ISO 27001 and ISO 9001 and information security
Assign topic to the user
Answer: No. While ISO 27001 focus is indeed information security, ISO 9001 purpose is quality management (if you note, nowhere in ISO 9001 the word "security" is mentioned). Regarding the aspects covered, they are similar in some aspects (e.g., document and record control, internal audit, management review, etc.) but completely different in others (e.g., only ISO 27001 covers information security risk assessment while only ISO 9001 covers product and service provision).
These articles will provide you further explanation about how to work with ISO 27001 and ISO 9001 together:
- Using ISO 9001 for implementing ISO 27001 https://advisera.com/27001academy/blog/2010/03/08/using-iso-9001-for-implementing-iso-27001/
- How to implement integrated management systems https://advisera.com/articles/how-to-implement-integrated-management-systems/
This material will also help you regarding how to ISO 27001 and ISO 9001 together:
- Free webi nar ISO 27001 implementation: How to make it easier using ISO 9001 https://advisera.com/27001academy/webinar/iso-27001-implementation-make-easier-using-iso-9001-free-webinar-demand/
Comment as guest or Sign in
Dec 27, 2016