ISO 27701:2019
PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

ISO 27701:2019 5.7.3: Management review

The management review requirements of ISO/IEC 27001 apply to the PIMS, so top management must review the privacy extension at planned intervals against the same defined input set and record the resulting decisions.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 66 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • NIST-CSF-GV.OV-01 Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
  • NIST-CSF-GV.OV-02 The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
  • NIST-CSF-GV.OV-03 Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
  • NIST-CSF-GV.PO-02 Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
  • NIST-CSF-GV.RM-01 Risk management objectives are established and agreed to by organizational stakeholders
  • NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes
  • NIST-CSF-GV.RM-07 Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions
  • NIST-CSF-ID.RA-08 Processes for receiving, analyzing, and responding to vulnerability disclosures are established

PCI DSS 4.0 · 5 controls

  • 12.10.2 12.10.2 Annual review and testing of the incident response plan
  • 12.4.2.1 12.4.2.1 Documentation of quarterly operational reviews
  • 12.5.2.1 12.5.2.1 Six-monthly scope confirmation for service providers
  • 12.5.3 12.5.3 Scope review after significant organisational change
  • 12.6.2 12.6.2 Awareness program reviewed annually and updated

ISO 22000:2018 · 3 controls

  • 9.3 Management review
  • 9.3.2 Management review input
  • 9.3.3 Management review output

ISO 37301:2021 · 3 controls

  • 9.3 Management review
  • 9.3.2 Management review inputs
  • 9.3.3 Management review results

ISO 9001:2015 · 3 controls

  • 9.3 Management review
  • 9.3.2 Management review inputs
  • 9.3.3 Management review outputs
  • AUCDR-IS-STEP1 Step 1 - Define and implement security governance for CDR data
  • AUCDR-IS-STEP4 Step 4 - Implement a formal controls assessment program

ISO 27001:2022 · 2 controls

  • 9.3.2 Management review inputs
  • 9.3.3 Management review results
  • ISO-37002-9.3 Management review
  • ISO37002-9.3 Management Review
  • ISO-39001-9.3 Management review
  • ISO39001-9.3 Management Review
  • ISO-41001-9.3 Management review
  • ISO41001-9.3 Management Review
  • ISO-50001-9.4 Management review
  • 9.3 Management review

ISO 56002 · 2 controls

  • ISO-56002-9.3 Management review
  • ISO56002-9.3 Management review

ISO/IEC 27003:2017 · 2 controls

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-PM-27 PM-27 Privacy Reporting
  • SP800-53-PM Program Management Family

SOC 2 · 2 controls

  • SOC2-CC1.2 CC1.2 Board independence and oversight of internal control (COSO principle 2)
  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • AS9100D-9.3 Management Review
  • SPC1-4.6 Management Review

C5 (Germany) · 1 control

  • C5-COM-04 Information on information security performance and management assessment of the ISMS

CIS Controls v8 · 1 control

  • CIS-7.2 Establish and Maintain a Remediation Process

CMMC 2.0 · 1 control

FedRAMP High · 1 control

FedRAMP Moderate · 1 control

ISO 13485:2016 · 1 control

  • 5.6 Management review

ISO 14001:2015 · 1 control

  • 9.3 Management review

ISO 14004:2016 · 1 control

  • 9.3 Management review

ISO 19011:2018 · 1 control

  • 5.5.6 Managing audit programme results

ISO 22301:2019 · 1 control

  • 9.3 Management review

ISO 27002:2022 · 1 control

  • 5.35 Independent review of information security

ISO 27005:2022 · 1 control

  • 10.6 Management review
  • ISO28001-4.18 Management review

ISO 30401 · 1 control

  • ISO30401-9.3 Management review

ISO 37001:2016 · 1 control

  • 9.3 9.3 Management review

ISO 45001:2018 · 1 control

  • 9.3 Management review

ISO 55001:2014 · 1 control

  • 9.3 Management review

ISO/IEC 27031:2011 · 1 control

  • 27031-9.3 Management Review

ISO/IEC 42001:2023 · 1 control

  • 9.3 Management review

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific requirements related to ISO/IEC 27001, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 5.7.3 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 66 it maps to, and the evidence behind each claim, over MCP and REST.