ISO/IEC 27010:2015
ISO/IEC 27010 provides guidelines for information security management for inter-sector and inter-organizational communications. It extends ISO 27001/27002 guidance for situations where organizations share information across sector boundaries, within communities of interest, or between organizations. Applicable to information sharing initiatives, ISACs, and trusted communities.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (24)
Access Control
| Code | Title |
|---|---|
| 27010-9.1 | Access Control to Shared Information |
| 27010-9.2 | Authentication of Sources |
Agreements
| Code | Title |
|---|---|
| 27010-4.2 | Sharing Agreements |
Classification
| Code | Title |
|---|---|
| 27010-7.1 | Information Classification for Sharing |
Clause 11-13: Physical, Operations, and Communications Security
| Code | Title |
|---|---|
| 27010-11.1 | Physical Protection |
| 27010-12.1 | Operational Procedures |
| 27010-12.2 | Protection from malware |
| 27010-13.1 | Communications Security |
| 27010-13.2 | Information transfer |
Clause 14-16: System Development, Supplier Relations, and Incident Management
| Code | Title |
|---|---|
| 27010-14.1 | Supplier and Third Party Handling |
| 27010-15.1 | Incident Management |
| 27010-16.1 | Continuity of Sharing |
Clause 17-18 and Annexes: Continuity and Compliance
| Code | Title |
|---|---|
| 27010-17.1 | Compliance |
| 27010-18.1 | Review and Improvement |
| 27010-A | Benefits of information sharing |
| 27010-B | Trust assessment guidance |
| 27010-C | Traffic Light Protocol |
| 27010-D | Information sharing community models |
Clause 5-6: Information Security Policies and Organization
| Code | Title |
|---|---|
| 27010-5.1 | Management Direction |
| 27010-5.2 | Information sharing community policies |
| 27010-6.1 | Roles and Responsibilities |
| 27010-6.2 | Contact with Authorities |
Clause 7-8: Human Resources and Asset Management
| Code | Title |
|---|---|
| 27010-7.1 | Information Classification for Sharing |
| 27010-7.2 | Handling Shared Information |
| 27010-8.1 | Membership Onboarding |
| 27010-8.2 | Membership Termination |
Clause 9-10: Access Control and Cryptography
| Code | Title |
|---|---|
| 27010-10.1 | Cryptographic Protection |
| 27010-9.1 | Access Control to Shared Information |
| 27010-9.2 | Authentication of Sources |
Communications
| Code | Title |
|---|---|
| 27010-13.1 | Communications Security |
Community
| Code | Title |
|---|---|
| 27010-4.1 | Information Sharing Community |
Compliance
| Code | Title |
|---|---|
| 27010-17.1 | Compliance |
Continuity
| Code | Title |
|---|---|
| 27010-16.1 | Continuity of Sharing |
Cryptography
| Code | Title |
|---|---|
| 27010-10.1 | Cryptographic Protection |
Handling
| Code | Title |
|---|---|
| 27010-7.2 | Handling Shared Information |
Improvement
| Code | Title |
|---|---|
| 27010-18.1 | Review and Improvement |
Incidents
| Code | Title |
|---|---|
| 27010-15.1 | Incident Management |
Membership
| Code | Title |
|---|---|
| 27010-8.1 | Membership Onboarding |
| 27010-8.2 | Membership Termination |
Operations
| Code | Title |
|---|---|
| 27010-12.1 | Operational Procedures |
Organisation
| Code | Title |
|---|---|
| 27010-6.1 | Roles and Responsibilities |
| 27010-6.2 | Contact with Authorities |
Physical
| Code | Title |
|---|---|
| 27010-11.1 | Physical Protection |
Policy
| Code | Title |
|---|---|
| 27010-5.1 | Management Direction |
Suppliers
| Code | Title |
|---|---|
| 27010-14.1 | Supplier and Third Party Handling |
Trust
| Code | Title |
|---|---|
| 27010-19.1 | Trust Anchors and Reputation |
Your Compliance Coverage
If you comply with ISO/IEC 27010:2015, you already cover:
TISAX — Trusted Information Security Assessment Exchange
39%
11 controls mapped
Compare →CFTC System Safeguards (17 CFR 37, 38, 39, 49)
36%
10 controls mapped
Compare →ISO 27001:2022
36%
10 controls mapped
Compare →+ 480 more: NIS2 Directive Implementing Acts (36%), CSA CCM v4 (36%)
See all 483 mapped frameworks ↓Maps to 483 other frameworks
Frequently Asked Questions
What is ISO/IEC 27010:2015?
ISO/IEC 27010:2015 is a compliance framework from International with 24 domains and 46 controls. ISO/IEC 27010 provides guidelines for information security management for inter-sector and inter-organizational communications. It extends ISO 27001/27002 guidance for situations where organizations share information across sector boundaries, within communities of interest, or between organizations. Applicable to information sharing initiatives, ISACs, and trusted communities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27010:2015 have?
ISO/IEC 27010:2015 has 46 controls organised across 24 domains. The largest domains are Clause 17-18 and Annexes: Continuity and Compliance (6 controls), Clause 11-13: Physical, Operations, and Communications Security (5 controls), Clause 5-6: Information Security Policies and Organization (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27010:2015 map to?
ISO/IEC 27010:2015 maps to 483 other compliance frameworks. The top mapping partners are TISAX — Trusted Information Security Assessment Exchange (39% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (36% coverage), ISO 27001:2022 (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 27010:2015 compliance?
Start your ISO/IEC 27010:2015 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27010:2015 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 46 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required