Skip to content

ISO 27001

What is ISO 27001?

The international standard for information security management systems (ISMS). The 2022 revision (ISO/IEC 27001:2022) includes 93 controls in Annex A, restructured into four themes.

Information Security

What the standards actually require on iso 27001

Requirements naming iso 27001 across 6 standards, quoted from the control text.

GLI-33 crosswalk to adjacent standards + state-specific technical standards. PCI DSS (Payment Card Industry Data Security Standard) v4.0 - applies to card-not-present payments in event wagering systems; required for any operator handling cards directly;

GLI33-Crosswalk-PCI-NIST-ISO-StateStandards · GLI-33 Crosswalk to PCI DSS, NIST CSF, ISO 27001, State Technical Standards
HKMA TM-G-14 controls

HKMA TM-G-1 coordination + 2024-2025 pipeline. COORDINATION WITH HKMA FRAMEWORKS: (a) HKMA SPM UMBRELLA (separately referenced) - TM-G-1 is one of 60+ SPM modules; SPM provides overall framework + supervisory expectations;

HKMA-TMG1-Coord-SPM-CRAF-Basel-FSB-2024-2025-Pipeline · TM-G-1 Coordination with HKMA SPM, C-RAF v2.0, Basel III, FSB, ISO 27001, NIST CSF and 2024-2025 Pipeline

Kuwait National Cybersecurity Framework (NCF) Govern function. Issued and maintained by Kuwait National Cybersecurity Centre (NCSC) under Council of Ministers Resolution.

KNCF-Govern-Strategy-Policy-NCSC-NIST-CSF-2-0-ISO-27001-Council-of-Ministers-Compliance-Assurance · Kuwait NCF Govern + Strategy + Policy + NCSC + NIST CSF 2.0 + ISO 27001 + Compliance Assurance

GAMP 5 crosswalk to general IT + security + medical device frameworks. NIST CSF 2.0: GxP-system IT general controls map to GOVERN + IDENTIFY (inventory + supplier risk) + PROTECT (access controls + encryption + secure dev) + DETECT (monitoring + audit trails)...

GAMP5-CrossMapping-NIST-ISO · Crosswalk to NIST CSF, ISO 27001/27017, ISO 13485 (Medical Devices) and ITIL

Ghana CSA crosswalk to international standards. NIST CSF 2.0 (February 2024): mapping GOVERN (CSA Ghana engagement + Cybersecurity Plan) + IDENTIFY (CII designation + asset + risk + supplier) + PROTECT (access controls + segmentation + encryption + training) +...

GhCSA-Crosswalk-NIST-ISO-27001-Sectoral · Crosswalk to NIST CSF 2.0, ISO 27001, ISO 22301 and Sector Standards

Questions people ask about iso 27001

What is ISO 27001?
The international standard for information security management systems (ISMS). The 2022 revision (ISO/IEC 27001:2022) includes 93 controls in Annex A, restructured into four themes.
Why is ISO 27001 important for compliance?
ISO 27001 is a key concept in Information Security. Understanding iso 27001 helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to ISO 27001?
Key concepts related to ISO 27001 include ISMS (Information Security Management System), Annex A, ISO 27002. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address ISO 27001?
ISO 27001 appears in the requirement text of GLI-33 - Gaming Laboratories International Event Wagering Systems, HKMA TM-G-1, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), Kuwait National Cybersecurity Framework, GAMP 5 - Good Automated Manufacturing Practice. Across these standards we have identified 20 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about ISO 27001?
Explore our compliance framework pages to see how iso 27001 applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how ISO 27001 applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.