Reference · information security

ISO/IEC 17799 to ISO/IEC 27000: A Short Overview

ISO/IEC 17799, "Information technology — Code of practice for information security management," began life as a British Standards Institution document, BS 7799, before being adopted by the International Organization for Standardization and the International Electrotechnical Commission. It set out a broad code of practice for organizational information security: policy, asset classification, personnel security, physical security, access control, and business-continuity planning, organized as a set of control objectives, not a rigid technical checklist. ISO itself still lists the withdrawn ISO/IEC 17799 framework in its catalog record, marked as replaced, never deleted outright.

From 17799 to the 27000 Family

In 2005 the standard was substantially revised, and in 2007 it was renumbered as ISO/IEC 27002, folding it into the newly established ISO/IEC 27000 family of information security management standards. That family is anchored by ISO/IEC 27001, which specifies the requirements for an information security management system (ISMS) that an organization can be formally certified against, with ISO/IEC 27002 supplying the detailed control guidance that supports it. The renumbering reflected a broader restructuring of ISO's security-standards catalog, not a change in the underlying subject matter — the control domains from the original 17799 code of practice carried forward largely intact.

Why the Standard Still Matters

Even though the ISO/IEC 17799 designation was formally retired, it remains a common reference point in security-compliance discussions because so much of the 27000-family control structure descends directly from it. Organizations pursuing ISO/IEC 27001 certification today are, in effect, building on a control framework whose lineage traces back to that original 1999-era code of practice, so the older designation still turns up in compliance documentation, audit checklists, and security-community discussion more than two decades later.

A Related Standard: BS 15000 and ISO/IEC 20000

Around the same period, a parallel British Standards Institution effort produced BS 15000, the first global standard specifically for IT service management, built to complement the ITIL framework's process guidance instead of duplicating it. Like 17799, it was later adopted internationally and renumbered — as ISO/IEC 20000 — and like the 27000 family, it retains the original standard's core structure while operating under a new designation. An organization running ISO/IEC 27001 for information security and ISO/IEC 20000 for service management is, in practice, certifying two adjacent but distinct disciplines against standards with a shared British-Standards lineage.

Frequently Asked Questions

Is ISO/IEC 17799 still a valid standard?

No. It was formally withdrawn and renumbered as ISO/IEC 27002 in 2007. ISO still lists the original record in its catalog, marked as replaced, but no organization can be certified against ISO/IEC 17799 today.

What is the difference between ISO/IEC 27001 and 27002?

ISO/IEC 27001 specifies the requirements for an information security management system (ISMS) that an organization can be formally certified against. ISO/IEC 27002 supplies the detailed control guidance that supports it — it is a reference, not a certifiable standard on its own.

Does BS15000 / ISO/IEC 20000 relate to ISO/IEC 27000?

They cover different ground. BS 15000, later standardized as ISO/IEC 20000, is the IT service management standard built to complement the ITIL framework. ISO/IEC 27000 is the information security management family. Both trace back to British Standards Institution originals, but they certify different things.

Why does the old "ISO 17799" name still show up in security discussions?

Because the 27000-family control structure descends directly from it: an organization pursuing ISO/IEC 27001 certification today is building on a control framework whose lineage traces back to that original 1999-era code of practice, so the retired name keeps turning up in older compliance documentation and audit checklists.