ISO 27018
Code of practice for protection of PII in public clouds acting as PII processors
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (10)
Data Lifecycle
| Code | Title |
|---|---|
| A.12.2 | Return, transfer and disposal of PII |
ISO 27018: Cloud Governance
Governance of cloud security (ISO 27018)
| Code | Title |
|---|---|
| ISO27018-01 | Shared responsibility model definition |
| ISO27018-02 | Cloud security policy and strategy |
| ISO27018-03 | Cloud risk assessment |
| ISO27018-04 | Regulatory compliance for cloud services |
| ISO27018-05 | Cloud security roles and responsibilities |
ISO 27018: Cloud Infrastructure Security
Securing cloud infrastructure (ISO 27018)
| Code | Title |
|---|---|
| ISO27018-16 | Virtual network segmentation |
| ISO27018-17 | Container and serverless security |
| ISO27018-18 | Cloud workload protection |
| ISO27018-19 | Image and template hardening |
| ISO27018-20 | Cloud configuration management |
ISO 27018: Cloud Operations & Monitoring
Operating and monitoring cloud securely (ISO 27018)
| Code | Title |
|---|---|
| ISO27018-21 | Cloud security monitoring and logging |
| ISO27018-22 | Incident response in cloud |
| ISO27018-23 | Cloud vulnerability management |
| ISO27018-24 | Cloud change management |
| ISO27018-25 | Service level agreement management |
ISO 27018: Data Protection in Cloud
Protecting data in cloud services (ISO 27018)
| Code | Title |
|---|---|
| ISO27018-11 | Data classification for cloud |
| ISO27018-12 | Encryption of cloud-stored data |
| ISO27018-13 | Data residency and sovereignty |
| ISO27018-14 | Data backup and recovery in cloud |
| ISO27018-15 | Secure data deletion in cloud |
ISO 27018: Identity & Access in Cloud
Identity management in cloud environments (ISO 27018)
| Code | Title |
|---|---|
| ISO27018-06 | Cloud identity management |
| ISO27018-07 | Multi-factor authentication for cloud |
| ISO27018-08 | Privileged access in cloud environments |
| ISO27018-09 | Federation and single sign-on |
| ISO27018-10 | API security and access tokens |
Incident
| Code | Title |
|---|---|
| A.12.1 | Notification of a data breach |
PII Principles
| Code | Title |
|---|---|
| A.1.1 | Consent and choice |
| A.2.1 | Purpose legitimacy and specification |
| A.3.1 | Collection limitation |
| A.4.1 | Data minimization |
| A.5.1 | Use, retention and disclosure limitation |
| A.6.1 | Accuracy and quality |
| A.7.1 | Openness, transparency and notice |
| A.8.1 | Individual participation and access |
| A.9.1 | Accountability |
Privacy by Design
| Code | Title |
|---|---|
| A.11.1 | Geographical location of PII |
| A.11.2 | Intended destination of PII |
Security
| Code | Title |
|---|---|
| A.10.1 | Information security |
| A.10.2 | Confidentiality obligations of personnel |
| A.10.3 | Restriction of creation of hardcopy material |
| A.10.4 | Control and logging of data restoration |
| A.10.5 | Protection of data on storage media leaving premises |
| A.10.6 | PII transmission |
| A.10.7 | Disclosure of PII |
Your Compliance Coverage
If you comply with ISO 27018, you already cover:
NIST SP 800-146
42%
19 controls mapped
Compare →NIST SP 800-145
42%
19 controls mapped
Compare →NIST SP 800-144
42%
19 controls mapped
Compare →+ 260 more: MTCS (Singapore) (42%), ISO 27017 (42%)
See all 263 mapped frameworks ↓Maps to 263 other frameworks
Frequently Asked Questions
What is ISO 27018?
ISO 27018 is a compliance framework from International with 10 domains and 45 controls. Code of practice for protection of PII in public clouds acting as PII processors It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO 27018 have?
ISO 27018 has 45 controls organised across 10 domains. The largest domains are PII Principles (9 controls), Security (7 controls), ISO 27018: Cloud Governance (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO 27018 map to?
ISO 27018 maps to 263 other compliance frameworks. The top mapping partners are NIST SP 800-146 (42% coverage), NIST SP 800-145 (42% coverage), NIST SP 800-144 (42% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO 27018 compliance?
Start your ISO 27018 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 27018 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required