nerdexam
(ISC)2

CGRC · Question #274

Which of the following parts of BS 7799 covers risk analysis and management? Response:

The correct answer is B. Part 3. BS 7799 Part 3 specifically addresses risk analysis and management within an information security management system.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Which of the following parts of BS 7799 covers risk analysis and management? Response:

Options

  • APart 1
  • BPart 3
  • CPart 2
  • DPart 4

How the community answered

(61 responses)
  • A
    2% (1)
  • B
    89% (54)
  • C
    7% (4)
  • D
    3% (2)

Why each option

BS 7799 Part 3 specifically addresses risk analysis and management within an information security management system.

APart 1

BS 7799 Part 1 (now ISO/IEC 27002) provides a code of practice for information security controls, not directly risk analysis and management methodology.

BPart 3Correct

BS 7799-3, titled "Guidelines for Information Security Risk Management," provides guidance on risk assessment, treatment, and management within the context of an information security management system (ISMS). This part focuses entirely on the methodologies and processes for managing information security risks.

CPart 2

BS 7799 Part 2 (now ISO/IEC 27001) specifies requirements for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an ISMS, but Part 3 specifically details risk management guidance.

DPart 4

There is no widely recognized BS 7799 Part 4; the standard primarily consisted of three parts.

Concept tested: BS 7799 standard parts and their focus

Source: https://www.iso.org/standard/74712.html

Topics

#BS 7799#Risk Management#Risk Analysis#Information Security Standards

Community Discussion

No community discussion yet for this question.

Full CGRC Practice