IEC 27001
What is IEC 27001?
The International Electrotechnical Commission's numbering for ISO 27001, the international standard for information security management systems.
Terms that appear alongside iec 27001
Each of these is named in at least one of the same controls as iec 27001. The number is how many controls name both.
- nist 28 shared controls
- information security 22 shared controls
- audit 21 shared controls
- cybersecurity 16 shared controls
- iso 27001 14 shared controls
- compliance 13 shared controls
- management system 13 shared controls
- policy 12 shared controls
Frameworks that govern iec 27001
What the standards actually require on iec 27001
Requirements naming iec 27001 across 6 standards, quoted from the control text.
STAR Certification is a third-party independent assessment that integrates the requirements of ISO/IEC 27001 with the CCM, including a maturity assessment, performed by an accredited certification body.
STAR-L2-01 · STAR Certification (ISO/IEC 27001 + CCM) →The policy requirements of ISO/IEC 27001 apply to the PIMS, meaning the policy set must commit the organization on privacy as well as on information security under the extended interpretation.
iso-27701-2019::5.3.2 · Policy →Security Dimension 2 Authentication per X.805 Clause 6.2: Authentication ensures the validity of the claimed identities of the entities participating in communication (e.g.
X805-Dim2-Authentication-Identity-Verification-Claimed-Identities-Entities-Communication · ITU-T X.805 Security Dimension 2 - Authentication + Identity Verification + Claimed Identity + Entity Authentication + Data Origin Authentication + Mutual Authentication + Multi-Factor + Cryptographic Authentication →The FSA expects financial institutions to implement a comprehensive cybersecurity risk management framework + aligned with NIST CSF 2.0 + FFIEC IT Examination Handbook + ISO/IEC 27001 ISMS + integrated into Enterprise Risk Management (ERM).
JP-FSA-CYB-Risk-Management-NIST-CSF-FFIEC-Aligned-Identify-Protect-Detect-Respond-Recover-Govern-Plan-Do-Check-Act · Japan FSA Cybersecurity Risk Management Framework + NIST CSF 2.0 Aligned + FFIEC Crosswalk + Identify Protect Detect Respond Recover Govern + ISO 27001 ISMS + Plan-Do-Check-Act + Inherent vs Residual Risk + Risk Appetite + Cyber Risk in ERM →GAMP 5 coordination with adjacent regulatory + standard frameworks. ICH Q9 QUALITY RISK MANAGEMENT: foundational risk-based decision making applicable to computerised systems validation; GAMP 5 implements ICH Q9 in CSV context.
GAMP5-Crosswalk-ICH-FDA-EMA-MHRA · Crosswalk to ICH Q9/Q10, FDA Part 11, EU Annex 11, MHRA Data Integrity and Sectoral Standards →IACS Unified Requirement E26 Cyber Resilience of Ships adopted April 2022 by International Association of Classification Societies (IACS).
IACS-UR-E26-Scope-Applicability-2024-IMO-MSC-428 · IACS UR E26 - Scope + Applicability + Effective 1 July 2024 + Coordination IMO MSC.428(98) + Member Societies →Questions people ask about iec 27001
What is IEC 27001?
Why is IEC 27001 important for compliance?
Which compliance frameworks address IEC 27001?
Where can I learn more about IEC 27001?
See how IEC 27001 applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.