The international standard for information security is actually TWO
documents:
1) ISO 17799
This is in fact a code of practice: a series of best practice controls
carefully defined for selection.
2) BS7799 / ISO 27001
This is a standard for an information security management system, often
known as an ISMS. It is increasingly aligned with other management standards,
such as ISO 9000.
SECUREZONE
AND THE STANDARD
We will shortly be introducing an entire sub-site devoted to this standard.
This will include an FAQ, forum, a resource directory, and a range of other
sections.
In the
meantime, the following resources may be of use: