CGRC · Question #274
Which of the following parts of BS 7799 covers risk analysis and management? Response:
The correct answer is B. Part 3. BS 7799 Part 3 specifically addresses risk analysis and management within an information security management system.
Question
Which of the following parts of BS 7799 covers risk analysis and management? Response:
Options
- APart 1
- BPart 3
- CPart 2
- DPart 4
How the community answered
(61 responses)- A2% (1)
- B89% (54)
- C7% (4)
- D3% (2)
Why each option
BS 7799 Part 3 specifically addresses risk analysis and management within an information security management system.
BS 7799 Part 1 (now ISO/IEC 27002) provides a code of practice for information security controls, not directly risk analysis and management methodology.
BS 7799-3, titled "Guidelines for Information Security Risk Management," provides guidance on risk assessment, treatment, and management within the context of an information security management system (ISMS). This part focuses entirely on the methodologies and processes for managing information security risks.
BS 7799 Part 2 (now ISO/IEC 27001) specifies requirements for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an ISMS, but Part 3 specifically details risk management guidance.
There is no widely recognized BS 7799 Part 4; the standard primarily consisted of three parts.
Concept tested: BS 7799 standard parts and their focus
Source: https://www.iso.org/standard/74712.html
Topics
Community Discussion
No community discussion yet for this question.