British Standard, US Standard or ISO Standard?


When coming to standardization, we face the common problem about who is eligible to release the standard. The standard in industrial product is easier than standard in policies or procedures. For the example, standard for video storage in VCR era. The competition between Betamax and VHS, or current competition in Digital Disc. Compare to standard in security such as BS17799 or ISO27001.

As you can see, the competition of industrial product standard is easier to be defined; who win the standard will be used by others. This easy because at the end the consumer who will buy the product is same: global society and nobody cares who release the standard.

Choosing the regulatory standard is really depend on the political situation in every country that using the standard. US Standard usually more effective in the country that it’s economical depend to US. And who follow British Standard maybe has an interaction more with British.

But if your company doesn't have any relation, which type of standard will you choose? Here is my suggestion.

1. Choose ISO first

International Standardization Organization (ISO),is the standard that already accepted worldwide. Usually ISO is an adaptation of British Standard (BS) or US Standard. ISO27001 for example is an adaptation from BS17799.

2. British Standard vs US Standard

When ISO is not available then you must choose between US or BS, in my opinion the best standard usually different depend on the area of standard. Business Continuity for an example. NIST-SP 800-34 compare to BS2599. Each standard completed others.

3. Mapping, avoid to much standard

When its coming to a lot of kind standard to adopt. One thing that you should do first is prepare the mapping process between each standard. So you don’t have to repeat the same activities

Any suggestion?


Trackback URL for this post:

http://www.securityprocedure.com/trackback/58