International

ISO/IEC 27040:2024

64 controls. 0 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

64 controls 0 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

No measured overlap with another framework in the corpus.

Every control

CodeControlAlso in
0-1Scope and purpose0
10.10File-based storage0
10.10.2NFS-based NAS0
10.10.3SMB-based NAS0
10.11Cloud computing storage0
10.11.1Securing cloud computing storage0
10.11.2CDMI security0
10.12Object-based storage0
10.13Data reductions0
10.14Data protection and recovery0
10.14.2Storage backups0
10.14.3Storage replication0
10.14.4Storage snapshots0
10.15Data archives and repositories0
10.15.2Data archives0
10.15.3Data Repositories0
10.16Virtualization0
10.16.1Storage virtualization0
10.16.2Storage for virtualized systems0
10.17Secure multi-tenancy0
10.18Secure autonomous data movement0
10.2Design and implementation of storage security0
10.2.2Storage security design principles0
10.2.3Storage system quality attributes0
10.2.4Retention, preservation, and disposal of data0
10.3Storage systems security0
10.3.1System hardening0
10.3.2Security auditing, accounting, and monitoring0
10.3.3Storage vulnerability management0
10.4Storage management0
10.4.2Authentication and authorization0
10.4.3Secure the management interfaces0
10.5Data confidentiality0
10.5.2Encryption and key management issues0
10.5.3Encryption of storage0
10.5.4Encrypting transferred data0
10.5.5Encrypting data at rest0
10.6Storage sanitization0
10.6.2Selection of sanitization methods0
10.6.3Media-based sanitization0
10.6.4Logical sanitization0
10.6.5Cryptographic erase0
10.6.6Verification of storage sanitization0
10.6.7Proof of sanitization0
10.7Direct attached storage0
10.8Storage networking0
10.8.2Storage area networks0
10.8.3Network Attached Storage protocols0
10.9Block-based storage0
10.9.1Fibre Channel (FC) storage0
10.9.2IP storage0
2-4Normative references, terms and abbreviations0
5Structure of this document and controls0
6Overview and concepts: storage concepts, storage security, storage security risks0
7Organizational controls for storage0
7.2Align storage and policy0
7.3Business continuity management0
7.4Compliance0
8People controls for storage0
9Physical controls for storage0
9.2Physically secure storage0
9.3Protect physical interfaces to storage0
9.4Isolation of storage systems0
AAnnex A (informative): storage security controls summary0

Tell me when ISO/IEC 27040:2024 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 27040:2024, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition