ISO 27001 and ISO 20000: from secure information to reliable service delivery

Organizations are investing heavily in information security. Rightly so, because cyber threats are increasing and customers expect their data and systems to be well protected. With ISO 27001, organizations can demonstrate that they take a systematic approach to information security and manage risks. But for customers, security is increasingly becoming a given. They also expect services to be reliable, predictable and consistently high in quality.

According to Rutger Fugers, an expert in cybersecurity and information security at Kiwa, this is where an important add-on to ISO 27001 comes in. ‘For IT service providers, software vendors, cloud providers and managed service providers, demonstrable service quality is becoming increasingly important. Customers and clients expect not only their information to be secure, but also services to be available and reliable, incidents to be handled properly and agreements to be honored. This is where ISO 20000 comes into play.’

Security and service delivery reinforce each other

ISO 27001 is the international standard for an Information Security Management System (ISMS). The standard helps organizations systematically identify information security risks and take appropriate measures. Confidentiality, integrity and availability of information are central to this. ISO 20000 focuses on a different, but closely related aspect: professionally organizing and managing IT service delivery. The standard helps organizations deliver IT services in a structured way, monitor performance and continuously improve service delivery.

Rutger Fugers: ‘Customers expect not only their information to be secure, but also IT services to be available and reliable, incidents to be resolved effectively and agreements to be honored. They want to know whether service levels are being met, responsibilities are clear and the organization has control over suppliers and outsourced services. ISO 20000 helps organizations demonstrably organize these aspects effectively and consistently deliver high quality IT services.’

What does ISO 20000 add?

ISO/IEC 20000-1 is the international standard for IT service management (ITSM). The standard helps organizations establish, operate, monitor and continuously improve their IT services. Customer satisfaction, process control and service quality are central to this. Among other things, ISO 20000 gives organizations greater control over incident, problem and change management. The standard also helps manage service levels and customer agreements, define responsibilities and systematically improve processes and performance.

The result is an IT organization that not only operates securely, but also demonstrably manages its service delivery. ‘ISO 20000 is essentially about delivering on your service promise,’ Fugers explains. ‘You make it clear what services you provide, what agreements apply to those services and how you ensure that you can consistently meet those agreements.’

The power of combination  

ISO 27001 and ISO 20000 complement each other well. ISO 27001 focuses on information security and managing security risks. ISO 20000 focuses on organizing and managing IT service delivery (see overview below). Combining the two standards creates a broad framework for digital reliability. This allows an organization to demonstrate not only that it carefully protects its information and systems, but also that it has professionally and predictably organized its service delivery.

ISO 27001

 

 

 

ISO 20000

Protects information           

 

 

 

Ensures service delivery        

Manages security risks         

 

 

 

Manages service processes       

Focuses on information security

 

 

 

Focuses on service quality      

Builds trust in data           

 

 

 

Builds trust in service delivery


The combination can also be implemented efficiently. Both standards are based on a management system approach and have areas of overlap, including risks, processes, responsibilities, monitoring, audits and continual improvement.

Towards secure and predictable service delivery?

‘ISO 27001 gives customers confidence in how you handle information. ISO 20000 then shows that you also have control over your service delivery,’ Fugers concludes. ‘Together, the certifications tell a much more complete story about an organization’s reliability. For organizations that are already ISO 27001 certified, ISO 20000 can therefore be a logical next step. The standard helps make the quality and predictability of IT service delivery more demonstrable and thereby strengthen the confidence of customers and clients.’

ISO 27001 and ISO 20000 complement each other: ISO 27001 provides a solid foundation for information security, while ISO 20000 helps demonstrate and ensure the quality and reliability of IT service delivery. Is your organization already ISO 27001 certified and are you ready to take the next step? Discover what ISO 20000 can mean for your IT services and how Kiwa can help you with both certification processes. Visit our pages on ISO 27001 certification and ISO 20000 certification for more information.

Contact

Learn more?

Would you like to know more about this topic? Call us at +31 (0)88 998 33 70 or fill out the contact form. Our experts will be happy to help you!

Go to contact form