nerdexam
(ISC)2

CAP · Question #112

BS 7799 is an internationally recognized ISM standard that provides high level, conceptual recommendations on enterprise security. BS 7799 is basically divided into three parts. Which of the…

The correct answer is B. BS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005. C. BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards D. BS 7799 Part 3 was published in 2005, covering risk analysis and management. BS 7799 Part 2 became ISO/IEC 27001, Part 1 was the original British Standard code of practice, and Part 3 covered risk analysis - while Part 1 became ISO/IEC 17799, not 27001.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

BS 7799 is an internationally recognized ISM standard that provides high level, conceptual recommendations on enterprise security. BS 7799 is basically divided into three parts. Which of the following statements are true about BS 7799? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ABS 7799 Part 1 was adopted by ISO as ISO/IEC 27001 in November 2005.
  • BBS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005.
  • CBS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards
  • DBS 7799 Part 3 was published in 2005, covering risk analysis and management.

How the community answered

(50 responses)
  • A
    6% (3)
  • B
    94% (47)

Why each option

BS 7799 Part 2 became ISO/IEC 27001, Part 1 was the original British Standard code of practice, and Part 3 covered risk analysis - while Part 1 became ISO/IEC 17799, not 27001.

ABS 7799 Part 1 was adopted by ISO as ISO/IEC 27001 in November 2005.

BS 7799 Part 1 was adopted by ISO as ISO/IEC 17799 (later renumbered ISO/IEC 27002), not ISO/IEC 27001 - that designation went to Part 2.

BBS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005.Correct

BS 7799 Part 2, which specified requirements for an information security management system (ISMS), was adopted by ISO as ISO/IEC 27001 in November 2005.

CBS 7799 Part 1 was a standard originally published as BS 7799 by the British StandardsCorrect

BS 7799 Part 1 was indeed the original standard published by the British Standards Institution, providing a code of practice for information security management.

DBS 7799 Part 3 was published in 2005, covering risk analysis and management.Correct

BS 7799 Part 3 was published in 2005 and specifically addressed information security risk analysis and management processes.

Concept tested: BS 7799 and ISO/IEC 27001 standard lineage

Source: https://www.iso.org/standard/42103.html

Topics

#Information Security Standards#BS 7799#ISO 27000 series#Risk Management

Community Discussion

No community discussion yet for this question.

Full CAP Practice