The ISO 27000 Series of Standards.

This series of standards govern the setup and running of an Information Security Management System. They are not, in themselves, standards for achieving any given level of security, but for providing the tools to allow your business to be run according to the levels of security risk (and expenditure) you, your customers and your partners expect.

As well as the certification standard, the series provides advice on implementation, risk management and will include specialist standards for particular industry segments.

The UK Government "Manual of Protective Security" and Ministry of Defence JSP440 are both strongly based on this series, albeit currently on slightly out-of-date versions, therefore adherence to these standards provides a good basis for learning to deal with government protectively-marked material.