International (ISO/IEC JTC 1/SC 27)

ISO/IEC 27557:2022

74 controls. 322 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

74 controls 322 frameworks share controls with it International (ISO/IEC JTC 1/SC 27) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
27557-4.1General principles0
27557-4.2Privacy risk integration0
27557-4.3Individual impact consideration206
27557-5.1Leadership and commitment15
27557-5.2Integration with organizational processes1
27557-5.3Design of framework0
27557-5.4Implementation and evaluation2
27557-6.1Communication and consultation16
27557-6.2Scope, context, and criteria for privacy170
27557-6.3Privacy risk assessment159
27557-6.4Privacy risk treatment91
27557-6.5Monitoring and review3
27557-6.6Recording and reporting92
27557-7.1Types of privacy risk0
27557-7.2Organizational consequences of privacy events0
27557-7.3Risk-based privacy program implementation91
ISO27557-10.1Continual Improvement16
ISO27557-10.2Documentation Management0
ISO27557-4.1Privacy Risk Management Scope1
ISO27557-4.2Privacy Context Establishment0
ISO27557-5.1Privacy Risk Management Leadership0
ISO27557-5.2Privacy Risk Roles and Responsibilities0
ISO27557-6.1Privacy Risk Assessment Methodology0
ISO27557-6.2Privacy Risk Identification0
ISO27557-6.3Privacy Risk Analysis0
ISO27557-6.4Privacy Risk Evaluation0
ISO27557-7.1Privacy Risk Treatment Options0
ISO27557-7.2Privacy Control Selection0
ISO27557-7.3Treatment Plan Documentation0
ISO27557-7.4Residual Privacy Risk Acceptance0
ISO27557-8.1Privacy Risk Communication0
ISO27557-8.2Consultation with Affected Parties0
ISO27557-9.1Privacy Risk Monitoring0
ISO27557-9.2Privacy Risk Review0
ISO27557-9.3Effectiveness Measurement0
44 Principles of organizational privacy risk management0
55 Framework0
5.15.1 Framework: general0
5.25.2 Leadership and commitment0
5.35.3 Integration0
5.45.4 Design0
5.4.15.4.1 Understanding the organization and its context0
5.4.25.4.2 Articulating risk management commitment0
5.4.35.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities0
5.4.45.4.4 Allocating resources0
5.4.55.4.5 Establishing communication and consultation0
5.55.5 Implementation0
5.65.6 Evaluation0
5.75.7 Improvement0
5.7.15.7.1 Adapting0
5.7.25.7.2 Continually improving0
66 Risk management process0
6.16.1 Process: general0
6.26.2 Communication and consultation0
6.36.3 Scope, context and criteria0
6.3.16.3.1 Scope, context and criteria: general0
6.3.26.3.2 Defining the scope0
6.3.36.3.3 External and internal context0
6.3.46.3.4 Defining risk criteria0
6.46.4 Risk assessment0
6.4.16.4.1 Risk assessment: general0
6.4.26.4.2 Risk identification0
6.4.36.4.3 Risk analysis0
6.4.46.4.4 Risk evaluation0
6.56.5 Risk treatment0
6.5.16.5.1 Risk treatment: general0
6.5.26.5.2 Selection of risk treatment options0
6.5.36.5.3 Preparing and implementing risk treatment plans0
6.66.6 Monitoring and review0
6.76.7 Recording and reporting0
ANNEXESAnnexes A to D (informative): identification of PII processing, example privacy events and causes, impact and consequence examples, severity scale template0
FRONTClauses 2 and 3: normative references and terms0
STANDARDISO/IEC 27557:2022: the standard, its scope and what is held0
STATUSEdition status: first edition 2022, current; not certifiable; the pair to ISO/IEC 27701 and ISO/IEC 291340

Tell me when ISO/IEC 27557:2022 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Roles and responsibilities matrix
  • Compliance policy
  • Compliance obligations register
  • Compliance objectives
  • Anti-bribery policy
  • Quality objectives

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO/IEC 27557:2022, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition