International

ISO/IEC 27010:2015

99 controls. 263 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

99 controls 263 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27010-10.1Cryptographic Protection137
27010-11.1Physical Protection27
27010-12.1Operational Procedures3
27010-12.2Protection from malware36
27010-13.1Communications Security65
27010-13.2Information transfer5
27010-14.1Supplier and Third Party Handling0
27010-15.1Incident Management75
27010-16.1Continuity of Sharing142
27010-17.1Compliance34
27010-18.1Review and Improvement0
27010-19.1Trust Anchors and Reputation0
27010-4.1Information Sharing Community0
27010-4.2Sharing Agreements0
27010-5.1Management Direction3
27010-5.2Information sharing community policies0
27010-6.1Roles and Responsibilities2
27010-6.2Contact with Authorities3
27010-7.1Information Classification for Sharing17
27010-7.2Handling Shared Information0
27010-8.1Membership Onboarding28
27010-8.2Membership Termination51
27010-9.1Access Control to Shared Information126
27010-9.2Authentication of Sources135
27010-ABenefits of information sharing0
27010-BTrust assessment guidance0
27010-CTraffic Light Protocol0
27010-DInformation sharing community models0
1-3Scope, normative references, terms and definitions0
10.1Cryptographic controls0
10.1.1Policy on the use of cryptographic controls0
10.1.2Key management0
12.2Protection from malware0
12.2.1Controls against malware0
12.4Logging and monitoring0
12.4.1Event logging0
12.4.2Protection of log information0
12.4.3Administrator and operator logs0
12.4.4Clock synchronization0
12.7Information systems audit considerations0
12.7.1Information systems audit controls0
12.7.2Community audit rights0
13.2Information transfer0
13.2.1Information transfer policies and procedures0
13.2.2Agreements on information transfer0
13.2.3Electronic messaging0
13.2.4Confidentiality or non-disclosure agreements0
15.1Information security in supplier relationships0
15.1.1Information security policy for supplier relationships0
15.1.2Addressing security within supplier agreements0
15.1.3Information and communication technology supply chain0
16.1Management of information security incidents and improvements0
16.1.1Responsibilities and procedures0
16.1.2Reporting information security events0
16.1.3Reporting information security weaknesses0
16.1.4Assessment of, and decision on, information security events0
16.1.5Response to information security incidents0
16.1.6Learning from information security incidents0
16.1.7Collection of evidence0
16.1.8Early warning system0
17.1Information security continuity0
17.1.1Planning information security continuity0
17.1.2Implementing information security continuity0
17.1.3Verify, review and evaluate information security continuity0
18.1Compliance with legal and contractual requirements0
18.1.1Identification of applicable legislation and contractual requirements0
18.1.2Intellectual property rights0
18.1.3Protection of records0
18.1.4Privacy and protection of personally identifiable information0
18.1.5Regulation of cryptographic controls0
18.1.6Liability to the information sharing community0
4.1Introduction to the concepts0
4.2Information sharing communities0
4.3Community management0
4.4Supporting entities0
4.5Inter-sector communication0
4.6Conformity: interpreting ISO/IEC 27001:2013 for a community0
4.7Communications model0
5.1Management direction for information security0
5.1.1Policies for information security0
5.1.2Review of the policies for information security0
7.1Prior to employment0
7.1.1Screening0
8.1Responsibility for assets0
8.1.3Acceptable use of assets0
8.1.4Return of assets0
8.2Information classification0
8.2.1Classification of information0
8.2.2Labelling of information0
8.2.3Handling of assets0
8.4Information exchanges protection0
8.4.1Information dissemination0
8.4.2Information disclaimers0
8.4.3Information credibility0
8.4.4Information sensitivity reduction0
8.4.5Anonymous source protection0
8.4.6Anonymous recipient protection0
8.4.7Onwards release authority0
ANNEXESAnnexes A to D (informative)0

Tell me when ISO/IEC 27010:2015 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 27010:2015, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition