International

ISO/IEC 27031:2011

27 controls. 316 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

27 controls 316 frameworks share controls with it International held in the corpus

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27031-10.1Continual Improvement16
27031-10.2Supplier Continuity Arrangements0
27031-10.3Communication During Incidents13
27031-4.1Overview of IRBC0
27031-4.2IRBC framework elements0
27031-5.1IRBC Policy169
27031-5.2ICT services and infrastructure scope0
27031-6.1Understanding the Organisation0
27031-6.2Business Impact Analysis for ICT1
27031-6.3Risk Assessment for ICT Continuity4
27031-7.1IRBC Strategy30
27031-7.2Resource Requirements181
27031-7.3Incident Response Structure0
27031-7.4IRBC Plans0
27031-7.5Awareness and Training1
27031-8.1Exercising and Testing113
27031-8.2Maintaining IRBC83
27031-8.3IRBC plan documents0
27031-8.4Awareness, competency and training0
27031-9.1Performance Measurement0
27031-9.2Internal Audit14
27031-9.3Management Review98
27031-9.4IRBC review and improvement0
27031-AIRBC milestones during disruption0
27031-BHigh availability embedded systems56
27031-CAssessing failure scenarios0
27031-DDeveloping performance criteria30

Tell me when ISO/IEC 27031:2011 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Approved information security policy
  • Policy review and approval history
  • Roles and responsibilities matrix
  • Management commitment statement
  • Policy communication evidence
  • breach notification template
  • complaint handling procedure
  • complaint register
  • PDPC complaint responses
  • 30-day SLA tracking

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27031:2011, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition