International (ISO/IEC JTC 1/SC 27)

ISO/IEC 27400:2022

53 controls. 290 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

53 controls 290 frameworks share controls with it International (ISO/IEC JTC 1/SC 27) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27400-10.1Vulnerability Management for IoT0
27400-10.2Incident Response for IoT0
27400-10.3Logging and Monitoring3
27400-11.1Decommissioning and Disposal0
27400-11.2Supplier and Third-Party Management0
27400-4IoT overview and concepts0
27400-5.1IoT Security and Privacy Governance18
27400-5.2IoT Risk Assessment27
27400-5.3Network and communication risks0
27400-5.4Data and privacy risks117
27400-6.1Secure Device Design111
27400-6.2Device Identity and Authentication138
27400-6.3Secure Update Mechanism81
27400-6.4Default Configuration Security58
27400-6.5Security monitoring and incident response157
27400-7.1Network Security for IoT110
27400-7.2Gateway Security0
27400-7.3Data minimization and purpose limitation117
27400-7.4Data retention and deletion110
27400-8.1Platform and Backend Security0
27400-8.2Data Protection in IoT0
27400-8.3Maintenance and update security0
27400-8.4Decommissioning security0
27400-9.1Privacy by Design for IoT0
27400-9.2Consent and Transparency0
27400-9.3Data Subject Rights for IoT0
55 IoT concepts0
5.25.2 Characteristics of IoT systems0
5.35.3 Stakeholders of IoT systems0
5.3.25.3.2 IoT service provider0
5.3.35.3.3 IoT service developer0
5.3.45.3.4 IoT user0
5.45.4 IoT ecosystem0
5.55.5 IoT service life cycles0
5.65.6 Domain based reference model0
66 Risk sources for IoT systems0
6.16.1 Risk sources: general0
6.26.2 Risk sources0
6.2.16.2.1 Risk sources: general categories0
6.2.26.2.2 Sample risk sources related to IoT domains0
6.2.36.2.3 Risk sources from outside the IoT domains0
6.2.46.2.4 Privacy related risk sources0
77 Security and privacy controls0
7.17.1 Security controls0
7.1.27.1.2 Security controls for IoT service developer and IoT service provider0
7.1.37.1.3 Security controls for IoT user0
7.27.2 Privacy controls0
7.2.27.2.2 Privacy controls for IoT service developer and IoT service provider0
7.2.37.2.3 Privacy controls for IoT user0
ANNEXAAnnex A (informative): IoT monitoring camera sample risk scenario0
FRONTClauses 2 to 4: references, terms and abbreviations0
STANDARDISO/IEC 27400:2022: the standard, its scope and what is held0
STATUSEdition status: first edition 2022, current; ISO/IEC 27402 builds on its controls0

Tell me when ISO/IEC 27400:2022 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for ISO/IEC 27400:2022, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition