ISO/IEC 27010:2015
ISO/IEC 27010 provides guidelines for information security management for inter-sector and inter-organizational communications. It extends ISO 27001/27002 guidance for situations where organizations share information across sector boundaries, within communities of interest, or between organizations. Applicable to information sharing initiatives, ISACs, and trusted communities.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Clause 11-13: Physical, Operations, and Communications Security
| Code | Title |
|---|---|
| 27010-11.1 | Secure areas |
| 27010-12.1 | Operational procedures and responsibilities |
| 27010-12.2 | Protection from malware |
| 27010-13.1 | Network security management |
| 27010-13.2 | Information transfer |
Clause 14-16: System Development, Supplier Relations, and Incident Management
| Code | Title |
|---|---|
| 27010-14.1 | Security requirements of information systems |
| 27010-15.1 | Information security in supplier relationships |
| 27010-16.1 | Management of information security incidents |
Clause 17-18 and Annexes: Continuity and Compliance
| Code | Title |
|---|---|
| 27010-17.1 | Information security continuity |
| 27010-18.1 | Compliance with legal and contractual requirements |
| 27010-A | Benefits of information sharing |
| 27010-B | Trust assessment guidance |
| 27010-C | Traffic Light Protocol |
| 27010-D | Information sharing community models |
Clause 5-6: Information Security Policies and Organization
| Code | Title |
|---|---|
| 27010-5.1 | Management direction for information security |
| 27010-5.2 | Information sharing community policies |
| 27010-6.1 | Internal organization for inter-sector communication |
| 27010-6.2 | Mobile devices and teleworking |
Clause 7-8: Human Resources and Asset Management
| Code | Title |
|---|---|
| 27010-7.1 | Prior to employment |
| 27010-7.2 | During employment |
| 27010-8.1 | Responsibility for assets |
| 27010-8.2 | Information classification |
Clause 9-10: Access Control and Cryptography
| Code | Title |
|---|---|
| 27010-10.1 | Cryptographic controls |
| 27010-9.1 | Business requirements of access control |
| 27010-9.2 | User access management |
Maps to 471 other frameworks
Frequently Asked Questions
What is ISO/IEC 27010:2015?
ISO/IEC 27010:2015 is a compliance framework from International with 6 domains and 25 controls. ISO/IEC 27010 provides guidelines for information security management for inter-sector and inter-organizational communications. It extends ISO 27001/27002 guidance for situations where organizations share information across sector boundaries, within communities of interest, or between organizations. Applicable to information sharing initiatives, ISACs, and trusted communities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27010:2015 have?
ISO/IEC 27010:2015 has 25 controls organised across 6 domains. The largest domains are Clause 17-18 and Annexes: Continuity and Compliance (6 controls), Clause 11-13: Physical, Operations, and Communications Security (5 controls), Clause 5-6: Information Security Policies and Organization (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27010:2015 map to?
ISO/IEC 27010:2015 maps to 471 other compliance frameworks. The top mapping partners are TISAX — Trusted Information Security Assessment Exchange (44% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (40% coverage), ISO 27001:2022 (40% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 27010:2015 compliance?
Start your ISO/IEC 27010:2015 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27010:2015 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 25 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required