Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 — Amendment 1

Sécurité de l'information, cybersécurité et protection de la vie privée — Recommandations pour la mise en œuvre intégrée de l'ISO/IEC 27001 et de l'ISO/IEC 20000-1 — Amendement 1

General Information

Publication Date
Current Stage
6060 - International Standard published
Start Date
Due Date
Completion Date
Ref Project


Buy Standard

ISO/IEC 27013:2021/Amd 1:2024 - Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 — Amendment 1 Released:12/10/2024
English language
4 pages
sale 15% off
sale 15% off

Standards Content (Sample)

ISO/IEC 27013
Third edition
Information security, cybersecurity
and privacy protection — Guidance
on the integrated implementation of
ISO/IEC 27001 and ISO/IEC 20000-1
Sécurité de l'information, cybersécurité et protection de la vie
privée — Recommandations pour la mise en œuvre intégrée de
l'ISO/IEC 27001 et de l'ISO/IEC 20000-1
Reference number
ISO/IEC 27013:2021/Amd. 1:2024(en) © ISO/IEC 2024

ISO/IEC 27013:2021/Amd. 1:2024(en)
© ISO/IEC 2024
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Published in Switzerland
© ISO/IEC 2024 – All rights reserved
ISO/IEC 27013:2021/Amd. 1:2024(en)
Information security, cybersecurity and privacy protection —
Guidance on the integrated implementation of ISO/IEC 27001
and ISO/IEC 20000-1
2  Normative references
Replace reference to ISO/IEC 27001 with the following:
ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security
management systems — Requirements
Also replace all references to ISO/IEC 27001:2013 throughout the text of the document with
ISO/IEC 27001:2022.
4.2  ISO/IEC 27001 concepts
Replace the last sentence of the 2 paragraph with the following:
Examples of requirements relevant to interested parties include business requirements, legal and regulatory
requirements and contractual obligations.
Replace the reference to ISO/IEC 27001:2013 with ISO/IEC 27001:2022.

4.4  Similarities and differences
Replace the third paragraph with the following:
See Annex A for details of the correspondence between ISO/IEC 27001:2022, Clauses 1 to 10, and
ISO/IEC 20000-1:2018, Clauses 1 to 10. See Annex B for a comparison of terms and definitions between
ISO/IEC 27000 and ISO/IEC 20000-1.

6.2.1  Requirements and controls
Replace the entire subclause with the following:
ISO/IEC 27001:2022, Clauses 4 to 10, specifies requirements for an ISMS. In addition, ISO/IEC 27001:2022,
Annex A, contains an extensive list of controls. The controls in ISO/IEC 27001:2022, Annex A, are not
requirements and are not mandatory. ISO/IEC 27001:2022, 6.1.3, specifies that the organization defines and
applies an information security risk treatment process to determine all controls necessary to implement
information security risk treatment options chosen and then compare the necessary controls with those in
ISO/IEC 27001:2022, Annex A, and verify that no necessary controls have been omitted. The statement of
applicability (SoA) is then used to record which controls are relevant to the organization’s ISMS. The controls
listed in ISO/IEC 27001:2022, Annex A, are not exhaustive and can be substituted with others, or additional
controls can be added as needed. This means it is possible for the organization’s SoA to:
a) include only a subset of the controls in ISO/IEC 27001:2022, Annex A;

© ISO/IEC 2024 – All rights reserved
ISO/IEC 27013:2021/Amd. 1:2024(en)
b) not include any of the ISO/IEC 27001:2022, Annex A, controls;
c) include alternative controls;
d) include a combination of controls from ISO/IEC 27001:2022, Annex A, and other sources.
Any control within ISO/IEC 27001:2022, Annex A, that would not modify one or more unacceptable risks,
is unnecessary for the organization. Similarly, controls not included in ISO/IEC 27001:2022, Annex A, can
be determined as necessary to modify risk. Organizations can design controls as required or identify them
from any source.
ISO/IEC 20000-1 specifies requirements for the SMS but does not list any controls and does not specify a
requirement for a Statement of Applicability, so there is no direct correlation between ISO/IEC 27001:2022,
Annex A, and ISO/IEC 20000-1. However, ISO/IEC 20000-1:2018,, includes a requirement to determine
controls to address information security risks to the SMS and the services, and to document the decisions
about these controls. In addition, there is a requirement to monitor and review the effectiveness of these
controls, and to take action if required.
Organizations wishing to integrate an ISMS and an SMS should distinguish between the requirements
specified in ISO/IEC 27001 and ISO/IEC 20000-1, and the information security controls specified in
ISO/IEC 27001:2022, Annex A. Even if it appears that there is a common topic area between a requirement
specified in ISO/IEC 20000-1 and a control included in ISO/IEC 27001:2022, Annex A, the distinction
between requirements and controls should be understood and communicated to avoid confusion within the
6.2.2   Assets and configuration items
Replace the reference to ISO/IEC 27001:2013 with ISO/IEC 27001:2022.
Add the following as a new final paragraph to 6.2.2:
ISO/IEC 27001:2022, Annex A includes control 8.9 for "configuration management". This term is also used in
ISO/IEC 20000-1, but not in the same sense, so care should be taken to not assume any

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.