CAP · Question #112
BS 7799 is an internationally recognized ISM standard that provides high level, conceptual recommendations on enterprise security. BS 7799 is basically divided into three parts. Which of the…
The correct answer is B. BS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005. C. BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards D. BS 7799 Part 3 was published in 2005, covering risk analysis and management. BS 7799 Part 2 became ISO/IEC 27001, Part 1 was the original British Standard code of practice, and Part 3 covered risk analysis - while Part 1 became ISO/IEC 17799, not 27001.
Question
BS 7799 is an internationally recognized ISM standard that provides high level, conceptual recommendations on enterprise security. BS 7799 is basically divided into three parts. Which of the following statements are true about BS 7799? Each correct answer represents a complete solution. Choose all that apply.
Options
- ABS 7799 Part 1 was adopted by ISO as ISO/IEC 27001 in November 2005.
- BBS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005.
- CBS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards
- DBS 7799 Part 3 was published in 2005, covering risk analysis and management.
How the community answered
(50 responses)- A6% (3)
- B94% (47)
Why each option
BS 7799 Part 2 became ISO/IEC 27001, Part 1 was the original British Standard code of practice, and Part 3 covered risk analysis - while Part 1 became ISO/IEC 17799, not 27001.
BS 7799 Part 1 was adopted by ISO as ISO/IEC 17799 (later renumbered ISO/IEC 27002), not ISO/IEC 27001 - that designation went to Part 2.
BS 7799 Part 2, which specified requirements for an information security management system (ISMS), was adopted by ISO as ISO/IEC 27001 in November 2005.
BS 7799 Part 1 was indeed the original standard published by the British Standards Institution, providing a code of practice for information security management.
BS 7799 Part 3 was published in 2005 and specifically addressed information security risk analysis and management processes.
Concept tested: BS 7799 and ISO/IEC 27001 standard lineage
Source: https://www.iso.org/standard/42103.html
Topics
Community Discussion
No community discussion yet for this question.