ISO/IEC 27013
ISO27k-aligned security awareness service

ISO/IEC 27013:2012 — Information technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 Status update July

Introduction

This standard provides guidance on implementing an integrated information security and IT service management system, based on both ISO/IEC 27001:2005 (ISMS) and ISO/IEC 20000-1:2011 (IT service management specification, derived from ITIL).

Scope and purpose

The standard advises users on the processes and supporting documentation required to implement an integrated dual management system, for example helping them to:

  • Implement ISO/IEC 27001 when they have already adopted ISO/IEC 20000-1, or vice versa;
  • Implement both ISO/IEC 27001 and ISO/IEC 20000-1 together from scratch (brave souls!); or
  • Align and coordinate pre-existing ISO/IEC 27001 and ISO/IEC 20000-1 management systems.

The standard proposes a framework for organizing and prioritizing activities, offering advice on:

  • Aligning the information security and service management and improvement objectives;
  • Coordinating multidisciplinary activities, leading to a more integrated and aligned approach (e.g. both donor standards specify incident management activities, with differing scopes for the incidents but otherwise quite similar);
  • A collective system of processes and supporting documents (policies, procedures etc.);
  • A common vocabulary and shared vision;
  • Combined business benefits to customers and service providers plus additional benefits arising from the integration of both management systems; and
  • Combined auditing of both management systems at the same time, with the consequent reduction in audit costs (we hope!).

The scope of this standard spans two ISO/IEC JTC1 subcommittees.  SC 27 and SC 7 collaborated to ensure that the information security and IT service management perspectives were both duly considered.

Two annexes compare the 27001 and 20000 standards side-by-side.

Status of the standard

The standard was published in October 2012.

Status update Juiy A project to revise the standard in line with the 2013 version of ISO/IEC 27001 is nearly finished, now at FDIS stage.  The second edition may be published during 2015.

Personal comments

Write out 1,000 times: “There is more to information security than securing IT.” 

I believe additional, pragmatic advice would help organizations implement ISO27k and ISO20k together, but changes in the second edition are mostly just updates and corrections.  It’s hard enough to guide and motivate a single ISO/IEC subcommittee to produce a formal standard: I suspect coordinating two subcommittees was even tougher!

Copyright © 2015 IsecT Ltd.