Skip to content

Information Security

What is Information Security?

The practice of protecting information by mitigating risks to its confidentiality, integrity, and availability. Governed by frameworks such as ISO 27001 and NIST CSF.

Information Security

What the standards actually require on information security

Requirements naming information security across 6 standards, quoted from the control text.

ISO 27002:202226 controls

Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.

iso-27002-2022::5.29 · Information security during disruption

Define and apply a risk assessment process with criteria, repeatability, and documented results.

27003-6.1.2 · Information Security Risk Assessment
ISO 27701:201915 controls

The requirement of ISO/IEC 27001 to implement the risk treatment plan applies to the PIMS, so the privacy controls chosen during treatment must actually be implemented and their implementation evidenced.

iso-27701-2019::5.6.3 · Information security risk treatment
APRA CPS 23414 controls

The entity must maintain response plans covering the information security incidents it considers could plausibly occur.

CPS234-P24 · Information Security Response Plans
ISO 27005:202214 controls

Requirement defined in ISO 27005:2022, clause 7.2 (Identifying information security risks). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_r...

iso-27005-2022::7.2 · Identifying information security risks

CISO or equivalent role is designated with sufficient authority, independence, and access to the board.

IS-II.C.1 · Information Security Roles and Responsibilities

Questions people ask about information security

What is Information Security?
The practice of protecting information by mitigating risks to its confidentiality, integrity, and availability. Governed by frameworks such as ISO 27001 and NIST CSF.
Why is Information Security important for compliance?
Information Security is a key concept in Information Security. Understanding information security helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Information Security?
Key concepts related to Information Security include ISO 27001. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Information Security?
Information Security appears in the requirement text of ISO 27002:2022, ISO/IEC 27003:2017, ISO 27701:2019, APRA CPS 234, ISO 27005:2022. Across these standards we have identified 99 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Information Security?
Explore our compliance framework pages to see how information security applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Information Security applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.