PRO+ Premium Content/Information Security magazine

Thank you for joining!
Access your Pro+ Content below.
July 2005

Perspectives: Lessons learned in BS 7799 certification

Earning the BS 7799 certification forces enterprises to get organized. Government regulations are forcing enterprises to develop repeatable, auditable security programs. Many security and risk managers are leaning on accepted standards to build umbrella security programs that encompass numerous best practices, demonstrate security, show repeatable processes for compliance and continual improvement, and better organize security efforts and budgets. My organization, the Bank of Montreal (BMO), is the first Canadian company to receive security certification under BS 7799, the British standard for security and the basis of ISO 17799. The ISO standard doesn't have a certification component, but, as we discovered, BS 7799 Part 2 provides a good framework for organizing security activities and maintaining regulatory compliance. Here are some of the lessons we learned during our certification process: Take the training. The BS 7799 certification bodies offer courses on attaining and maintaining certification—they're well worth the time....

Access this PRO+ Content for Free!

By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.

You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.

Features in this issue

  • Mission Impossible

    Seven ways to leverage your infrastructure against spyware.

  • All Aboard!

    To gain buy-in and support for your security policies, it's best to start at the top.

Columns in this issue






  • CIO Trends #6: Nordics

    In this e-guide, read how the High North and Baltic Sea collaboration is about to undergo a serious and redefining makeover to ...

  • CIO Trends #6: Middle East

    In this e-guide we look at the role of information technology as the Arabian Gulf commits billions of dollars to building more ...

  • CIO Trends #6: Benelux

    In this e-guide, read about the Netherlands' coalition government's four year plan which includes the term 'cyber' no fewer than ...