SlideShare a Scribd company logo
Implementing Service Management
System and IT Security management
with Integrated ISO/IEC 2000-1 and
ISO/IEC 27000-series
By:
Septafiansyah Dwi P.
Institut Teknologi Bandung
ITSM or SMS
IT service management, is a concept that combines with system
management, network management, system development
management and incident management, problem management,
service management, security and so on helping enterprises to manage
the process of constructing, implement, maintaining, and planning for
IT system through effective management method (Tang, 2009).
ISO 20000 – Standar in IT Service
Management
What is it?
The formulation of ITIL practices into an international standard
Management of 13 key IT services to meet business requirements
(predominantly internally focused)
Specifies a number of closely related processes that brought together will
help ensure that an organisation delivers managed IT services to its internal
customers
Comprehensive but not exhaustive
Planning, implementing, monitoring, improvement of new and changed
services
The benefits ISO 20000
• A consistent approach to service management
• IT service provision becomes measurable and accountable
• Consistent levels of service are agreed
• Improved communication flows between IT and the business
• IT gain better understanding of the business requirement
• Reduced risk of business failure
• A reduction in the number of avoidable and repeat incidents
• Higher availability of systems and services
Service management system
1. Scope
1.1. General
1.2.
Application
2.No
rmati
ve
refre
nces
3.
Term
s and
defin
itions
4. SMS general requirements
4.1.
Manageme
nt
responsibilit
y
4.2.
Governance
of processes
operated by
other
parties
4.3
Documentat
ion
managemen
t
4.4
Resource
managemen
t
Establish
and
improvethe
SMS ..
5. Design and transition of
new or changed service
5.1 General
5.2 Plan
new or
changed
services
5.3 Design
and
developmen
t of new or
changed
services
5.4
Transition
of new or
changed
services
6. Service delivery process
6.1 Service
level
managemen
t
6.2 Service
reporting
6.3 Service
continuity
and
availability
managemen
t
6.4
Budgeting
and
accounting
for services
6.5
Capacity
managemen
t
6.6
Information
security
managemen
t
7.
Relationsip
process
7.1.
Business
relationship
managemen
t
7.2 Supplier
managemen
t
8.
Resolution
process
8.1. Incident
and service
request
managemen
t
8.2
Problem
managemen
t
9. Control process
9.1
Configuratio
n
managemen
t
9.2 Change
managemen
t
9.3 Release
and
deployment
managemen
t
Implementing PDCA to service managment
Plan
•Establishing
•Documenting
•Agreeing SMS
Do
•Implementing
•Operating the SMS
Check
•Monitoring,
•Measuring,
•Reviewing SMS
Act
•Improving the SMS
•Improving the service
Policies Objectives Plans Process
Service Management System
SMS
Service
Management
Process
Service
Indonesia Hot Topic Issue
ISO27001
ISO27001 is the standard for establishing, controlling, monitoring and
improving an Information Security Management System (ISMS). It
provides the requirements for an ISMS framework as well as 133
controls (much like the “shalls” in ISO 20000.) (Implement ISO, 2012)
It is compatible with other standards such as NIST 800-53, ISO 27005,
COSO, Detiknas. and uses a risk-based assesment approach to
determine the scope of its implementation within an organisation. The
main goals of the ISO 27001 standard are to manage information
security, maintain business continuity and comply with regulation. It
addresses all information,physical security, environmental aspects,
outsourcing issues, etc.
The benefits ISO27000
• Reduction in possibly damaging/embarrassing information leaks and
failures
• Total risk mitigation, security of brand equity
• Reduction in costs due to fewer security incidents
• Common policies and control across the whole organisation
• Increased staff awareness
• Better monitored and audited systems and information flows
• The risk significantly reduced
“where does the ISO 20000-1 fit in with ISO 27001?”
Integrated SMS and ISMS
It is ISO 27001 which fits in to ISO 20000 and specifically in Section 6.6
Information Security Management. This section addresses information
security policy, controls and changes/incidents as related to IT-based
information. ISO 27001 can provide much further details and information
in terms of setting up security elements in your organisation. ISO 27001
tells you “how” to do it rather than stating that you “have” to do it.
In other words, aim to combine some of the implementation activities
such as the audit review / risk assesment. There are advantages to having
a single audit team to look at both Management Systems. This eliminates
redundancies and gives good value for money and make Polinela
established one of aspect in good governance university. As stated
above, both standards use common management approaches, are both
based on processes and also use the PDCA principles.
Advantages in integrated management
system
There are a number of advantages in implementing an integrated management system which
takes into account not only the services provided but also the protection of information assets.
These benefits can be experienced whether one standard is implemented before the other, or
both standards are implemented simultaneously. Management and organizational processes, in
particular, can derive benefit from the similarities between the International Standards and
their common objectives.
Key benefits of an integrated implementation include:
a) the credibility, to internal or external customers of the organization, of an effective and
secure service;
b) the lower cost of an integrated programme of two projects, where achieving both service
management and information security are part of an organization’s strategy;
c) a reduction in implementation time due to the integrated development of processes
common to both standards;
d) elimination of unnecessary duplication;
e) a greater understanding by service management and security personnel of each others’
viewpoints;
감사합니다

More Related Content

PPTX
Integrating sms and isms
PDF
ISO 27001 Certification - The Benefits and Challenges
PPTX
Is iso 27001, an answer to security
PDF
Isms awareness presentation
PDF
ISO 27001:2013 - Changes
PDF
Transitioning to iso 27001 2013
PPTX
Presentation on iso 27001-2013, Internal Auditing and BCM
PPT
ISO 27001 Benefits
Integrating sms and isms
ISO 27001 Certification - The Benefits and Challenges
Is iso 27001, an answer to security
Isms awareness presentation
ISO 27001:2013 - Changes
Transitioning to iso 27001 2013
Presentation on iso 27001-2013, Internal Auditing and BCM
ISO 27001 Benefits

What's hot (18)

PDF
Infosec Audit Lecture_4
PPTX
Basic introduction to iso27001
PPT
ISMS Part I
PPT
Iso27001 Isaca Seminar (23 May 08)
PPTX
Iso 27001 certification
DOCX
ISO 27001:2013 Implementation procedure
PDF
Iso 27001 metrics and implementation guide
PPT
Popular Pitfalls In Isms Compliance
PDF
STAND OUT: Why You Should Become ISO 27001 Certified
PDF
ISO27001: Implementation & Certification Process Overview
DOCX
Iso 27001 2013 Standard Requirements
PDF
NQA Your Complete Guide to ISO 27001
PDF
ISO 27001 ISMS MEASUREMENT
PDF
What is ISO 27001 ISMS
PPT
The best way to use ISO 27001
PPTX
Iso 27001 awareness
PDF
ISO 27001 Implementation_Documentation_Mandatory_List
Infosec Audit Lecture_4
Basic introduction to iso27001
ISMS Part I
Iso27001 Isaca Seminar (23 May 08)
Iso 27001 certification
ISO 27001:2013 Implementation procedure
Iso 27001 metrics and implementation guide
Popular Pitfalls In Isms Compliance
STAND OUT: Why You Should Become ISO 27001 Certified
ISO27001: Implementation & Certification Process Overview
Iso 27001 2013 Standard Requirements
NQA Your Complete Guide to ISO 27001
ISO 27001 ISMS MEASUREMENT
What is ISO 27001 ISMS
The best way to use ISO 27001
Iso 27001 awareness
ISO 27001 Implementation_Documentation_Mandatory_List
Ad

Similar to Integrating sms and isms (20)

PDF
pk article aug 14
PPTX
New Microsoft PowerPoint Presentation
PPTX
2017 QA Forum presentation Igor Stevkosvski CIS.pptx
PDF
How Your Organization Can Become ISO Certified...It's easier than you think
PDF
What is iso iec 20000
PDF
What is iso iec 20000
PDF
It security iso 27001
PPTX
Experience from Implementation of ISO 20000
PPT
Overview of ISO 27001 ISMS
PDF
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
PPT
Iso 20000 standard implementation
PDF
Unlocking Success with ISO 20000-1:2018 Certification
PPS
ISO/I20000 in a nutshell
PPT
Iso 20000 presentation
PPTX
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
PDF
Select information security system 2015en
PPTX
Standardization of IT Processes
PPTX
ISO 20000 Service Management. pptx
PPTX
Benefits of Integrating ISO and CMMI Service Management System Frameworks
PDF
The Road to ISO 20K Certification - ITSMF Ottawa Conference March 2014
pk article aug 14
New Microsoft PowerPoint Presentation
2017 QA Forum presentation Igor Stevkosvski CIS.pptx
How Your Organization Can Become ISO Certified...It's easier than you think
What is iso iec 20000
What is iso iec 20000
It security iso 27001
Experience from Implementation of ISO 20000
Overview of ISO 27001 ISMS
✅ WHY IS ISO 20000-1 CERTIFICATION A GOOD IDEA FOR YOUR ORGANIZATION GROWTH?
Iso 20000 standard implementation
Unlocking Success with ISO 20000-1:2018 Certification
ISO/I20000 in a nutshell
Iso 20000 presentation
Lynda Cooper: ISO/IEC 20000 - The Launch of the Revised Standard
Select information security system 2015en
Standardization of IT Processes
ISO 20000 Service Management. pptx
Benefits of Integrating ISO and CMMI Service Management System Frameworks
The Road to ISO 20K Certification - ITSMF Ottawa Conference March 2014
Ad

Recently uploaded (20)

PPTX
Cell Types and Its function , kingdom of life
PPTX
Renaissance Architecture: A Journey from Faith to Humanism
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
PDF
Basic Mud Logging Guide for educational purpose
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PDF
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
PDF
Chapter 2 Heredity, Prenatal Development, and Birth.pdf
PDF
STATICS OF THE RIGID BODIES Hibbelers.pdf
PDF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PPTX
PPH.pptx obstetrics and gynecology in nursing
PPTX
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
PPTX
Week 4 Term 3 Study Techniques revisited.pptx
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
PDF
01-Introduction-to-Information-Management.pdf
PDF
O7-L3 Supply Chain Operations - ICLT Program
PPTX
Pharmacology of Heart Failure /Pharmacotherapy of CHF
PDF
Abdominal Access Techniques with Prof. Dr. R K Mishra
PPTX
human mycosis Human fungal infections are called human mycosis..pptx
Cell Types and Its function , kingdom of life
Renaissance Architecture: A Journey from Faith to Humanism
Module 4: Burden of Disease Tutorial Slides S2 2025
Basic Mud Logging Guide for educational purpose
O5-L3 Freight Transport Ops (International) V1.pdf
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
Chapter 2 Heredity, Prenatal Development, and Birth.pdf
STATICS OF THE RIGID BODIES Hibbelers.pdf
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PPH.pptx obstetrics and gynecology in nursing
BOWEL ELIMINATION FACTORS AFFECTING AND TYPES
Week 4 Term 3 Study Techniques revisited.pptx
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
FourierSeries-QuestionsWithAnswers(Part-A).pdf
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
01-Introduction-to-Information-Management.pdf
O7-L3 Supply Chain Operations - ICLT Program
Pharmacology of Heart Failure /Pharmacotherapy of CHF
Abdominal Access Techniques with Prof. Dr. R K Mishra
human mycosis Human fungal infections are called human mycosis..pptx

Integrating sms and isms

  • 1. Implementing Service Management System and IT Security management with Integrated ISO/IEC 2000-1 and ISO/IEC 27000-series By: Septafiansyah Dwi P. Institut Teknologi Bandung
  • 2. ITSM or SMS IT service management, is a concept that combines with system management, network management, system development management and incident management, problem management, service management, security and so on helping enterprises to manage the process of constructing, implement, maintaining, and planning for IT system through effective management method (Tang, 2009).
  • 3. ISO 20000 – Standar in IT Service Management What is it? The formulation of ITIL practices into an international standard Management of 13 key IT services to meet business requirements (predominantly internally focused) Specifies a number of closely related processes that brought together will help ensure that an organisation delivers managed IT services to its internal customers Comprehensive but not exhaustive Planning, implementing, monitoring, improvement of new and changed services
  • 4. The benefits ISO 20000 • A consistent approach to service management • IT service provision becomes measurable and accountable • Consistent levels of service are agreed • Improved communication flows between IT and the business • IT gain better understanding of the business requirement • Reduced risk of business failure • A reduction in the number of avoidable and repeat incidents • Higher availability of systems and services
  • 5. Service management system 1. Scope 1.1. General 1.2. Application 2.No rmati ve refre nces 3. Term s and defin itions 4. SMS general requirements 4.1. Manageme nt responsibilit y 4.2. Governance of processes operated by other parties 4.3 Documentat ion managemen t 4.4 Resource managemen t Establish and improvethe SMS .. 5. Design and transition of new or changed service 5.1 General 5.2 Plan new or changed services 5.3 Design and developmen t of new or changed services 5.4 Transition of new or changed services 6. Service delivery process 6.1 Service level managemen t 6.2 Service reporting 6.3 Service continuity and availability managemen t 6.4 Budgeting and accounting for services 6.5 Capacity managemen t 6.6 Information security managemen t 7. Relationsip process 7.1. Business relationship managemen t 7.2 Supplier managemen t 8. Resolution process 8.1. Incident and service request managemen t 8.2 Problem managemen t 9. Control process 9.1 Configuratio n managemen t 9.2 Change managemen t 9.3 Release and deployment managemen t
  • 6. Implementing PDCA to service managment Plan •Establishing •Documenting •Agreeing SMS Do •Implementing •Operating the SMS Check •Monitoring, •Measuring, •Reviewing SMS Act •Improving the SMS •Improving the service Policies Objectives Plans Process Service Management System SMS Service Management Process Service
  • 8. ISO27001 ISO27001 is the standard for establishing, controlling, monitoring and improving an Information Security Management System (ISMS). It provides the requirements for an ISMS framework as well as 133 controls (much like the “shalls” in ISO 20000.) (Implement ISO, 2012) It is compatible with other standards such as NIST 800-53, ISO 27005, COSO, Detiknas. and uses a risk-based assesment approach to determine the scope of its implementation within an organisation. The main goals of the ISO 27001 standard are to manage information security, maintain business continuity and comply with regulation. It addresses all information,physical security, environmental aspects, outsourcing issues, etc.
  • 9. The benefits ISO27000 • Reduction in possibly damaging/embarrassing information leaks and failures • Total risk mitigation, security of brand equity • Reduction in costs due to fewer security incidents • Common policies and control across the whole organisation • Increased staff awareness • Better monitored and audited systems and information flows • The risk significantly reduced
  • 10. “where does the ISO 20000-1 fit in with ISO 27001?”
  • 11. Integrated SMS and ISMS It is ISO 27001 which fits in to ISO 20000 and specifically in Section 6.6 Information Security Management. This section addresses information security policy, controls and changes/incidents as related to IT-based information. ISO 27001 can provide much further details and information in terms of setting up security elements in your organisation. ISO 27001 tells you “how” to do it rather than stating that you “have” to do it. In other words, aim to combine some of the implementation activities such as the audit review / risk assesment. There are advantages to having a single audit team to look at both Management Systems. This eliminates redundancies and gives good value for money and make Polinela established one of aspect in good governance university. As stated above, both standards use common management approaches, are both based on processes and also use the PDCA principles.
  • 12. Advantages in integrated management system There are a number of advantages in implementing an integrated management system which takes into account not only the services provided but also the protection of information assets. These benefits can be experienced whether one standard is implemented before the other, or both standards are implemented simultaneously. Management and organizational processes, in particular, can derive benefit from the similarities between the International Standards and their common objectives. Key benefits of an integrated implementation include: a) the credibility, to internal or external customers of the organization, of an effective and secure service; b) the lower cost of an integrated programme of two projects, where achieving both service management and information security are part of an organization’s strategy; c) a reduction in implementation time due to the integrated development of processes common to both standards; d) elimination of unnecessary duplication; e) a greater understanding by service management and security personnel of each others’ viewpoints;

Editor's Notes

  • #4: Perumusan praktek ITIL ke dalam standar internasional Pengelolaan 13 layanan TI kunci untuk memenuhi kebutuhan bisnis (terutama berfokus secara internal) Menentukan sejumlah proses terkait erat yang membawa bersama-sama akan membantu memastikan bahwa organisasi memberikan layanan TI berhasil pelanggan internal Komprehensif tapi tidak menyeluruh Perencanaan, pelaksanaan, pemantauan, perbaikan layanan baru dan berubah