01 · 1995–2000
BS 7799 lineage
British information-security practice separated a control code from certifiable management-system requirements.
ASSURANCE DNA · INFORMATION SECURITY
A risk-based information-security management system for preserving confidentiality, integrity and availability through governance, treatment, operation and improvement.
Which information risks could prevent the promised service from remaining confidential, accurate and available?
It is an organisational management standard. A certificate cannot prove that the architecture, cloud configuration, people or suppliers proposed in one tender are secure. Source-bounded interpretation: no certification, protected text reproduction or award prediction.
LIVING EXPERIMENT · JOURNEY
A classified information object travels through bidder, partner, buyer and delivery boundaries. Unowned transfers break the path; verified controls preserve it.
ORIGIN × EVOLUTION × CURRENT PRACTICE
Technology, data, defence, financial, health, professional-services and public-sector supply organisations handling sensitive or operationally critical information.
01 · 1995–2000
British information-security practice separated a control code from certifiable management-system requirements.
02 · 2005
The management-system requirements became an international reference for information-security risk governance.
03 · 2013
The second edition aligned with modern management-system structure and made contextual risk treatment central.
04 · 2022–2024
The current edition modernised terminology and alignment with the contemporary control reference; the 2024 amendment added climate consideration.
A certificate is not evidence that every proposed architecture or supplier interface is secure. The bid must map its actual data, risks and residual decisions.
OFFICIAL SOURCE FRESHNESS MONITOR
Monthly official-source reachability and change review.
The check records source reachability and a content fingerprint. It does not silently change the page or claim that an edition changed.
PUBLICLY DESCRIBABLE ANATOMY
These are navigational interpretations, not substitute clauses. Use the official publication for normative wording.
Set the bid security scope around actual data, systems, interfaces, locations and parties.
Name security decision rights, risk acceptance authority and independent challenge.
Assess threat, vulnerability, consequence and likelihood, then select proportionate treatment.
Plan competence, awareness, communication and controlled security evidence.
Operate secure design, supplier, access, change, incident and continuity controls.
Define monitoring, audit, management review and contract-security reporting.
Contain incidents and nonconformities, remove causes and update risk treatment.
BEFORE × INTERVENTION × AFTER
A fictional service processes special-category data across buyer, prime, cloud and support-provider boundaries.
A worked assurance map, not a security certification or penetration-test result.
The response attaches a certificate and 94-control spreadsheet, but cannot show the data flow, risk owner or applicability of 17 inherited supplier controls.
The bid scopes the service, models data and trust boundaries, records risk treatment, checks supplier inheritance and names residual-risk acceptance.
Every security claim is linked to a risk, control owner, operating evidence and mobilisation test; non-applicable controls have an explicit rationale.
PROPORTIONATE IMPLEMENTATION
It is an organisational management standard. A certificate cannot prove that the architecture, cloud configuration, people or suppliers proposed in one tender are secure.
Flow map, treatment decisions, review note
Risk treatment, SoA mapping, residual acceptance
Control operation records, audits, management review
SOURCE TRAIL · REVIEWED 26 JUL 2026
Publication status can change. Exact conformity questions belong with the current licensed publication and competent assurance.
Current edition, public description, status and amendment
Open primary source ↗ISO/IECPublic explanation of ISMS purpose and use
Open primary source ↗UK NCSCPublic operational context for supplier interfaces
Open primary source ↗