ISO/IEC 27011:2024
ISO/IEC 27011 provides guidelines supporting the implementation of information security controls in telecommunications organizations based on ISO/IEC 27002. It addresses sector-specific security requirements for telecommunications operators including network security, service availability, customer data protection, and lawful interception compliance.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
Clause 1-4: Introduction and Framework
| Code | Title |
|---|---|
| 27011-1 | Scope |
| 27011-2 | Normative references |
| 27011-3 | Terms and definitions |
| 27011-4 | Structure of this document |
| 27400-1 | Scope |
| 27400-3 | Terms and definitions |
| 27400-4 | IoT overview and concepts |
Clause 5: Organizational Controls for Telecommunications
| Code | Title |
|---|---|
| 27011-5.1 | Policies for information security |
| 27011-5.2 | Information security roles and responsibilities |
| 27011-5.3 | Segregation of duties |
| 27011-5.4 | Threat intelligence for telecom |
| 27011-5.5 | Information security in project management |
| 27011-5.6 | Supplier relationships and telecom supply chain |
Clause 6: People Controls for Telecommunications
| Code | Title |
|---|---|
| 27011-6.1 | Screening |
| 27011-6.2 | Terms and conditions of employment |
| 27011-6.3 | Information security awareness, education and training |
| 27011-6.4 | Remote working |
Clause 7: Physical Controls for Telecommunications
| Code | Title |
|---|---|
| 27011-7.1 | Physical security perimeters |
| 27011-7.2 | Physical entry and securing offices |
| 27011-7.3 | Equipment protection |
| 27011-7.4 | Storage media and equipment disposal |
Clause 8: Technological Controls for Telecommunications
| Code | Title |
|---|---|
| 27011-8.1 | User endpoint devices and privileged access |
| 27011-8.2 | Network security and segregation |
| 27011-8.3 | Cryptography and key management |
| 27011-8.4 | Logging and monitoring |
| 27011-8.5 | Vulnerability and malware management |
| 27011-8.6 | Data protection and backup |
Network and Service Security
User plane, control plane, and SBA security
Maps to 609 other frameworks
Frequently Asked Questions
What is ISO/IEC 27011:2024?
ISO/IEC 27011:2024 is a compliance framework from International with 6 domains and 27 controls. ISO/IEC 27011 provides guidelines supporting the implementation of information security controls in telecommunications organizations based on ISO/IEC 27002. It addresses sector-specific security requirements for telecommunications operators including network security, service availability, customer data protection, and lawful interception compliance. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27011:2024 have?
ISO/IEC 27011:2024 has 27 controls organised across 6 domains. The largest domains are Clause 1-4: Introduction and Framework (7 controls), Clause 5: Organizational Controls for Telecommunications (6 controls), Clause 8: Technological Controls for Telecommunications (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27011:2024 map to?
ISO/IEC 27011:2024 maps to 609 other compliance frameworks. The top mapping partners are TISAX — Trusted Information Security Assessment Exchange (63% coverage), CFTC System Safeguards (17 CFR 37, 38, 39, 49) (59% coverage), GLI-33 — Gaming Laboratories International Event Wagering Systems (59% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 27011:2024 compliance?
Start your ISO/IEC 27011:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27011:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 27 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required