ISO/IEC 17799 to ISO/IEC 27000: A Short Overview
ISO/IEC 17799, "Information technology — Code of practice for information security management," began life as a British Standards Institution document, BS 7799, before being adopted by the International Organization for Standardization and the International Electrotechnical Commission. It set out a broad code of practice for organizational information security: policy, asset classification, personnel security, physical security, access control, and business-continuity planning, organized as a set of control objectives, not a rigid technical checklist. ISO itself still lists the withdrawn ISO/IEC 17799 framework in its catalog record, marked as replaced, never deleted outright.
From 17799 to the 27000 Family
In 2005 the standard was substantially revised, and in 2007 it was renumbered as ISO/IEC 27002, folding it into the newly established ISO/IEC 27000 family of information security management standards. That family is anchored by ISO/IEC 27001, which specifies the requirements for an information security management system (ISMS) that an organization can be formally certified against, with ISO/IEC 27002 supplying the detailed control guidance that supports it. The renumbering reflected a broader restructuring of ISO's security-standards catalog, not a change in the underlying subject matter — the control domains from the original 17799 code of practice carried forward largely intact.
Why the Standard Still Matters
Even though the ISO/IEC 17799 designation was formally retired, it remains a common reference point in security-compliance discussions because so much of the 27000-family control structure descends directly from it. Organizations pursuing ISO/IEC 27001 certification today are, in effect, building on a control framework whose lineage traces back to that original 1999-era code of practice, so the older designation still turns up in compliance documentation, audit checklists, and security-community discussion more than two decades later.
A Related Standard: BS 15000 and ISO/IEC 20000
Around the same period, a parallel British Standards Institution effort produced BS 15000, the first global standard specifically for IT service management, built to complement the ITIL framework's process guidance instead of duplicating it. Like 17799, it was later adopted internationally and renumbered — as ISO/IEC 20000 — and like the 27000 family, it retains the original standard's core structure while operating under a new designation. An organization running ISO/IEC 27001 for information security and ISO/IEC 20000 for service management is, in practice, certifying two adjacent but distinct disciplines against standards with a shared British-Standards lineage.