International

ISO/IEC 27011:2024

96 controls. 285 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

96 controls 285 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27011-4Structure of this document2
27011-5.1Policies for Information Security in Telecoms3
27011-5.10Acceptable Use of Customer Data0
27011-5.15Access Control for Network Elements1
27011-5.2Information Security Roles in Telecoms110
27011-5.22Monitoring of Supplier Services0
27011-5.23Cloud and Hosted Telecoms Services0
27011-5.3Segregation of duties128
27011-5.30ICT Readiness for Continuity1
27011-5.4Threat intelligence for telecom18
27011-5.5Information security in project management0
27011-5.6Supplier relationships and telecom supply chain76
27011-5.7Threat Intelligence for Telecoms0
27011-6.1Screening of Telecoms Personnel0
27011-6.2Terms and conditions of employment1
27011-6.3Awareness and Training169
27011-6.4Remote working2
27011-7.1Physical security perimeters29
27011-7.10Storage Media Handling in Telecoms1
27011-7.2Physical entry and securing offices1
27011-7.3Equipment protection27
27011-7.4Physical Security of Network Sites6
27011-8.1User Endpoint Devices156
27011-8.12Data Leakage Prevention for Telecoms1
27011-8.15Logging of Network and Service Events0
27011-8.16Monitoring Activities1
27011-8.2Network security and segregation64
27011-8.20Network Security for Telecoms Core0
27011-8.21Security of Network Services1
27011-8.22Segregation of Networks1
27011-8.24Use of Cryptography1
27011-8.27Secure System Architecture1
27011-8.3Cryptography and key management142
27011-8.32Change Management for Network2
27011-8.4Logging and monitoring68
27011-8.5Vulnerability and malware management82
27011-8.6Data protection and backup175
27011-8.7Protection Against Malware0
1-3Scope, normative references, definitions and abbreviations0
4.1Structure of this Recommendation | International Standard0
4.2.1-2Goal, and the kinds of telecommunications organization0
4.2.3Information security considerations in telecommunications0
4.2.5.1How to establish information security requirements0
4.2.5.2Assessing information security risks0
4.2.5.3Selecting information security controls0
5Organizational controls0
5.12Classification of information0
5.15Access control0
5.19Information security in supplier relationships0
5.2Information security roles and responsibilities0
5.20Addressing information security within supplier agreements0
5.21Managing information security in the ICT supply chain0
5.24Information security incident management planning and preparation0
5.25Assessment and decision on information security events0
5.26Response to information security incidents0
5.27Learning from information security incidents0
5.30ICT readiness for business continuity0
5.37Documented operating procedures0
5.38TEL: Interconnected telecommunications services0
5.39TEL: Security management of telecommunications services delivery0
5.40TEL: Response to spam0
5.41TEL: Response to DoS/DDoS attacks0
5.42TEL: Non-disclosure of communications0
5.43TEL: Essential communications0
5.44TEL: Legality of emergency actions0
5.45TEL: Coordination for information security incident management0
5.5Contact with authorities0
5.9Inventory of information and other associated assets0
6People controls0
6.1Screening0
6.2Terms and conditions of employment0
7Physical controls0
7.1Physical security perimeter0
7.11Supporting utilities0
7.12Cabling security0
7.15TEL: Securing communication centres0
7.16TEL: Securing telecommunications equipment room0
7.17TEL: Securing physically isolated operation areas0
7.18TEL: Equipment sited in other carriers' premises0
7.19TEL: Equipment sited in user premises0
7.2Physical entry0
7.8Equipment siting and protection0
8Technological controls0
8.14Redundancy of information processing facilities0
8.15Logging0
8.19Installation of software on operational systems0
8.21Security of network services0
8.22Segregation of networks0
8.31Separation of development, test and production environments0
8.32Change management0
8.35TEL: Telecommunications carrier identification and authentication by users0
AAnnex A: additional guidance for network security0
A.1.1Protection against network attack0
A.1.2Drawing the attention of users0
A.2.1Gathering information on the causes of congestion0
A.2.2Measures against network congestion0

Tell me when ISO/IEC 27011:2024 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Privacy notice and versioning
  • Choice and consent records
  • Data subject request logs
  • Personal information inventory
  • Confidential information inventory
  • Encryption configuration baselines
  • Role definitions
  • Privileged access management records
  • Separation of duty matrices
  • Periodic privilege reviews

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27011:2024, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition