ISO/IEC 27011:2024
ISO/IEC 27011 provides guidelines supporting the implementation of information security controls in telecommunications organizations based on ISO/IEC 27002. It addresses sector-specific security requirements for telecommunications operators including network security, service availability, customer data protection, and lawful interception compliance.
ISO/IEC 27011:2024 is a compliance framework from International with 8 domains and 44 controls that map to 291 other frameworks. The largest domains are Technological (11 controls), Organisational (8 controls), Clause 1-4: Introduction and Framework (7 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Clause 1-4: Introduction and Framework
Clause 5: Organizational Controls for Telecommunications
| Code | Title |
|---|---|
| 27011-5.3 | Segregation of duties |
| 27011-5.4 | Threat intelligence for telecom |
| 27011-5.5 | Information security in project management |
| 27011-5.6 | Supplier relationships and telecom supply chain |
Clause 6: People Controls for Telecommunications
Clause 7: Physical Controls for Telecommunications
Clause 8: Technological Controls for Telecommunications
| Code | Title |
|---|---|
| 27011-8.2 | Network security and segregation |
| 27011-8.3 | Cryptography and key management |
| 27011-8.4 | Logging and monitoring |
| 27011-8.5 | Vulnerability and malware management |
| 27011-8.6 | Data protection and backup |
Organisational
| Code | Title |
|---|---|
| 27011-5.1 | Policies for Information Security in Telecoms |
| 27011-5.10 | Acceptable Use of Customer Data |
| 27011-5.15 | Access Control for Network Elements |
| 27011-5.2 | Information Security Roles in Telecoms |
| 27011-5.22 | Monitoring of Supplier Services |
| 27011-5.23 | Cloud and Hosted Telecoms Services |
| 27011-5.30 | ICT Readiness for Continuity |
| 27011-5.7 | Threat Intelligence for Telecoms |
Physical
| Code | Title |
|---|---|
| 27011-7.10 | Storage Media Handling in Telecoms |
Technological
| Code | Title |
|---|---|
| 27011-8.1 | User Endpoint Devices |
| 27011-8.12 | Data Leakage Prevention for Telecoms |
| 27011-8.15 | Logging of Network and Service Events |
| 27011-8.16 | Monitoring Activities |
| 27011-8.20 | Network Security for Telecoms Core |
| 27011-8.21 | Security of Network Services |
| 27011-8.22 | Segregation of Networks |
| 27011-8.24 | Use of Cryptography |
| 27011-8.27 | Secure System Architecture |
| 27011-8.32 | Change Management for Network |
| 27011-8.7 | Protection Against Malware |
Your Compliance Coverage
If you comply with ISO/IEC 27011:2024, you already cover:
ISO 27002:2022
41%
16 controls mapped
Compare →TISAX - Trusted Information Security Assessment Exchange
31%
12 controls mapped
Compare →NIST Privacy Framework
31%
12 controls mapped
Compare →+ 288 more: AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (28%), NIST SP 800-82 Revision 3: Guide to Industrial Control Systems (ICS) Security (26%)
See all 291 mapped frameworks ↓Maps to 291 other frameworks
What is ISO/IEC 27011:2024 and who does it apply to?
ISO/IEC 27011:2024 is a compliance framework from International with 8 domains and 44 controls. ISO/IEC 27011 provides guidelines supporting the implementation of information security controls in telecommunications organizations based on ISO/IEC 27002. It addresses sector-specific security requirements for telecommunications operators including network security, service availability, customer data protection, and lawful interception compliance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27011:2024 actually require?
ISO/IEC 27011:2024 has 44 controls organised across 8 domains. The largest domains are Technological (11 controls), Organisational (8 controls), Clause 1-4: Introduction and Framework (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27011:2024 do I already cover?
ISO/IEC 27011:2024 maps to 291 other compliance frameworks. The top mapping partners are ISO 27002:2022 (41% coverage), TISAX - Trusted Information Security Assessment Exchange (31% coverage), NIST Privacy Framework (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 27011:2024?
Start your ISO/IEC 27011:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27011:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 44 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required