ISO 27001:2022
Organizational controls – ISO 27001:2022

ISO 27001:2022 5.31: Legal, statutory, regulatory and contractual requirements

The organization is to identify, record and keep current every requirement bearing on information security, whether it comes from law, statute, regulation or contract, together with how it intends to meet each one. Purpose (stated in ISO/IEC 27002:2022): keeps the organization compliant with the laws, regulations and contracts that concern information security. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.31.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 109 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27701:2019 · 22 controls

  • 5.2.2 Understanding the needs and expectations of interested parties
  • 5.4 Planning
  • 5.4.1 Actions to address risks and opportunities
  • 6.15 Compliance
  • 6.15.1 Compliance with legal and contractual requirements
  • 7.2 Conditions for collection and processing
  • 7.2.2 Identify lawful basis
  • 7.2.4 Obtain and record consent
  • 7.2.5 Privacy impact assessment
  • 7.3.1 Determining and fulfilling obligations to PII principals
  • 7.3.10 Automated decision making
  • 7.3.6 Access, correction and/or erasure
  • 7.5 PII sharing, transfer, and disclosure
  • 7.5.1 Identify basis for PII transfer between jurisdictions
  • 8.2 Conditions for collection and processing
  • 8.2.2 Organization’s purposes
  • 8.2.5 Customer obligations
  • 8.3 Obligations to PII principals
  • 8.5.1 Basis for PII transfer between jurisdictions
  • 8.5.2 Countries and international organizations to which PII can be transferred
  • 8.5.4 Notification of PII disclosure requests
  • 8.5.5 Legally binding PII disclosures

ISO/IEC 42001:2023 · 8 controls

  • 4.2 Understanding the needs and expectations of interested parties
  • 6.1.2 AI risk assessment
  • 7.5.1 General
  • A.2.3 Alignment with other organizational policies
  • A.5.4 Assessing AI system impact on individuals or groups of individuals
  • A.7.3 Acquisition of data
  • A.8.5 Information for interested parties
  • A.9.3 Objectives for responsible use of AI system

NIST SP 800-53 Rev 5 · 7 controls

SOC 2 · 7 controls

  • SOC2-CC2.3 CC2.3 Communication with external parties about internal control (COSO principle 15)
  • SOC2-P4.2 P4.2 Retaining personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • SOC2-P6.2 P6.2 Record of authorised disclosures
  • SOC2-P6.4 P6.4 Privacy commitments from vendors and third parties
  • SOC2-P6.6 P6.6 Notifying breaches and incidents
  • SOC2-P8.1 P8.1 Inquiries, complaints, disputes and compliance monitoring

HIPAA Security Rule · 6 controls

FedRAMP High · 4 controls

  • CM-10 Software Usage Restrictions
  • SA-4 Acquisition Process
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SI-12 Information Management and Retention

FedRAMP Moderate · 4 controls

  • CM-10 Software Usage Restrictions
  • SA-4 Acquisition Process
  • SA-9(5) External System Services | Processing, Storage, and Service Location (SA-9(5))
  • SI-12 Information Management and Retention

C5 (Germany) · 3 controls

  • C5-COM-01 Identification of applicable legal, regulatory, self-imposed or contractual requirements
  • C5-INQ-01 Legal Assessment of Investigative Inquiries
  • C5-PSS-12 Locations of Data Processing and Storage

COBIT 2019 · 3 controls

  • MEA03.01 MEA03.01 Identify external compliance requirements
  • MEA03.02 MEA03.02 Optimize response to external requirements
  • MEA03.03 MEA03.03 Confirm external compliance

DORA · 3 controls

ISO 22301:2019 · 3 controls

  • 4.1 Understanding the organization and its context
  • 4.2 Understanding the needs and expectations of interested parties
  • 4.2.2 Legal and regulatory requirements

NIS2 Directive · 3 controls

  • Art.24 Use certified ICT products, services and processes where the Member State requires it
  • Art.26 Establish which Member State has jurisdiction, and designate a Union representative if not established in the Union
  • Art.3.4 Submit and maintain entity registration information with the competent authority
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity - including privacy and civil liberties obligations - are understood and managed
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders

APPI · 2 controls

  • APPI-A17 Specification of the Purpose of Use
  • APPI-A28 Provision to Third Parties in Foreign Countries
  • CPS230-9 Management of the Full Range of Operational Risks
  • CPS230-P12 Key Principles for Operational Risk, Resilience and Service Providers
  • SEC01-BP03 Identify and validate control objectives
  • SEC07-BP01 Understand your data classification scheme
  • ASBv3-DP-5 Use customer-managed key option in data at rest encryption when required
  • ASBv3-LT-6 Configure log storage retention

CIS Controls v8 · 2 controls

  • CIS-15.4 Ensure Service Provider Contracts Include Security Requirements
  • CIS-17.4 Establish and Maintain an Incident Response Process

EU AI Act · 2 controls

ISO 27001:2013 · 2 controls

  • A.18.1.1 Identification of applicable legislation and contractual requirements
  • A.18.1.5 Regulation of cryptographic controls

PCI DSS 4.0 · 2 controls

  • 12.5.2 12.5.2 Annual and change-driven scope confirmation
  • 12.9.2 12.9.2 TPSP support for customer information requests
  • 7.1.b-measures Article 7(1)(b): take the cybersecurity measures the legislation prescribes
  • 7.1.d Article 7(1)(d): implement the Presidency's policies, strategies, action plans and regulatory acts on cyber maturity

APRA CPS 234 · 1 control

  • CPS234-36 APRA Notification of Material Control Weakness within 10 Business Days
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data

CMMC 2.0 · 1 control

GDPR · 1 control

ISO 27002:2022 · 1 control

  • 5.31 Legal, statutory, regulatory and contractual requirements
  • 03.14.08 Information Management and Retention
  • 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)
  • 1.7 1.7 Check other laws beyond data protection before monitoring
  • 3(2)(b) Regulation 3(2)(b) Purpose: to ascertain compliance with regulatory or self-regulatory practices or procedures

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Organizational controls – ISO 27001:2022

You are reading one control. How much of ISO 27001:2022 have you already done?

ISO 27001:2022 5.31 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27001:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27001:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 170 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 109 it maps to, and the evidence behind each claim, over MCP and REST.