Organisations building operational maturity in Vietnam often face a practical question: which framework should guide infrastructure and IT operations, ITIL, ISO 27001, or both?
The two frameworks serve different, complementary purposes.
What Each Framework Actually Covers
ITIL focuses on service management: how IT services are designed, delivered, supported and improved over time. It provides structure for incident management, change management and service level performance.
ISO 27001 focuses specifically on information security management: how an organisation identifies, manages and mitigates information security risk systematically.
In practice, this distinction shows up clearly in how incidents are handled. An ITIL-mature organisation has a documented process for detecting, escalating and resolving a service disruption, with clear ownership at each stage. Overlay ISO 27001 on top of that and the same incident process gains defined security classification, evidence retention and notification obligations specific to the type of data or system affected. Without the ITIL foundation, the ISO 27001 security requirements exist as policy statements with no reliable operational process to execute them consistently.
The same pattern repeats across change management and access control. ITIL’s structured change process gives ISO 27001’s requirement for controlled, auditable changes something concrete to attach to. Attempting the reverse, building security controls first and hoping an operational process emerges around them later, is why so many security frameworks end up as documentation exercises disconnected from how work actually happens day to day.
Vendors and enterprise customers increasingly ask about both frameworks during procurement, so the sequencing question is not purely internal. Being able to describe a coherent maturity path, rather than a partial patchwork of both frameworks, tends to land better in those conversations than either framework alone.
A Common Mistake: Certifying Before Operating
A frequent misstep is pursuing ISO 27001 certification as a sales or compliance requirement before the underlying operational discipline exists. The certification audit itself can often be passed with the right documentation, policies and a well-rehearsed set of interviews. What tends to fail afterwards is day-to-day adherence, because the controls were designed to satisfy an auditor rather than to fit naturally into how the operations team actually works.
The result is a predictable cycle: controls degrade between audits, gaps accumulate, and the following year’s recertification becomes a scramble to reconstruct evidence rather than a confirmation of steady practice. Building the ITIL foundation first avoids this cycle, because the security controls are layered onto processes the team is already following for entirely separate operational reasons, which makes them far more likely to persist.
Getting the Sequencing Right
Organisations frequently need both, but the sequencing matters. ITIL provides the operational foundation on which effective security controls can be reliably implemented and sustained.
For organisations operating across multiple sites in Vietnam, this sequencing becomes even more important, as operational consistency across locations is what ultimately determines whether a security framework functions as intended, rather than existing only in documentation.
For organisations early in this journey, a useful rule of thumb is to delay the ISO 27001 certification conversation until incident management, change management and service level reporting are functioning reliably on their own, even informally. Certification readiness naturally follows operational readiness, and rarely works well in the other order.
It is also worth noting that neither framework needs to be adopted wholesale on day one. Many organisations start with the specific ITIL processes most relevant to their current pain points, commonly incident and change management, and expand into the fuller framework as operational maturity grows. The same incremental approach works for ISO 27001 controls, starting with the highest-risk data categories and systems rather than attempting comprehensive coverage immediately. This phased approach is generally more sustainable than a big-bang rollout of either framework.
The organisations that build ITIL-based operational discipline first, then layer ISO 27001 controls on top of it, typically achieve certification with far less friction, and maintain it far more sustainably.


