Information security guidelines were used for various governmental organizations in the Netherlands. One organization called it the BIG (Baseline Information Security for Municipalities) the other BIR (Baseline Information Security for the Civil Service). Since January 2019, all these guidelines have been replaced by BIO - Baseline Information Security Government.
ISO 27001 is a standard for how information security can be structured in a process-based manner. It is a "high level structure" that is used within the scope of ISO 9001 (quality assurance) and ISO 14001 (environmental management).
BIO is a derivative of ISO 27001. ISO 27001 outlines what needs to be done, but in ISO 27002 you get extensive tools and action points to use when implementing. You can only get certified in ISO 27001 and not for ISO 27002. ISO 27002 is more like the manual for implementing ISO 27001.
Achieving ISO 27001 certification demonstrates that a company has: