|
BS7799-3 is designed to support the requirements of ISO 27001, the specification for an information management system. ISO 27001 is also, of course, the foundation for certification and audit for information security management.
The BS7799-3 publication covers the ground of various previous documents in the 'PD' series, notably PD 3002 and PD 3005. It's focus is risk management... particularly in the context of business risk. Ultimately it is expected that this standard will become ISO 27005, although no time table is in place for this idea.
BS7799-3 is expected to be published very late in 2005, or early in 2006
NOTE: The PD Series
The PD series, significant parts of which will from BS7799-3, comprised the following:
PD 3001 - Preparing for BS 7799-2 Certification
PD 3002 - Guide to BS 7799 Risk Assessment
PD 3003 - Are You Ready for a BS 7799-2 Audit?
PD 3004 - Guide to the Implementation and Auditing of BS 7799 Controls
PD 3005 - Guide on the Selection of BS 7799-2 Controls
|