{
  "class": "BSI-Methodik-Grundschutz-plus-plus",
  "id": "GC.7.2",
  "links": [
    {
      "href": "#GC.7.1.2",
      "rel": "required"
    },
    {
      "href": "#GC.12.1",
      "rel": "required"
    }
  ],
  "parts": [
    {
      "id": "GC.7.2_stm",
      "name": "statement",
      "props": [
        {
          "name": "documentation",
          "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/documentation_guidelines.csv",
          "value": "Risikobetrachtung"
        },
        {
          "name": "result",
          "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/result.csv",
          "value": "eine dedizierte Risikobetrachtung von Geschäftsprozessen oder Informationen mit hohem Schutzbedarf"
        },
        {
          "name": "result_specification",
          "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/result.csv",
          "value": "entsprechend der gewählten Methodik für das Informationssicherheitsrisikomanagement"
        },
        {
          "name": "action_word",
          "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/action_words.csv",
          "value": "ausführen"
        },
        {
          "name": "modal_verb",
          "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/modal_verbs.csv",
          "value": "MUSS"
        }
      ],
      "prose": "Governance und Compliance MUSS eine dedizierte Risikobetrachtung von Geschäftsprozessen oder Informationen mit hohem Schutzbedarf entsprechend der gewählten Methodik für das Informationssicherheitsrisikomanagement ausführen."
    },
    {
      "id": "GC.7.2_gdn",
      "name": "guidance",
      "prose": "Diese Anforderung stellt den Aussprungpunkt in die Risikobetrachtung dar, deren konkrete Ausgestaltung nicht durch den GS++ vorgegeben wird. Gängige Standards als Basis für ein Risikomanagement sind die ISO27005, die ISO31000 oder der BSI Standard 200-3."
    }
  ],
  "props": [
    {
      "name": "alt-identifier",
      "value": "c86010f0-6e07-429a-a203-529ebdc6c99a"
    },
    {
      "name": "sec_level",
      "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/security_level.csv",
      "value": "normal-SdT"
    },
    {
      "name": "effort_level",
      "ns": "https://github.com/BSI-Bund/Stand-der-Technik-Bibliothek/tree/main/documentation/namespaces/effort_level.csv",
      "value": "0"
    }
  ],
  "title": "Geschäftsprozesse mit hohem Schutzbedarf"
}