International

ISO/IEC 27014:2020

60 controls. 49 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

60 controls 49 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27014-10.1Continual Improvement of Governance0
27014-4Concepts0
27014-5.1Governance Objectives0
27014-5.2Governance Principles0
27014-5.3Effectiveness0
27014-5.4Efficiency0
27014-5.5Alignment0
27014-5.6Continuous improvement47
27014-6.1Evaluate Process0
27014-6.2Direct Process0
27014-6.3Monitor Process0
27014-6.4Communicate Process0
27014-6.5Assure Process0
27014-7.1Roles and Responsibilities of Governing Body1
27014-7.2Roles of Executive Management0
27014-7.2.1Objective 1: Establish comprehensive information security0
27014-7.2.2Objective 2: Risk-based decision making0
27014-7.2.3Objective 3: Set direction of acquisition0
27014-7.2.4Objective 4: Ensure conformance0
27014-7.2.5Objective 5: Foster security-positive culture0
27014-7.2.6Objective 6: Performance relative to business outcomes0
27014-7.3Relationship Between Governing Body and Management0
27014-7.3.1Evaluate0
27014-7.3.2Direct0
27014-7.3.3Monitor0
27014-7.3.4Communicate0
27014-7.3.5Assure0
27014-8.1Alignment with Enterprise Governance0
27014-8.2Risk Appetite and Tolerance0
27014-8.3Resource Optimisation0
27014-8.4Performance Measurement0
27014-8.5Conformance and Compliance0
27014-9.1Stakeholder Engagement1
27014-9.2Reporting to External Parties0
1-5Scope, references, definitions, abbreviations, use and structure0
6Governance and management standards0
6.1Overview: governance and management of information security0
6.2Governance activities within the scope of an ISMS0
6.4Thread of governance within the organization0
7Entity governance and information security governance0
7.1Governance areas within an entity and the place of information security0
7.2Governance objectives0
7.2.1Objective 1: establish integrated, comprehensive, entity-wide information security0
7.2.2Objective 2: make decisions using a risk-based approach0
7.2.3Objective 3: set the direction of acquisition0
7.2.4Objective 4: ensure conformance with internal and external requirements0
7.2.5Objective 5: foster a security-positive culture0
7.2.6Objective 6: ensure security performance meets current and future requirements of the entity0
7.3Governance processes0
7.3.2Evaluate0
7.3.3Direct0
7.3.4Monitor0
7.3.5Communicate0
8The governing body's requirements on the ISMS0
8.1Organization and ISMS0
8.2Scenarios0
8.2.1Type A: the ISMS organization is the whole entity0
8.2.2Type B: the ISMS organization forms part of a larger entity0
8.2.3Type C: the ISMS organization includes parts of several entities0
ANNEXESAnnexes A to C (informative)0

Tell me when ISO/IEC 27014:2020 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Decision register
  • Governance objectives
  • Conformance report
  • Culture survey
  • Investigator notebooks
  • Timestamped logs

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27014:2020, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition