This series of standards govern the setup and running of an Information Security Management System. They are not, in themselves, standards for achieving any given level of security, but for providing the tools to allow your business to be run according to the levels of security risk (and expenditure) you, your customers and your partners expect.
As well as the certification standard, the series provides advice on implementation, risk management and will include specialist standards for particular industry segments.
The UK Government "Security Policy Framework" and Ministry of Defence JSP440 are both strongly linked to this series, therefore adherence to these standards provides a good basis for learning to deal with government protectively-marked material and is a requirement for handling material up to and including Impact Level 3.