Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1
信息安全、网络安全和隐私保护.ISO/IEC 27001和ISO/IEC 20000-1综合实施指南
This document gives guidance on the integrated implementation of ISO/IEC?27001 and ISO/IEC?20000-1 for organizations intending to:
a) implement ISO/IEC27001 when ISO/IEC?20000-1 is already implemented, or vice versa;
b) implement both ISO/IEC27001 and ISO/IEC?20000-1 together; or
c) integrate existing management systems based on ISO/IEC27001 and ISO/IEC?20000-1.
This document focuses exclusively on the integrated implementation of an information security management system (ISMS) as specified in ISO/IEC?27001 and a service management system (SMS) as specified in ISO/IEC?20000-1.