 | BS 7799: Encyclopedia - BS 7799
BS 7799
BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in 1995. It was written by the United Kingdom Government's Department of Trade and Industry (DTI), and after several revisions, was eventually adopted by ISO as ISO 17799, "Information Technology - Code of practice for information security management." in 2000. ISO 17799 was most recently revised in June 2005.
A second part to BS7799 was first published by BSI in 1999, known as BS 7799 Part 2, titled "Information Security Management Systems - Specification with guidance for use." BS 7799-2 focused on how to implement an Information Security Management System (ISMS), referrering to the information security management structure and controls identified in ISO 17799. The 2002 version of BS 7799-2 introduced the Plan-Do-Check-Act (PDCA) (Deming quality assurance model), aligning it with quality standards such as ISO 9000. BS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005.
Certification/registration of an organisation's ISMS against ISO 27001 is one means of providing assurance that the certified/registered organisation has implemented a system for the management of information security in line with the standard. In some countries, the bodies which verify conformity of ISMS to specified standards are called "certification bodies", in others "registration bodies", in others "assessment and registration bodies", or "certification/ registration bodies", and in others still, "registrars".
ISO 27001 certification usually involves a two-stage audit process:
Stage 1 is a "table top" review of the existence and completeness of key documentation like the Security Policy, Statement of Applicability, Information Security Management System (ISMS).
Stage 2 is a detailed, in-depth audit involving testing the existence and effectiveness of the controls stated in the ISMS as well as their supporting documentation.
BS7799-3 was due to be published late in 2005. It will cover risk analysis and management, and will align particularly with ISO 27001.
BS 7799 - Reference
- ISO/IEC 17799:2005
- ISO/IEC 27001:2005
Other related archives1995, 1999, 2000, 2002, 2005, British Standards Institute, ISO, ISO 17799, ISO 9000, PDCA, United Kingdom
 Adapted from the Wikipedia article "BS 7799", under the G.N U Free Docmentation License. Please also see http://en.wikipedia.org/wiki |