Frequently asked differences
ISO 9001 is a management system standard for quality management system, whereas ISO 27001 is for information security management system. The eventual output of ISO 9001 is a customer satisfaction, whereas for ISO 27001 it is information risk reduction. The only area that is common is the existence of document management system and the spirit of plan-do-check-act. ISO 9001 is fairly a general standard focusing on quality management system, for all type of organizations. However ISO 20000 is purely IT service quality. Domains such as configuration management have no ISO 9000 equivalence. Organizations choosing to implement ISO 9001 for IT departments should chose ISO 20000 as the latter provide a better return on investment. The concept of 'quality' and 'customer satisfaction' is a generic objective that exists in both; The principle of Plan-do-check-act is common to all management system standards. ISO 20000 focuses on quality of IT service delivery, whereas ISO 27001 focuses on information (including IT) risks especially vulnerabilities and their controls; ISO 20000 has components of IT service risks; One of the key domains of ISO 20000 is information security; The definition of information in PCI DSS is any card information that is 'stored, processed, and transmitted' in the client environment. The definition of information in ISO 27001 is 'anything that has a business value'. At the network layer, PCI-DSS principles are fairly covered in ISO 27001. Both standards have a reference to continual improvement. SSAE 16 implementation can be partly demonstrated by ISO 27002/ISO 27001. A certified ISO 27001 organisation can definitely achieve faster SSAE 16 compliance. BS 259999 is more holistic whereas ISO 27001 is more information infrastructure; BS 25999 ensures that your 'cash generating' functions are up and running at the earliest in case of a disaster; Both standards focus on risk assessment as a common point but the objectives are different. ISO 27001 focuses on removing vulnerabilities whose exploit that can result in an incident, whereas BS 25999 focuses on restoration vulnerabilities such as not having a plan in place; BS 25999 is about business services, whereas ISO 20000 is about IT services; In the implementation of one standard, the journey of the continuity readiness or continuity capability is built. This reduces the project implementation of the next standard. For the subject of the business continuity, BS 25999 is more holistic. On the other hand, ISO 24762 is focused on specifics of ICT recovery capability; One of the key domains of BS25999 is "Developing and implementing BCM response". One of the responses that organisation may have is a hot, warm or cold site. When an organisation has chosen one such option, ISO 24762 acts a good reference point for implementation. The scope of PCI-DSS is based on the existence of card data in the organisation's network. If you accepts, transmits or stores any cardholder datam PCI is applicable. Controls objectives on network and associated IT infrastructure policies can be demonstrated as evidence for compliance in both the standards. Implementation of one compliance can speed up the implementation of the other given the scope of the organisations' requirement is identical. |
Differences between standards
Information reflects opinions of Probal Choudhuri (Founder - CEO) - Coral eSecure. The reader should understand the difference in the context of a macro analysis, rather than micro analysis. Please do not hesitate to write to him at pc@coralesecure.com.
Disclaimer: Coral does not guarantee the accuracy of the above listed information as they are subject to regular changes. Coral shall not be held responsible for any action taken resulting in loss due to information reference made herein. Some of the interpretation involved the opinion of Coral consultants and their experience, which is a result of several years of consulting, implementation and training experience. There can be situations where readers may disagree with such opinions.

What is the difference between ISO 9001 and ISO 27001/ISO 27002?