Back to Frameworks

ISO/IEC 27014:2020

International
v2020
14 domains
39 controls

Information security, cybersecurity and privacy protection - Governance of information security. Provides guidance on concepts, objectives, and processes for the governance of information security. Intended for governing bodies and top management of organizations. Applicable to all types and sizes of organizations.

Unverified

ISO/IEC 27014:2020 is a compliance framework from International with 14 domains and 39 controls that map to 52 other frameworks. The largest domains are Clause 1-4: Introduction and Context (6 controls), Clause 5: Guiding Principles (6 controls), Clause 7: Governance Objectives and Processes (6 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykControl text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (14)

Assure

1 controls
Controls in the Assure domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-6.5Assure Process

Clause 1-4: Introduction and Context

6 controls
Controls in the Clause 1-4: Introduction and Context domain of ISO/IEC 27014:20202 controls
CodeTitle
27014-4Concepts
29134-4General overview

Clause 5: Guiding Principles

6 controls
Controls in the Clause 5: Guiding Principles domain of ISO/IEC 27014:20206 controls
CodeTitle
27014-5.1Governance Objectives
27014-5.2Governance Principles
27014-5.3Effectiveness
27014-5.4Efficiency
27014-5.5Alignment
27014-5.6Continuous improvement

Clause 6: Governance Relationships

3 controls
Controls in the Clause 6: Governance Relationships domain of ISO/IEC 27014:20203 controls
CodeTitle
27014-6.1Evaluate Process
27014-6.2Direct Process
27014-6.3Monitor Process

Clause 7.3: Governance Processes

5 controls
Controls in the Clause 7.3: Governance Processes domain of ISO/IEC 27014:20205 controls
CodeTitle
27014-7.3.1Evaluate
27014-7.3.2Direct
27014-7.3.3Monitor
27014-7.3.4Communicate
27014-7.3.5Assure

Clause 7: Governance Objectives and Processes

6 controls
Controls in the Clause 7: Governance Objectives and Processes domain of ISO/IEC 27014:20206 controls
CodeTitle
27014-7.2.1Objective 1: Establish comprehensive information security
27014-7.2.2Objective 2: Risk-based decision making
27014-7.2.3Objective 3: Set direction of acquisition
27014-7.2.4Objective 4: Ensure conformance
27014-7.2.5Objective 5: Foster security-positive culture
27014-7.2.6Objective 6: Performance relative to business outcomes

Communicate

3 controls
Controls in the Communicate domain of ISO/IEC 27014:20203 controls
CodeTitle
27014-6.4Communicate Process
27014-9.1Stakeholder Engagement
27014-9.2Reporting to External Parties

Conformance

1 controls
Controls in the Conformance domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-8.5Conformance and Compliance

Improvement

1 controls
Controls in the Improvement domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-10.1Continual Improvement of Governance

Integration

1 controls
Controls in the Integration domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-8.1Alignment with Enterprise Governance

Monitor

1 controls
Controls in the Monitor domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-8.4Performance Measurement

Resources

1 controls
Controls in the Resources domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-8.3Resource Optimisation

Risk

1 controls
Controls in the Risk domain of ISO/IEC 27014:20201 controls
CodeTitle
27014-8.2Risk Appetite and Tolerance

Roles

3 controls
Controls in the Roles domain of ISO/IEC 27014:20203 controls
CodeTitle
27014-7.1Roles and Responsibilities of Governing Body
27014-7.2Roles of Executive Management
27014-7.3Relationship Between Governing Body and Management

Your Compliance Coverage

If you comply with ISO/IEC 27014:2020, you already cover:

Maps to 52 other frameworks

35 total controls
ISO 37001:2016
1 source controls mapped|1 target controls covered
3%
ISO/IEC 38500:2024
1 source controls mapped|1 target controls covered
3%
SQF Code Edition 9 - Safe Quality Food
1 source controls mapped|1 target controls covered
3%
Voluntary Principles on Security and Human Rights (VPs)
1 source controls mapped|1 target controls covered
3%
UK FCA/PRA Operational Resilience Framework
1 source controls mapped|1 target controls covered
3%
TISAX - Trusted Information Security Assessment Exchange
1 source controls mapped|1 target controls covered
3%
SWIFT CSCF
1 source controls mapped|1 target controls covered
3%
SA8000:2014 - Social Accountability Standard
1 source controls mapped|1 target controls covered
3%
PIC/S Guide to Good Manufacturing Practice for Medicinal Products
1 source controls mapped|1 target controls covered
3%
NIST SP 800-39
1 source controls mapped|1 target controls covered
3%
NIST SP 800-37
1 source controls mapped|1 target controls covered
3%
NIST SP 800-30
1 source controls mapped|1 target controls covered
3%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
3%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
1 source controls mapped|1 target controls covered
3%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|1 target controls covered
3%
ICH E6(R3) - Good Clinical Practice
1 source controls mapped|2 target controls covered
3%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
3%
IATF 16949:2016 - Quality Management System for Automotive Production
1 source controls mapped|2 target controls covered
3%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
1 source controls mapped|1 target controls covered
3%
German Supply Chain Due Diligence Act (LkSG)
1 source controls mapped|1 target controls covered
3%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|2 target controls covered
3%
BRCGS Global Standard for Food Safety Issue 9
1 source controls mapped|2 target controls covered
3%
ISO 31000
1 source controls mapped|1 target controls covered
3%
ISO/IEC 27003:2017
1 source controls mapped|2 target controls covered
3%
ISO 9001
1 source controls mapped|3 target controls covered
3%
ISO 27005
1 source controls mapped|1 target controls covered
3%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
1 source controls mapped|1 target controls covered
3%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
1 source controls mapped|2 target controls covered
3%
AS9100D - Aerospace Quality Management System
1 source controls mapped|1 target controls covered
3%
ISO 45001
1 source controls mapped|1 target controls covered
3%
South Korea ISMS-P
1 source controls mapped|1 target controls covered
3%
EASA Part-IS - Information Security in Aviation
1 source controls mapped|1 target controls covered
3%
3%
ISO 30401
1 source controls mapped|1 target controls covered
3%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|2 target controls covered
3%
AICPA Privacy Management Framework (PMF)
1 source controls mapped|1 target controls covered
3%
ISO 22000
1 source controls mapped|1 target controls covered
3%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|2 target controls covered
3%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|1 target controls covered
3%
ISO 19011
1 source controls mapped|1 target controls covered
3%
ISO 37301
1 source controls mapped|1 target controls covered
3%
ISO 56002
1 source controls mapped|1 target controls covered
3%
ISO 55001
1 source controls mapped|1 target controls covered
3%
Aged Care Quality Standards 2019 (repealed edition)
1 source controls mapped|1 target controls covered
3%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
3%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|1 target controls covered
3%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
3%
ISO 39001:2012 - Road Traffic Safety Management
1 source controls mapped|1 target controls covered
3%
ISO 37001
1 source controls mapped|1 target controls covered
3%

What is ISO/IEC 27014:2020 and who does it apply to?

ISO/IEC 27014:2020 is a compliance framework from International with 14 domains and 39 controls. Information security, cybersecurity and privacy protection - Governance of information security. Provides guidance on concepts, objectives, and processes for the governance of information security. Intended for governing bodies and top management of organizations. Applicable to all types and sizes of organizations. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 27014:2020 actually require?

ISO/IEC 27014:2020 has 39 controls organised across 14 domains. The largest domains are Clause 1-4: Introduction and Context (6 controls), Clause 5: Guiding Principles (6 controls), Clause 7: Governance Objectives and Processes (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 27014:2020 do I already cover?

ISO/IEC 27014:2020 maps to 52 other compliance frameworks. The top mapping partners are ISO 37001:2016 (3% coverage), ISO/IEC 38500:2024 (3% coverage), SQF Code Edition 9 - Safe Quality Food (3% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ISO/IEC 27014:2020?

Start your ISO/IEC 27014:2020 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27014:2020 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 39 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required