The Elsmar Cove Forum and Site Map The Elsmar Cove Wiki More Free Files The Elsmar Cove Forums Discussion Thread Index Post Attachments Listing Failure Modes Services and Solutions to Problems Elsmar cove Forums Main Page Elsmar Cove Home Page

Go Back   The Elsmar Cove Forum > ISO (International Organization for Standardization) Standards > Other ISO and International Standards and European Regulations


The Elsmar Cove Forum SideBar!
Monitor the Forum
Monitor New Forum Posts
New Threads Feeds
RSS FeedRSS Feed
Sponsor Link










$ Contributor Forum Access
Courtesy Quick Links

Links that Elsmar Cove visitors will find useful in your quest for knowledge:


Howard's International Quality Services

Atul's Symphony Technologies

Dave Scott's Scott Quality Solutions

Praxiom Research Group


NIST's Engineering Statistics Handbook

IRCA - International Register of Certified Auditors

SAE - Society of Automotive Engineers

Quality Digest Portal

IEST - Institute of Environmental Sciences and Technology

ASQ - American Society for Quality


All the Important Standards and Related Web Sites in the World
Reply
 
Thread Tools Search this Thread Rate Thread Content Display Modes
  #1  
Old 9th February 2004, 02:41 PM
venkat venkat is offline
Involved - Posts

Registration Date: Feb 2002
Location: India/Chennai
Age: 42
 
Posts: 41
Thanks Given to Others: 1
Thanked 0 Times in 0 Posts
Karma Power: 32
Karma: 25
venkat has less than 100 Karma points so far.
Read This! ISO 17799 and BS 7799 - Security Standards - ISMS is not a quality standard

There has been a misconception that ISMS is a quality management system, which is not so.
Though BS7799 borrows some of the practices of ISO 9001:2000 standard this is essentially not a QMS.
Moreover the Information Security Manager reports to the top management. A person wielding a MR post cannot hold a post of Information Security Manager because there will be a conflict of interest.
Kindly request you to send your inputs on this

Also is it possible to use six sigma for BS 7799
__________________
venkat
Reply With Quote

Sponsored Links
  #2  
Old 9th February 2004, 04:46 PM
Marc's Avatar
Marc Marc is offline
Your Elsmar Cove Host

Registration Date: Jan 1996
Location: West Chester, Ohio - USA
Age: 59
 
Posts: 15,860
Thanks Given to Others: 1,896
Thanked 1,570 Times in 1,021 Posts
Blog Entries: 4
Karma Power: 605
Karma: 11579
Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.
Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.Marc is appreciated, and has over 1700 Karma points.
Send a message via AIM to Marc Send a message via Skype™ to Marc
Lurker

For those like me who didn't know (I'm not sure what ISMS is, but...):

BS7799 is a security standard.

ISO 17799 is the most widely recognised security standard. It is based upon BS7799, which was last published in May 1999, an edition which itself included many enhancements and improvements on previous versions. The first version of ISO 17799 was published in December 2000.

ISO17799 is comprehensive in its coverage of security issues. It contains a substantial number of control requirements, some extremely complex. Compliance with ISO 17799, or indeed any detailed security standard, is therefore a far from trivial task, even for the most security conscious of organizations. Certification can be even more daunting.

It is recommended therefore that ISO 17799 is approached step by step. The best starting point is often an assessment of the current position, followed by identification of what changes are needed for ISO17799. From here, planning and implementation must be undertaken.
__________________
A Search is a terrible thing to waste!
One Test is Worth 1000 Expert Opinions - The plural of anecdote is not data.
We can't solve problems by using the same kind of thinking we used when we created them. - Unknown
Reply With Quote
Sponsored Links

  #3  
Old 1st March 2004, 11:00 AM
SaraHol SaraHol is offline
Inactive Registered Visitor

Registration Date: Mar 2004
Location: UK
 
Posts: 2
Thanks Given to Others: 0
Thanked 0 Times in 0 Posts
Karma Power: 24
Karma: 10
SaraHol has less than 100 Karma points so far.
Default Quoting Sources

Marc: When you do a post like that, quoting pretty much word for word from an existing web site, the least you should really do is quote the source.

I thought it was kinda familiar, and found it at
Security Policy World

with URL
http://www.information-security-poli...o17799desc.htm

It's not a big issue, but it's a good habit to get into.

All the best
Reply With Quote
  #4  
Old 1st March 2004, 02:38 PM
Sidney Vianna's Avatar
Sidney Vianna Sidney Vianna is offline
Post responsibly

Registration Date: Oct 2001
Location: Long Beach, CA - USofA
 
Posts: 4,953
Thanks Given to Others: 688
Thanked 1,912 Times in 1,083 Posts
Karma Power: 467
Karma: 16797
Sidney Vianna is appreciated, and has over 1700 Karma points.
Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.
Default All the MS's

Quote:
Originally Posted by Marc

For those like me who didn't know (I'm not sure what ISMS is, but...):

Information Security Management Systems.

There are both an International and US based ISMS Users Group.

Check Information Security Management Systems (ISMS) Users Group
__________________
Fighting organizational dysfunction, one post at a time.

Last edited by Sidney Vianna; 1st March 2004 at 07:25 PM.
Reply With Quote
  #5  
Old 15th December 2004, 05:37 AM
pargovind pargovind is offline
Shy Poster (1 to 5 Posts)

Registration Date: Dec 2004
Location: India, Tamilnadu, Chennai
 
Posts: 1
Thanks Given to Others: 0
Thanked 0 Times in 0 Posts
Karma Power: 21
Karma: 10
pargovind has less than 100 Karma points so far.
BIG Smile BS 7799-2 in the USA

Hello,

The ISO 17799 Standards are not Certifying standards, whereas Certification can be obtained under BS-7799-2 Standards. Still, a Company can always seek certification under ISO 17799 Standards. But such a certification does not have any seal of authority from a Certifying Agency.

I understand that, in the US, most companies have been reluctant to get BS 7799-2 certification, but that it is picking momentum now, though slowly.

Could anybody confirm my perceptions?

Govind Srinivasan
Chennai India
Reply With Quote
  #6  
Old 18th January 2005, 10:03 PM
Mr BS7799's Avatar
Mr BS7799 Mr BS7799 is offline
Inactive Registered Visitor

Registration Date: Jan 2005
Location: Philippines
Age: 36
 
Posts: 11
Thanks Given to Others: 0
Thanked 0 Times in 0 Posts
Karma Power: 20
Karma: 20
Mr BS7799 has less than 100 Karma points so far.
Default

There are two standards under the ISO/BS world that pertains to information security. ISO/IEC 17799:2000 and BS 7799-2:2002.

The closest analogy I could make for these two are the ISO 9001:2000 and ISO 9004:2000.

ISO/IEC 17799:2000 provides guidance in implementing BS 7799 controls
(should, henceforth not mandatory)

BS 7799-2:2002 provides the requirements to achieve an ISMS
(shall, mandatory)

Mr Pargovind is correct that certification can be only be issued for BS 7799. But organizations, can still be "compliant" to ISO/IEC 17799.

Lastly, BS 7799-2:2002 will become an ISO standard by 2nd quarter of this year. It shall have the name ISO 24742:2005.

IMHO, reluctance of American companies probably stems from the fact the BS7799 is a British Standard. The momentum increase could "probably" be attributed to the impending release of ISO 24742:2005.

Warm regards to all the members and contributors!!!
__________________
Quis custodiet ipsos custodes. "Who will guard the guardians?"
Reply With Quote
  #7  
Old 20th June 2005, 01:18 PM
Sidney Vianna's Avatar
Sidney Vianna Sidney Vianna is offline
Post responsibly

Registration Date: Oct 2001
Location: Long Beach, CA - USofA
 
Posts: 4,953
Thanks Given to Others: 688
Thanked 1,912 Times in 1,083 Posts
Karma Power: 467
Karma: 16797
Sidney Vianna is appreciated, and has over 1700 Karma points.
Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.
Default

Quote:
Originally Posted by Mr BS7799

Lastly, BS 7799-2:2002 will become an ISO standard by 2nd quarter of this year. It shall have the name ISO 24742:2005.
Looks like BS7799-2 will become ISO/IEC 27001, Information security management system (ISMS) requirements, which can be used for certification.

http://www.iso.org/iso/en/commcentre...05/Ref963.html

Ref.: 963
20 June 2005

Improved ISO/IEC 17799 makes information assets even more secure

An improved version of the joint ISO/IEC standard that has become the burgeoning e-commerce community’s international benchmark for information security management has just been published.

The revised ISO/IEC 17799, Information technology – Security techniques – Code of practice for information security management, integrates the latest developments in the field to maintain it as the international standard code of practice.

The modern interconnected e-commerce environment, with information now exposed to a growing number and a wider variety of threats and vulnerabilities, is the main beneficiary of the standard.

Ted Humphreys, Convenor of the ISO/IEC working group that developed ISO/IEC 17799:2005, said: “The revised version of this standard provides organizations with many state-of-the-art additions and improvements in information security best practice.

“For example, better management of security arrangements with external businesses, outsourcing and service providers, enhanced indicant handling capability, dealing with problems of patch management, mobile devices, wireless technologies and harmful mobile code via the Internet, improvements in best practice managing human resources and several other new features.”

ISO/IEC 17799:2005 is a code of practice for information security management. It is not a certification standard and was neither designed, nor is it suitable for this purpose. It will be followed in the last quarter of the year (publication currently expected in November 2005) by the specification standard ISO/IEC 27001, Information security management system (ISMS) requirements, which can be used for certification.

The new version addresses the security of information in its widest sense, providing best business practice, guidelines and general principles for implementing, maintaining and managing information security in any organization, producing and using information in any form.

Any organization has assets, essential to its continuity. Arguably, information in its various forms is the most important asset, be it printed, stored electronically, posted or e-mailed, shown on film or spoken. For most businesses, information security may be essential to maintain competitive edge, cash flow, profitability, legal compliance and commercial image. But many businesses and most non-business organizations may hold information as their only asset. An absence of information security may threaten their integrity and, therefore, very existence.

ISO/IEC 17799:2005 recognizes that the level of security that can be achieved purely through technical means is limited. The required level of security – established through assessing the levels of risk and associated costs through breaches of security, against the costs of implementing security – should always be driven by appropriate management controls and procedures. Information security management requires, as a minimum, participation by all employees in the organization. It may also require participation from shareholders, suppliers, third parties and customers.

ISO/IEC 17799:2005 identifies the controls that form the starting point for information security. It covers the critical success factors, the organization of information security, asset management, human resources, physical and environmental security, communications and operations management, information systems acquisition, development and maintenance, incident management, business continuity management and compliance. It is destined to become an essential tool for organizations of every type and size, whether public or private.

Ted Humphreys commented: “Users of this standard can also demonstrate to business partners, customers and suppliers that they are fit enough and secure enough to do business with, providing the chance for them to turn their investment in information security into business-enabling opportunities.

“In summary, this revised ISO/IEC 17799 is the most important of standard for managing information security that has been developed – it establishes a truly international common language for information security for all organizations around the world to engage with each other to do business.”

ISO/IEC 17799:2005, Information technology – Security techniques – Code of practice for information security management, costs 200 Swiss francs and is available from ISO national member institutes (see the complete list with contact details) and from ISO Central Secretariat (see below). It was developed by ISO/IEC Joint Technical Committee JTC 1, Information technology, Subcommittee SC 27, Security techniques, Working Group WG 1, Requirements, security services and guidelines.
__________________
Fighting organizational dysfunction, one post at a time.
Reply With Quote
  #8  
Old 7th July 2005, 07:19 PM
Sidney Vianna's Avatar
Sidney Vianna Sidney Vianna is offline
Post responsibly

Registration Date: Oct 2001
Location: Long Beach, CA - USofA
 
Posts: 4,953
Thanks Given to Others: 688
Thanked 1,912 Times in 1,083 Posts
Karma Power: 467
Karma: 16797
Sidney Vianna is appreciated, and has over 1700 Karma points.
Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.Sidney Vianna is appreciated, and has over 1700 Karma points.
Default http://www.free-press-release.com/news/200507/1120737392.html

Summary:

The final draft of the new security management standard, ISO 27001, has been released.

Website: ISO 17799 Newsletter: News & Updates for ISO 27001 and ISO17799

For_Immediate_Release:

Significant changes to major standards are rare and infrequent, to say the least. Two such changes to closely related standards even more so. However, this scenario has recently occurred with respect to the information security standards.

Following hot on the heels of the publication of ISO 17799 2005, the final draft of ISO 27001 has now been produced.


WHAT IS ISO 27001?

ISO 27001 is the replacement for BS7799. This in turn is the 'sister publication' for ISO 17799. Whereas ISO 17799 is a 'code of practice', describing individual controls for potential implementation, BS7799 outlines the requirements for an Information Security Management System. In other words, it sets out a system for the management of information security, within which the controls described within ISO 17799 may be selected.

BS7799 is in fact the part of the standard set against which certification is granted. This mantle will be passed to ISO 27001 upon final publication.

The new (draft) version has incorporated a number of significant changes. It further 'harmonizes' the approach with other management standards, such as ISO 9001, and builds further upon the PDCA model (Plan-Do-Check-Act). However, the main driver in terms of timing seems to have been the urgent need for re-alignment with the new version of ISO 17799 (2005) as opposed to the old version (2000).


WHY A 'DRAFT' VERSION?

BS799 was submitted for 'fast track' to become an ISO standard some time ago. Even this process though is lengthy, requiring due process and consultation. It has now passed all the key voting stages, however, and final publication is expected later this year.

This of course presents something of a dilemma. BS7799 is not aligned properly with the current 2005 version of ISO 17799.

To address this, SNV (the Swiss national standards body) and BSI have offered a free upgrade to the final version, to those who purchase the draft version from their respective online shops (see below). This enables organizations to work with the final draft (known as the FDIS version), without having to re-purchase to obtain the copy with any i's dotted, and t's crossed.


WHY 27001?
Major topic based standards tend to be grouped together in terms of a series. Typical of this is the ISO 9000 series (quality management) and the ISO 14000 series (environmental management). 27000 has been earmarked for the information security management series.

The first publication within this series is of course 27001. However, it is envisaged that eventually ISO 17799 will be renumbered as ISO 27002. A new document, for security measurement and metrics, is being produced for potential publication as ISO 27004.


OFFICIAL SOURCES

SNV: The Swiss national standards body, SNV, offer ISO 27001 FDIS from the following site:
ISO 17799 and ISO 27001 Information Security - Standards Online

BSI: Through the StandardsDirect outlet, BSI offer the draft standard from the following page:
ISO 27001 and ISO 17799 Information Security Standards - Standards Direct

A special version of the ISO 17799 Toolkit, the standard's support and starter kit, which includes the new standard (draft), is available via both these sites.

Both the above versions are currently in English language only.
__________________
Fighting organizational dysfunction, one post at a time.
Reply With Quote
Reply

Lower Navigation Bar
Go Back   The Elsmar Cove Forum > ISO (International Organization for Standardization) Standards > Other ISO and International Standards and European Regulations

Bookmarks


Visitors Currently Viewing this Thread: 1 (0 Registered Visitors and 1 Unregistered Guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Forum Search
Display Modes Rate Thread Content
Rate Thread Content:

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Discussion Threads
Discussion Thread Title Thread Starter Forum Replies Last Post or Poll Vote
BS 7799-3 Security Risk Standard Published ISOgal Other ISO and International Standards and European Regulations 1 2nd April 2006 10:36 PM
BS 7799 and ISO 17799 document and records - Security Information Arte Records and Data - Quality, Legal and Other Evidence 12 24th April 2005 10:55 AM
ISMS, ITIL, ISO and others - BS7799 is interpreted as a quality standard venkat Various Other Specifications, Standards, and related Requirements 4 18th January 2005 11:47 AM
BS ISO/IEC 17799:2000 - Code of practice for information security management Brian Dowsett Software Quality Assurance 5 3rd August 2004 06:13 AM
IT security subjects - Auditor suggested we implement BS 7799 meserret Various Other Specifications, Standards, and related Requirements 2 17th May 2001 08:42 AM



The time now is 03:07 PM. All times are GMT -4.
The time zone can be changed in your UserCP --> Options.



   

All Y'All Come Back Now, Y' Hear?

Made With A Mac! FreeBSD OS Powered by Apache!
Using php4 Forums provided and maintained by Marc Smith Database by MySQL

FAIR USE and CORRECTNESS NOTICE: This site contains copyrighted material the use of which has not always been specifically authorized by the copyright owner. We are making such material available in our efforts to advance understanding of environmental, political, human rights, economic, democracy, scientific, and social justice issues, etc. We believe herein constitutes a 'fair use' of any such copyrighted material as provided for in section 107 of the US Copyright Law. In accordance with Title 17 U.S.C. Section 107, the material on this site is distributed without profit to those who have expressed a prior interest in receiving the included information for research and educational purposes. For more information go to: http://www.law.cornell.edu/uscode/17/ If you wish to use copyrighted material from this site for purposes of your own that go beyond 'fair use', you must obtain permission from the copyright owner. In addition, I do not guarantee the correctness of the content. The risk of using content from the Elsmar Cove web site and forums remains with the user/visitor.

Responsibility Statement: Each person is responsible for anything they post in the Elsmar Cove forum. Neither I, Marc Timothy Smith, nor any of the forum Moderators, are responsible for the content of posts people make. Liability for post content resides with the poster as does interpretation and/or acceptance and/or use of advice by the reader.

Complaints: If you have a complaint with a post in a forum discussion thread, including Content in general, fighting, flaming, copyright infringement, defamation and/or 'slander', please use the 'Report This Post Report This Post Button button which appears at the top of every post in every thread.

Site courtesy of:
Marc Timothy Smith - Cayman Business Systems, 8466 Lesourdsville-West Chester Road, West Chester, Ohio 45069-1929 - USA
(513) 341-6272

To contact me, click the Google Voice link below, enter Your Name and Your Phone Number and Google will ring your phone and connect you for free!

The Elsmar Cove Web Site is *CopyFree*
no new posts