What is ISO/IEC 27013 about?
ISO/IEC 27013 aims to help organizations integrate their implementation of an information security management system to ISO/IEC 27001:2017 and a services management system to ISO/IEC 20000-1:2018.
Who is ISO/IEC 27013 for?
ISO/IEC 27013 on information security, cybersecurity, and privacy protection are useful for:
- IT companies such as cloud providers and software developers
- Online and offline service providers
- Financial institutions
- Health organizations with health records
- High tech companies tasked with protecting intellectual property
- Consulting companies seeking the right methodology to resolve their clients’ security issues
Why should you use ISO/IEC 27013?
ISO/IEC 27013 provides for the credible provision of effective and secure information/IT services. ISO/IEC 27013 can lower the cost of implementing, maintaining, and auditing an integrated management system where effective and efficient management of both services and information security are part of an organization’s strategy. ISO/IEC 27013 can reduce implementation time due to the integrated development of processes common to both standards. ISO/IEC 27013 can support better communication, increased reliability, and improved operational efficiency through the elimination of unnecessary duplication. ISO/IEC 27013 can strengthen the understanding by service management and information security personnel of each other’s viewpoints. ISO/IEC 27013 can strengthen organizational risk management.
ISO/IEC 27013 contributes to UN Sustainable Development Goal 9 on the industry, innovation, and infrastructure by underpinning more secure and resilient infrastructures.

