ISO 27701:2019
PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

ISO 27701:2019 5.2.1: Understanding the organization and its context

The organization must determine its role as a controller, joint controller or processor, and must determine the external and internal factors that affect whether the PIMS can deliver the outcomes intended for it, including applicable privacy legislation, regulation, judicial and administrative decisions, organizational governance and contractual requirements; where it acts in both roles, the roles must be separated and each made the subject of its own set of controls.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 46 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

SOC 2 · 5 controls

  • SOC2-CC1.3 CC1.3 Structures, reporting lines, authorities and responsibilities (COSO principle 3)
  • SOC2-CC2.1 CC2.1 Relevant, quality information to support internal control (COSO principle 13)
  • SOC2-CC3.1 CC3.1 Objectives specified clearly enough to assess risk (COSO principle 6)
  • SOC2-CC3.2 CC3.2 Identifying and analysing risks to objectives (COSO principle 7)
  • SOC2-CC3.4 CC3.4 Identifying and assessing significant changes (COSO principle 9)
  • NIST-CSF-GV.OC-01 The organizational mission is understood and informs cybersecurity risk management
  • NIST-CSF-GV.OC-04 Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

ISO 22000:2018 · 2 controls

  • 4.1 Understanding the organization and its context
  • 5.2.1 Establishing the food safety policy
  • ISO-39001-4.1 Understanding the organization and its context
  • ISO39001-4.1 Understanding the Organization and Its Context
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO41001-4.1 Understanding the Organization and Its Context
  • ISO-50001-4.1 Understanding the organization and its context
  • 4.1 Understanding the organization and its context

ISO 56002 · 2 controls

  • ISO-56002-4.1 Understanding the organization and its context
  • ISO56002-4.1 Understanding the organization and its context

ISO 9001:2015 · 2 controls

  • 4.1 Understanding the organization and its context
  • 5.2.1 Establishing the quality policy

ISO/IEC 23894:2023 · 2 controls

  • 23894-5.4.1 Understanding Organization and Context
  • 5.4.1 Understanding the organization and its context

ISO/IEC 27003:2017 · 2 controls

  • 27003-4.1 Understanding the Organization and Its Context
  • ISO27003-4.1 Understanding the organization and its context

NIST SP 800-53 Rev 5 · 2 controls

  • AS9100D-4.1 Understanding the Organization and Its Context

CCPA/CPRA · 1 control

  • §1798.100(d) Contractual Requirements for Third Parties, Service Providers, and Contractors

FedRAMP High · 1 control

  • RA-3 Risk Assessment

FedRAMP Moderate · 1 control

  • RA-3 Risk Assessment

HIPAA Security Rule · 1 control

ISO 14001:2015 · 1 control

  • 4.1 Understanding the organization and its context

ISO 14004:2016 · 1 control

  • 4.1 Understanding the organization and its context

ISO 19011:2018 · 1 control

  • 7.6 Maintaining and improving auditor competence

ISO 22301:2019 · 1 control

  • 4.1 Understanding the organization and its context
  • ISO-22313-4.1 Understanding the organization and its context

ISO 31000:2018 · 1 control

  • 5.4.1 Understanding the organization and its context

ISO 37001:2016 · 1 control

  • 4.1 4.1 Understanding the organization and its context
  • ISO-37002-4.1 Understanding the organization and its context

ISO 37301:2021 · 1 control

  • 4.1 Understanding the organization and its context

ISO 45001:2018 · 1 control

  • 4.1 Understanding the organization and its context

ISO 55001:2014 · 1 control

  • 4.1 Understanding the organization and its context

ISO/IEC 42001:2023 · 1 control

  • 4.1 Understanding the organization and its context

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 5.2.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 46 it maps to, and the evidence behind each claim, over MCP and REST.