Skip to main content

ISO/IEC 27013:2015 - Information technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1

Archived
Published on: 10/10/2017 Last update: 22/10/2019

The standard advises users on the processes and supporting documentation required to implement an integrated dual management system, for example helping them to:
    Implement ISO/IEC 27001 when they have already adopted ISO/IEC 20000-1, or vice versa;
    Implement both ISO/IEC 27001 and ISO/IEC 20000-1 together from scratch or
    Align and coordinate pre-existing ISO/IEC 27001 and ISO/IEC 20000-1 management systems.
The standard proposes a framework for organizing and prioritizing activities, offering advice on:
    Aligning the information security and service management and improvement objectives;
    Coordinating multidisciplinary activities, leading to a more integrated and aligned approach ;
    A collective system of processes and supporting documents (policies, procedures etc.);
    A common vocabulary and shared vision;
    Combined business benefits to customers and service providers plus additional benefits arising from the integration of both management systems; and
    Combined auditing of both management systems at the same time, with the consequent reduction in audit costs.

Categorisation

Format
PDF
Status
Completed
Representation technique
Human Language