This guide addresses the topic of risk assessment in the context of BS 7799 and in particular the development and certification of BS 7799 information security and management systems. It aims at providing a common basis and understanding of the underlying concepts behind risk assessment and risk management, the terminology used, and the overall process and options for assessing and managing the risks.