ISO/IEC 27010:2015
ISO/IEC 27010 provides guidelines for information security management for inter-sector and inter-organizational communications. It extends ISO 27001/27002 guidance for situations where organizations share information across sector boundaries, within communities of interest, or between organizations. Applicable to information sharing initiatives, ISACs, and trusted communities.
ISO/IEC 27010:2015 is a compliance framework from International with 9 domains and 28 controls that map to 269 other frameworks. The largest domains are Clause 17-18 and Annexes: Continuity and Compliance (6 controls), Clause 11-13: Physical, Operations, and Communications Security (5 controls), Clause 5-6: Information Security Policies and Organization (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (9)
Agreements
| Code | Title |
|---|---|
| 27010-4.2 | Sharing Agreements |
Clause 11-13: Physical, Operations, and Communications Security
| Code | Title |
|---|---|
| 27010-11.1 | Physical Protection |
| 27010-12.1 | Operational Procedures |
| 27010-12.2 | Protection from malware |
| 27010-13.1 | Communications Security |
| 27010-13.2 | Information transfer |
Clause 14-16: System Development, Supplier Relations, and Incident Management
| Code | Title |
|---|---|
| 27010-14.1 | Supplier and Third Party Handling |
| 27010-15.1 | Incident Management |
| 27010-16.1 | Continuity of Sharing |
Clause 17-18 and Annexes: Continuity and Compliance
| Code | Title |
|---|---|
| 27010-17.1 | Compliance |
| 27010-18.1 | Review and Improvement |
| 27010-A | Benefits of information sharing |
| 27010-B | Trust assessment guidance |
| 27010-C | Traffic Light Protocol |
| 27010-D | Information sharing community models |
Clause 5-6: Information Security Policies and Organization
Clause 7-8: Human Resources and Asset Management
Clause 9-10: Access Control and Cryptography
| Code | Title |
|---|---|
| 27010-10.1 | Cryptographic Protection |
| 27010-9.1 | Access Control to Shared Information |
| 27010-9.2 | Authentication of Sources |
Community
| Code | Title |
|---|---|
| 27010-4.1 | Information Sharing Community |
Trust
| Code | Title |
|---|---|
| 27010-19.1 | Trust Anchors and Reputation |
Your Compliance Coverage
If you comply with ISO/IEC 27010:2015, you already cover:
TISAX - Trusted Information Security Assessment Exchange
32%
9 controls mapped
Compare →NIS2 Directive Implementing Acts
29%
8 controls mapped
Compare →Singapore Government Instruction Manual on ICT&SS Management (IM8)
29%
8 controls mapped
Compare →+ 266 more: ISO 28001:2007 Supply Chain Security Management (29%), NIST SP 800-53 Rev 5 (29%)
See all 269 mapped frameworks ↓Maps to 269 other frameworks
What is ISO/IEC 27010:2015 and who does it apply to?
ISO/IEC 27010:2015 is a compliance framework from International with 9 domains and 28 controls. ISO/IEC 27010 provides guidelines for information security management for inter-sector and inter-organizational communications. It extends ISO 27001/27002 guidance for situations where organizations share information across sector boundaries, within communities of interest, or between organizations. Applicable to information sharing initiatives, ISACs, and trusted communities. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27010:2015 actually require?
ISO/IEC 27010:2015 has 28 controls organised across 9 domains. The largest domains are Clause 17-18 and Annexes: Continuity and Compliance (6 controls), Clause 11-13: Physical, Operations, and Communications Security (5 controls), Clause 5-6: Information Security Policies and Organization (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27010:2015 do I already cover?
ISO/IEC 27010:2015 maps to 269 other compliance frameworks. The top mapping partners are TISAX - Trusted Information Security Assessment Exchange (32% coverage), NIS2 Directive Implementing Acts (29% coverage), Singapore Government Instruction Manual on ICT&SS Management (IM8) (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 27010:2015?
Start your ISO/IEC 27010:2015 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27010:2015 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 28 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required