Overview - ISO/IEC 27013:2021 (Integrated ISMS & SMS)
ISO/IEC 27013:2021 provides guidance for the integrated implementation of an Information Security Management System (ISMS) (ISO/IEC 27001) and a Service Management System (SMS) (ISO/IEC 20000-1). It helps organizations that want to:
The standard focuses on aligning the service lifecycle and information security/cybersecurity and privacy protection to avoid duplication, reduce cost, and improve operational efficiency.
Key topics and technical requirements
ISO/IEC 27013:2021 does not reproduce clause text from the normative standards but provides practical mapping and guidance around overlapping and differing areas. Key topics include:
- Overview and comparison of ISO/IEC 27001 and ISO/IEC 20000‑1 concepts and terminology (references ISO/IEC 27000:2018).
- Approaches for integrated implementation, including scope considerations and typical pre‑implementation scenarios.
- Integrated implementation considerations covering technical and process areas such as:
- requirements and controls alignment,
- assets and configuration items,
- service design and transition,
- risk assessment and risk management,
- supplier/third‑party risk,
- incident, problem, major incident management, and evidence collection,
- classification, escalation and change management.
- Potential gains from integration: service level management, continual improvement, capacity, continuity and availability, release and deployment management.
- Informative annexes mapping clauses and controls between ISO/IEC 27001:2013 and ISO/IEC 20000‑1:2018, plus term comparisons.
Practical applications and users
ISO/IEC 27013 is practical guidance for:
- CISOs, CIOs and IT service managers planning integrated ISMS and SMS deployments.
- Compliance and risk officers harmonizing security and service requirements.
- Managed service providers (MSPs), auditors and consultants implementing or assessing combined management systems.
- Organizations of all sizes using technology and digital services that need coordinated cybersecurity, privacy protection and service delivery.
Benefits include stronger credibility for secure services, lower implementation and audit costs, faster deployment, improved communication and reduced duplication of effort.
Related standards
Keywords: ISO/IEC 27013:2021, integrated implementation, ISMS, SMS, ISO/IEC 27001, ISO/IEC 20000‑1, information security, service management, cybersecurity, privacy protection, risk management, incident management.