Overview
ISO/IEC 27013:2021/Amd 1:2024 is an important amendment to the international standard offering guidance on the integrated implementation of ISO/IEC 27001:2022 and ISO/IEC 20000-1:2018. This update, published by ISO in 2024, aligns requirements and terminologies between the two widely recognized management system standards for information security management systems (ISMS) and IT service management systems (SMS).
The amendment clarifies the relationship between these standards, streamlines language by updating references to the 2022 version of ISO/IEC 27001, and enhances the practical application of controls and requirements to support organizations aiming to implement both standards cohesively. This supports a unified approach to safeguarding cybersecurity, privacy, and service management.
Key Topics
-
Integrated Implementation Guidance
Offers comprehensive advice on harmonizing ISO/IEC 27001’s ISMS and ISO/IEC 20000-1’s SMS, highlighting overlapping and unique requirements.
-
Updates to References
Replaces all ISO/IEC 27001:2013 references with the latest ISO/IEC 27001:2022, ensuring alignment with current best practices.
-
Clarification of Controls and Requirements
Explains the distinction between requirements (mandatory elements) and controls (often optional or risk-based), especially in ISO/IEC 27001 Annex A, and how these relate to SMS requirements.
-
Risk Treatment and Control Selection
Emphasizes the organization's responsibility to perform information security risk assessments and tailor controls accordingly, integrating security measures with IT service management processes.
-
Requirements on Change Management and Configuration Management
Updates and clarifies terms, stresses planned, documented control of changes to ISMS and IT services, and alerts to differences in ‘configuration management’ definitions between the two standards.
-
Annex Modifications
Detailed changes in annex tables showing the correspondence of clauses and terminology between ISO/IEC 27001:2022 and ISO/IEC 20000-1:2018, assisting in clearer understanding and practical usage.
Applications
Organizations adopting ISO/IEC 27013:2021/Amd 1:2024 guidance can effectively integrate their information security management systems (ISMS) with IT service management systems (SMS) to achieve:
- Enhanced coordination between security and service management teams
- Streamlined processes reducing duplication and operational conflicts
- Comprehensive risk management encompassing both information assets and IT services
- Improved compliance with legal, contractual, and regulatory requirements relevant to cybersecurity and privacy
- Strengthened change management practices aligned across ISMS and SMS
- Better service availability and continuity supported by integrated controls
This integration supports sectors such as finance, healthcare, telecommunications, and public services that require robust cybersecurity measures combined with reliable IT service delivery.
Related Standards
-
ISO/IEC 27001:2022 – Information Security Management Systems - Requirements
The core standard setting out requirements for establishing, implementing, maintaining, and continually improving an ISMS with a focus on information security risks.
-
ISO/IEC 20000-1:2018 – IT Service Management Systems - Requirements
Defines requirements for establishing an SMS to ensure effective planning, delivery, and improvement of IT services with a focus on customer satisfaction and service quality.
-
ISO/IEC 27000 series – Overview and Vocabulary for Information Security Management
Provides foundational concepts and terminology supporting ISO/IEC 27001 and related standards, facilitating common understanding.
-
Additional Guidelines on Risk Management and Privacy
Though not directly amended in ISO/IEC 27013:2021/Amd 1:2024, organizations may refer to ISO/IEC 27701 for privacy information management and ISO 31000 for risk management principles.
By applying ISO/IEC 27013:2021/Amd 1:2024, organizations gain crucial guidance to unify their cybersecurity and service management approaches efficiently, ensuring resilient, compliant, and customer-focused operations.