BS 7799 The Code of Practice for information security management

William List · The Computer Bulletin · 1995

The Code of Practice was issued in September 1993 by the DTI and BSI. After minor modifications, it became British Standard in February 1995 (No. BS7799). This standard has been forwarded to ISO for consideration as an international standard. The Standard describes its objectives as follows: To provide a common basis for companies to develop, implement and measure effective security management practice. To provide confidence in inter-company trading. The Standard is a code: it is not a detailed standard like many IT standards (for example EDIFACT message standards, X25, etc.). It is a compilation of controls applicable in mainly IT environments and constitutes a set of baseline security controls. Certain controls are described as Key Controls (see p. 9) which every organisation should have. The remainder of the baseline is only applicable where appropriate to the processing in organisations. The Standard is not all encompassing therefore it is expected that organisations will implement additional procedures to meet their specific requirements

Read the paper · More papers on PaperTik