ISO/IEC 27031:2011
Information technology - Security techniques - Guidelines for information and communication technology readiness for business continuity. Provides a framework of methods and processes for organizations to improve ICT readiness to support business operations during disruptions. Describes the concepts and principles of ICT readiness for business continuity (IRBC).
ISO/IEC 27031:2011 is a compliance framework from International with 9 domains and 27 controls that map to 307 other frameworks. The largest domains are Annexes: Supporting Guidance (4 controls), Clause 4-5: Overview and IRBC Concepts (4 controls), Clause 8: IRBC Implementation (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (9)
Annexes: Supporting Guidance
Clause 4-5: Overview and IRBC Concepts
Clause 6: IRBC Relationship to BCM
Clause 7: IRBC Planning and Objectives
Clause 8: IRBC Implementation
Clause 9: Monitor and Review
Implement
| Code | Title |
|---|---|
| 27031-10.3 | Communication During Incidents |
| 27031-7.3 | Incident Response Structure |
| 27031-7.4 | IRBC Plans |
| 27031-7.5 | Awareness and Training |
Improve
| Code | Title |
|---|---|
| 27031-10.1 | Continual Improvement |
Strategy
| Code | Title |
|---|---|
| 27031-10.2 | Supplier Continuity Arrangements |
Your Compliance Coverage
If you comply with ISO/IEC 27031:2011, you already cover:
PSD2 SCA
30%
8 controls mapped
Compare →OSFI B-13
30%
8 controls mapped
Compare →Open Banking Security
30%
8 controls mapped
Compare →+ 304 more: Monetary Authority of Singapore Technology Risk Management Guidelines (30%), HKMA SPM (30%)
See all 307 mapped frameworks ↓Maps to 307 other frameworks
What is ISO/IEC 27031:2011 and who does it apply to?
ISO/IEC 27031:2011 is a compliance framework from International with 9 domains and 27 controls. Information technology - Security techniques - Guidelines for information and communication technology readiness for business continuity. Provides a framework of methods and processes for organizations to improve ICT readiness to support business operations during disruptions. Describes the concepts and principles of ICT readiness for business continuity (IRBC). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27031:2011 actually require?
ISO/IEC 27031:2011 has 27 controls organised across 9 domains. The largest domains are Annexes: Supporting Guidance (4 controls), Clause 4-5: Overview and IRBC Concepts (4 controls), Clause 8: IRBC Implementation (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27031:2011 do I already cover?
ISO/IEC 27031:2011 maps to 307 other compliance frameworks. The top mapping partners are PSD2 SCA (30% coverage), OSFI B-13 (30% coverage), Open Banking Security (30% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO/IEC 27031:2011?
Start your ISO/IEC 27031:2011 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27031:2011 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 27 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required