ISO/IEC 27013:2021
Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1
Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 60
- Дата публикации:
- 25 ноября 2021 г.
- Издание:
- ISO/IEC IS 27013 edition 3 version 1
- ICS:
- 03.080.99
This document gives guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 for organizations intending to: a) implement ISO/IEC27001 when ISO/IEC 20000-1 is already implemented, or vice versa; b) implement both ISO/IEC27001 and ISO/IEC 20000-1 together; or c) integrate existing management systems based on ISO/IEC27001 and ISO/IEC 20000-1. This document focuses exclusively on the integrated implementation of an information security management system (ISMS) as specified in ISO/IEC 27001 and a service management system (SMS) as specified in ISO/IEC 20000-1.
Abstract
Overview - ISO/IEC 27013:2021 (Integrated ISMS & SMS)
ISO/IEC 27013:2021 provides guidance for the integrated implementation of an Information Security Management System (ISMS) (ISO/IEC 27001) and a Service Management System (SMS) (ISO/IEC 20000-1). It helps organizations that want to:
- implement ISO/IEC 27001 when ISO/IEC 20000‑1 is already in place (or vice versa),
- implement both standards concurrently, or
- integrate separate management systems based on ISO/IEC 27001 and ISO/IEC 20000‑1.
The standard focuses on aligning the service lifecycle and information security/cybersecurity and privacy protection to avoid duplication, reduce cost, and improve operational efficiency.
Key topics and technical requirements
ISO/IEC 27013:2021 does not reproduce clause text from the normative standards but provides practical mapping and guidance around overlapping and differing areas. Key topics include:
- Overview and comparison of ISO/IEC 27001 and ISO/IEC 20000‑1 concepts and terminology (references ISO/IEC 27000:2018).
- Approaches for integrated implementation, including scope considerations and typical pre‑implementation scenarios.
- Integrated implementation considerations covering technical and process areas such as:
- requirements and controls alignment,
- assets and configuration items,
- service design and transition,
- risk assessment and risk management,
- supplier/third‑party risk,
- incident, problem, major incident management, and evidence collection,
- classification, escalation and change management.
- Potential gains from integration: service level management, continual improvement, capacity, continuity and availability, release and deployment management.
- Informative annexes mapping clauses and controls between ISO/IEC 27001:2013 and ISO/IEC 20000‑1:2018, plus term comparisons.
Practical applications and users
ISO/IEC 27013 is practical guidance for:
- CISOs, CIOs and IT service managers planning integrated ISMS and SMS deployments.
- Compliance and risk officers harmonizing security and service requirements.
- Managed service providers (MSPs), auditors and consultants implementing or assessing combined management systems.
- Organizations of all sizes using technology and digital services that need coordinated cybersecurity, privacy protection and service delivery.
Benefits include stronger credibility for secure services, lower implementation and audit costs, faster deployment, improved communication and reduced duplication of effort.
Related standards
- ISO/IEC 27001:2013 - Information security management system (ISMS) requirements
- ISO/IEC 20000‑1:2018 - Service management system (SMS) requirements
- ISO/IEC 27000:2018 - Overview and vocabulary for ISMS
Keywords: ISO/IEC 27013:2021, integrated implementation, ISMS, SMS, ISO/IEC 27001, ISO/IEC 20000‑1, information security, service management, cybersecurity, privacy protection, risk management, incident management.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27013:2021
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
BS ISO/IEC 20000-10:2018
ДействующийInformation technology. Service management. Concepts and vocabulary.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…