nerdexam
EC-Council

712-50 · Question #107

Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology?

The correct answer is D. ISO 27005. ISO 27005 is the ISO standard specifically dedicated to information security risk management, and it defines a structured five-stage risk management process: context establishment, risk assessment, risk treatment, risk acceptance, and risk communication/monitoring. It is the…

Security Program Management & Operations

Question

Which International Organization for Standardization (ISO) below BEST describes the performance of risk management, and includes a five-stage risk management methodology?

Options

  • AISO 27001
  • BISO 27002
  • CISO 27004
  • DISO 27005

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    9% (2)
  • D
    83% (19)

Explanation

ISO 27005 is the ISO standard specifically dedicated to information security risk management, and it defines a structured five-stage risk management process: context establishment, risk assessment, risk treatment, risk acceptance, and risk communication/monitoring. It is the only standard in the 27000 series that focuses exclusively on the performance of risk management as a process.

Why the distractors are wrong:

  • A. ISO 27001 establishes the requirements for an Information Security Management System (ISMS) - it references risk management as a component but doesn't define the methodology itself.
  • B. ISO 27002 provides a code of practice - a catalog of security controls and implementation guidance, not a risk management methodology.
  • C. ISO 27004 covers measurement and monitoring of information security - metrics and evaluation, not risk management process design.

Memory tip: Think of the number 5 in 27005 as a hint - it's the standard with the five-stage risk methodology. Alternatively, remember "5 = survive risk" - 27005 is how your security program survives by managing risk systematically.

Topics

#ISO 27005#Risk Management#Information Security#Five-stage methodology

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice