Search
Topics
  Create an account Home  ·  Topics  ·  Downloads  ·  Your Account  ·  Submit News  ·  Top 10  
Modules
· Home
· Downloads
· FAQ
· Feedback
· Forums
· Papers
· Statistics
· Surveys
· Top 10
· Topics
· Web Links
· Your Account

Who's Online
There are currently, 22 guest(s) and 0 member(s) that are online.

You are Anonymous user. You can register for free by clicking here

ISO17799 Search



Languages
Select Interface Language:


ISO 17799 Resources
There are now quite a few BS7799, ISO27001 and ISO 17799 portals on the web offering commercial tools & products. Possibly the most complete is ISO 17799 and ISO 27001 Central.

Call for Papers
We are shortly to launch a content section for papers and articles on ISO 17799 implementation, BS7799, AS4444, ISO 27001, UNE71502, and information security generally. If you have produced a paper and would like us to publish it, please contact us via the feedback form above.

ISO 27001, ISO 27002 & ISO17799 User Group: Forums

17799.Com :: View topic - Certification against BS/ ISO
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

Certification against BS/ ISO

 
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate
View previous topic :: View next topic  
Author Message
NMS
Newbie
Newbie


Joined: Nov 01, 2006
Posts: 1

PostPosted: Thu Nov 02, 2006 1:49 am    Post subject: Certification against BS/ ISO Reply with quote

Folks - this is my first post to this forum.

I heard that organizaions can only be certified against 27001. They why we have BS17799? why two of them for the same purpose?

Please foucs some more light on this.

Thanks in advance
Back to top
View user's profile
SecAdmin
Newbie
Newbie


Joined: Jul 24, 2004
Posts: 26

PostPosted: Thu Nov 02, 2006 7:37 am    Post subject: Reply with quote

The situation is straight forward: ISO 27001 replaced BS7799-2 last year (2006).
Back to top
View user's profile
Vonnie
Newbie
Newbie


Joined: Jan 04, 2007
Posts: 16
Location: UK

PostPosted: Tue Jan 30, 2007 3:05 am    Post subject: Reply with quote

ISO27001 is what you certify to. It has statements such as 'Shall', it is black and white and if you dont meet the requirements of the standard you dont 'pass'. It does make some very good points and requires the development of a Risk Strategy & Treatment Plan etc...

ISO17799 provides the Code of Practice, and provides statements such as 'should' giving you the chance to choose what you implement as 'best practice', this can be used as guidance for 'compliance to'.
You cannot certify to ISO17799.

Hope that helps!
Back to top
View user's profile Visit poster's website
Calvin
Newbie
Newbie


Joined: Aug 30, 2005
Posts: 39

PostPosted: Tue Jan 30, 2007 4:13 am    Post subject: Reply with quote

Just to add...we still have BS7799 (not BS17799) around because a lot of companies are upgrading the certification to ISO27001.

However new certifcations are only given for ISO27001. (correct me if I am wrong here)

Calvin
Back to top
View user's profile
Vonnie
Newbie
Newbie


Joined: Jan 04, 2007
Posts: 16
Location: UK

PostPosted: Tue Jan 30, 2007 4:40 am    Post subject: Reply with quote

Yep BS7799 (part 1) certifications are still valid, but companies can choose to move to ISO27001 or sit out until their certification expires.

ISO17799:2000 was updated to ISO17799:2005, but it too will change its name again to ISO27002 IN LATE 2007/8.!! Shocked
Back to top
View user's profile Visit poster's website
Coffeeman
Newbie
Newbie


Joined: Jun 30, 2009
Posts: 1

PostPosted: Wed Jul 01, 2009 5:11 am    Post subject: Reply with quote

Folks - this is my first post to this forum.

I heard that organizaions can only be certified against 27001. They why we have BS17799? why two of them for the same purpose?

Please foucs some more light on this.

Thanks in advance Embarassed
Back to top
View user's profile Visit poster's website
Rupert
Newbie
Newbie


Joined: Jul 12, 2009
Posts: 1

PostPosted: Mon Jul 13, 2009 12:44 pm    Post subject: ISO27002 Certification in Austrlia Reply with quote

Hi,

I am having problems in finding someone who can certify our organisation in Australia for ISO27002.

I have tried:
    PwC
    KPMG
    Standards Australia
    SAI Global
    JAS-ANZ
None of them certify in Australia.

Any Ideas?
Back to top
View user's profile
TomH
Newbie
Newbie


Joined: Sep 15, 2009
Posts: 1

PostPosted: Tue Sep 15, 2009 4:01 pm    Post subject: Reply with quote

Quote:
ISO17799:2000 was updated to ISO17799:2005, but it too will change its name again to ISO27002...


Yes ISO27002 is ISO17799:2005.

Also, ISO27002 maps directly to ISO27001 "Annex A" catalog of controls.

However...

ISO27001 Annex A uses "shall"
ISO27002 uses "should"

ISO27002 provides more information about each control. It provides implementation advice for the controls in ISO27001 Annex A.

Reading ISO27002 helps one to understand the "spirit and intent" of the controls in ISO27001 Annex A.

Thanks,

Tom
Back to top
View user's profile
Display posts from previous:   
Post new topic   Reply to topic    17799.Com Forum Index -> ISO17799 Discussion and Debate All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Powered by phpBB 2.0.8 © 2001 phpBB Group
phpBB port v2.1 based on Tom Nitzschner's phpbb2.0.6 upgraded to phpBB 2.0.4 standalone was developed and tested by:
ArtificialIntel, ChatServ, mikem,
sixonetonoffun and Paul Laudanski (aka Zhen-Xjell).

Version 2.1 by Nuke Cops © 2003 http://www.nukecops.com

Forums ©

 
The ISO 17799 Implementation Forum: A BS7799 / ISO27001, ISO17799 and ISO 27000 User Group
All logos and trademarks are property of their respective owner. Comments are property of their posters. The rest © 2005 ISO17799 / ISO 27002 Forum
AKA: BS 7799, SPE 20003, SS 627799, JIS X 5080, AS/NZS 4444, ISO 27001. Other links: UKAS accreditation body. SV
Website source phpnuke.org (c) 2003, and is Free Software under GNU / GPL licence. All Rights Are Reserved.