ISO 27701:2019
What is ISO 27701:2019?
. It comprises 136 controls organised across 6 domains, published by ISO/IEC, and applies in International.
How ISO 27701:2019 maps to other frameworks
All 136 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 6 domains ISO 27701:2019 groups its controls into
Frameworks that share controls with ISO 27701:2019
Each of these has at least one control mapped to a control in ISO 27701:2019. The number is how many ISO 27701:2019 controls are shared, counted from the mapping graph.
GDPR
42 shared controlsNIST SP 800-53 Rev 5
38 shared controlsAPEC Cross-Border Privacy Rules (CBPR) System
33 shared controlsAPPI
32 shared controlsAustralia Consumer Data Right - Banking (CDR)
31 shared controlsSOC 2
30 shared controlsAustralian Privacy Principles (APPs)
26 shared controlsISO 19011:2018
25 shared controlsImplementation guides for frameworks that overlap ISO 27701:2019
Training on frameworks that overlap ISO 27701:2019
There is no course on ISO 27701:2019 itself. These cover frameworks that share controls with it, so the material carries across even though the standard named is different.
Where ISO 27701:2019 overlaps with the standards you already hold
What ISO 27701:2019 means in your sector
What ISO 27701:2019 means for your job
Questions people ask about ISO 27701:2019
What is ISO 27701:2019?
How many controls does ISO 27701:2019 have?
Where does ISO 27701:2019 apply?
What frameworks does ISO 27701:2019 map to?
How do I get started with ISO 27701:2019 compliance?
Query ISO 27701:2019 programmatically
ISO 27701:2019, its 136 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO 27701:2019 API reference and MCP config →What ISO 27701:2019 requires, control by control
Each page carries the requirement text for one ISO 27701:2019 control and what an assessor expects to see as evidence.
- 5-1 General
- 5-2-1 Understanding the organization and its context
- 5-2-2 Understanding the needs and expectations of interested parties
- 5-2-3 Determining the scope of the information security management system
- 5-2-4 Information security management system
- 5-3-1 Leadership and commitment
- 5-3-2 Policy
- 5-3-3 Organizational roles, responsibilities and authorities
- 5-4-1 Actions to address risks and opportunities
- 5-4-2 Information security objectives and planning to achieve them
How much of another standard ISO 27701:2019 already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- APEC Cross-Border Privacy Rules (CBPR) System to ISO 27701:2019 crosswalk
- APPI to ISO 27701:2019 crosswalk
- Australia Consumer Data Right - Banking (CDR) to ISO 27701:2019 crosswalk
- ISO 27701:2019 to Australian Privacy Principles (APPs) crosswalk
- AWS Well-Architected Security Pillar to ISO 27701:2019 crosswalk
- Azure Security Benchmark to ISO 27701:2019 crosswalk
- C5 (Germany) to ISO 27701:2019 crosswalk
- CCPA/CPRA to ISO 27701:2019 crosswalk
How ready are you for ISO 27701:2019?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.