This document provides guidance to users of BS 7799-2:2002 and the code of practice, BS 7799-1:2000 (ISO/IEC 17799). PD 3001 provides guidance on the ‘Plan, Do, Check, Act’ model and the information security management system (ISMS) process requirements, certification process and preparing for certification.