Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 16 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - ISO 17799 2005 Released Today
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

ISO 17799 2005 Released Today

 
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate
View previous topic :: View next topic  
Author Message
Jade5
Guest





PostPosted: Fri Jun 17, 2005 10:08 pm    Post subject: ISO 17799 2005 Released Today Reply with quote

Just a quick heads up: The new version of ISO 17799 has finally been published.

For anyone unaware, this has been worked on for quite a long time, and replaces the 2000 edition with immediate effect.

It includes an extra chapter, and much of the existing content has been re-worked or extended.

It's available from the usual places, incuding BSI's 'Standards Direct' (standardsdirect.org/iso17799.htm) and as part of the ISO 17799 Toolkit (iso17799-made-easy.com).

Jade
Back to top
lemp
Newbie
Newbie


Joined: Jun 12, 2005
Posts: 1

PostPosted: Sun Jun 19, 2005 1:33 pm    Post subject: Reply with quote

Hi Jade.

How does this release impact to the BS 7799:2 registration process?. Do we have to wait for BS7799:2:2005?

Best Regards

-luis
Back to top
View user's profile Visit poster's website
Jade5.
Guest





PostPosted: Sun Jun 19, 2005 5:37 pm    Post subject: Reply with quote

Luis,

I've looked at this and there seems to be no impact on the registration process.

However, the new ISO 17799 does seem to prepare some ground for the new release of BS7799, which as you may be aware, is expected later this year.

So basically, no change... yet.


Jade
Back to top
Knersus
Guest





PostPosted: Mon Jul 04, 2005 9:24 pm    Post subject: Impact of BS ISO/IEC 27001:2005 standard on certification Reply with quote

If your planned date of certification occurs before release of the New Standard, your Statement of Applicability must conform to the Old Standard for your certification.
If your planned date of certification is after release of the standard, your Statement of Applicability will need to conform to the New Standard at certification. Any current ISMS projects aimed at achieving certification after release of the New Standard should consider starting the conversion process now.
If you have an existing ISMS which is due for re-certification after the release of the New Standard, you will have to convert your ISMS so that it complies with the New Standard before you can be re-certified.

Best regards,

Knersus
Back to top
whiteHippo
Newbie
Newbie


Joined: Sep 04, 2005
Posts: 2

PostPosted: Mon Sep 05, 2005 4:49 pm    Post subject: Impact of BS ISO/IEC 27001:2005 standard on certification Reply with quote

hi Knersus,

Any official note regarding the certification process that you'd mentioned?

cheers,
lorraine
Back to top
View user's profile
Mastman888
Newbie
Newbie


Joined: Sep 16, 2005
Posts: 10

PostPosted: Fri Sep 16, 2005 11:50 pm    Post subject: Reply with quote

The certification (or re-certification) process will be similar to that of the ISO 9000:94 to 9000:2000 transition. At some point the "old" certificates will cease to be valid and the ISMS will eventually need to be adjusted to the new standard (Quote from BSI: "Once BS ISO/IEC 27001 is published the old BS 7799-2:2002 will be withdrawn. For those certified to BS 7799-2 there will be a transition period.")

So:
- If you're already audited/certified according to BS7799-2:2002 you will have enough time to adjust your ISMS to the 27001 requirements.
- If you're near completion of your ISMS and are planning an audit/cert, I would suggest waiting for the 27001, adjust your ISMS (based on 17799:2005) and going for the new standard certificate. This would be much easier than re-working a BS7799-2 certified ISMS.
- If you're in the early stages, there's no real problem as you are probably using the 2005 version of 17799 and have plenty of time to create your ISMS according to the new standards and requirements.

Hope this helps.

Rob
CISSP
Back to top
View user's profile
whiteHippo
Newbie
Newbie


Joined: Sep 04, 2005
Posts: 2

PostPosted: Sat Sep 17, 2005 6:54 pm    Post subject: Reply with quote

Thanks Rob for the clear explanation.

For those just got certified to BS7799-2:2002, what is the transition period to BS ISO/IEC 27001?

cheers,
lorraine
Back to top
View user's profile
Mastman888
Newbie
Newbie


Joined: Sep 16, 2005
Posts: 10

PostPosted: Tue Sep 27, 2005 11:06 pm    Post subject: Reply with quote

lorraine,
Judging from the 9000 transition, there should be ample time. The 9000:2000 standard was released in December 2000 and all "old" certificates (1994-based) ceased to be valid on 1/1/2003, so that gave people a good two years to adjust.
Also, note that 27001 has not been released yet (expected November 2005), so as soon as that happens, there will be more definite transition-end dates both from BS and ISO.
If I were you though, I would start planning the initial "generic" steps of the transition (assuming from your question that you have recently certified an ISMS). This may also include transition presentations/training offered by most national standards bodies or reputable certification bodies (BS and BVQI respectively pop to mind). These sessions are usually a day long and include mappings of the differences between the old and new standards and you get a pretty good idea of what the transition is all about (and how auditors will handle it!).

Cheers,
Rob, CISSP
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.