ISO 27001’s origin
ISO 27001 is a global standard that originated with the establishment of management standard BS 7799. The standard was split into two parts:
- Part 1: A code of practice that deals with controls and provides formally managed information security. It was adopted as ISO 17799 Information Technology – Code of Practice for Information Security Management in December 2000.
- Part 2: A specification for implementing the ISMS. It was first published by the British Standards Institution (BSI) in 1999 as Information Security Management Systems – Specifications with guidance for use. Later, in 2002, it was revised to introduce the Plan-Do-Check-Act (PDCA) quality assurance model.
As a standard for guiding the creation and implementation of an ISMS, BS 7799 was developed with the support of the UK Department of Trade and Industry (DTI). The BSI published BS 7799 in 1995. A key goal of BS 7799 was to allow an organization’s management...