002 provides a code of practice - a catalog of security controls and implementation guidance, not a risk management methodology.
- C. ISO 27004 covers measurement and monitoring of information security - metrics and evaluation, not risk management process design.
Memory tip: Think of the number 5 in 27005 as a hint - it's the standard with the five-stage risk methodology. Alternatively, remember "5 = survive risk" - 27005 is how your security program survives by managing risk systematically.
Topics
Community Discussion
No community discussion yet for this question.