BSI 21/30398709 DC:2020 Edition
$13.70
BS ISO/IEC 27013. Information security, cybersecurity and privacy protection. Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1
Published By | Publication Date | Number of Pages |
BSI | 2020 | 63 |
This document provides guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 for those organizations that are intending to either
-
implement ISO/IEC 27001 when ISO/IEC 20000-1 is already implemented, or vice versa,
-
implement both ISO/IEC 27001 and ISO/IEC 20000-1 together, or
-
integrate existing management systems based on ISO/IEC 27001 and ISO/IEC 20000-1.
This document focuses exclusively on the integrated implementation of an information security management system (ISMS) as specified in ISO/IEC 27001 and a service management system (SMS) as specified in ISO/IEC 20000-1. In practice, ISO/IEC 27001 and ISO/IEC 20000-1 can also be integrated with other management system standards, such as ISO 9001 and ISO 14001.
Annex A of this document provides a comparison of content at a clause level between ISO/IEC 27001 and ISO/IEC 20000-1.
Annex B of this document provides a comparison of topics between the requirements specified in ISO/IEC 20000-1 and the controls in ISO/IEC 27001, Annex A.
Annex C of this document provides a comparison of:
-
terms defined in ISO/IEC 27000, the glossary for the ISO/IEC 27000 family of standards;
-
terms defined or used in ISO/IEC 20000-1.