This document provides guidance on the enterprise protective security architecture and the framework of protective security policies, processes and types of controls necessary to mitigate and manage security risks across the protective security domains, including:
security governance;
personnel security;
information security;
cybersecurity;
physical security.
This document is applicable for any organization.
BSI recommends this version of standard for organisations operating in or with the UK. The ISO edition is available here if required.