International

ISO 27018

75 controls. 291 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

75 controls 291 frameworks share controls with it International held in the corpus

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

ISO/IEC 27018:2019 Evidence & Implementation Kit

75 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
A.1.1Consent and choice0
A.1.1Consent and choice0
A.10.1Information security6
A.10.1Information security6
A.10.10User ID management0
A.10.11Contract measures0
A.10.12Sub-contracted PII processing0
A.10.13Access to data on pre-used data-storage space0
A.10.2Confidentiality obligations of personnel13
A.10.2Confidentiality obligations of personnel13
A.10.3Restriction of creation of hardcopy material4
A.10.3Restriction of creation of hardcopy material4
A.10.4Control and logging of data restoration6
A.10.4Control and logging of data restoration6
A.10.5Protection of data on storage media leaving premises0
A.10.5Protection of data on storage media leaving premises0
A.10.6PII transmission1
A.10.6PII transmission1
A.10.7Disclosure of PII0
A.10.7Disclosure of PII0
A.10.8Unique use of user IDs0
A.10.9Records of authorized users0
A.11.1Geographical location of PII0
A.11.1Geographical location of PII0
A.11.2Intended destination of PII0
A.11.2Intended destination of PII0
A.11.3Disposal of PII0
A.11.4Temporary files1
A.11.5PII transmission1
A.12.1Notification of a data breach0
A.12.1Notification of a data breach0
A.12.2Return, transfer and disposal of PII1
A.12.2Return, transfer and disposal of PII1
A.12.3Periodic audits and reviews0
A.2.1Purpose legitimacy and specification0
A.2.1Purpose legitimacy and specification0
A.3.1Collection limitation0
A.3.1Collection limitation0
A.4.1Data minimization0
A.4.1Data minimization0
A.5.1Use, retention and disclosure limitation0
A.5.1Use, retention and disclosure limitation0
A.6.1Accuracy and quality1
A.6.1Accuracy and quality1
A.7.1Openness, transparency and notice0
A.7.1Openness, transparency and notice0
A.8.1Individual participation and access0
A.8.1Individual participation and access0
A.9.1Accountability0
A.9.1Accountability0
ISO27018-01Shared responsibility model definition135
ISO27018-02Cloud security policy and strategy14
ISO27018-03Cloud risk assessment123
ISO27018-04Regulatory compliance for cloud services58
ISO27018-05Cloud security roles and responsibilities14
ISO27018-06Cloud identity management34
ISO27018-07Multi-factor authentication for cloud69
ISO27018-08Privileged access in cloud environments64
ISO27018-09Federation and single sign-on0
ISO27018-10API security and access tokens0
ISO27018-11Data classification for cloud120
ISO27018-12Encryption of cloud-stored data112
ISO27018-13Data residency and sovereignty0
ISO27018-14Data backup and recovery in cloud142
ISO27018-15Secure data deletion in cloud89
ISO27018-16Virtual network segmentation55
ISO27018-17Container and serverless security0
ISO27018-18Cloud workload protection0
ISO27018-19Image and template hardening43
ISO27018-20Cloud configuration management43
ISO27018-21Cloud security monitoring and logging79
ISO27018-22Incident response in cloud109
ISO27018-23Cloud vulnerability management53
ISO27018-24Cloud change management34
ISO27018-25Service level agreement management0

Tell me when ISO 27018 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Customer agreement clauses
  • Processing instructions log
  • Use restriction policy
  • Audit trail
  • QA checklist
  • Reviewer signoff
  • IAM policy
  • MFA enforcement report
  • Federation configuration
  • API token inventory

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 27018, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition