ISO/IEC 27040:2024
ISO/IEC 27040:2024 gives requirements and guidance for the security of data storage: protection of data while stored in ICT systems and in transit across the links associated with storage, covering devices and media, their management, applications and services, and user activity through the lifetime of devices and media and after end of use. Structured on the ISO/IEC 27002:2022 themes: organizational controls (aligning storage with policy, business continuity, compliance), people controls, physical controls (physically secure storage, protected physical interfaces, isolation of storage systems) and technological controls (secure design principles, quality attributes, retention and disposal; system hardening, logging and monitoring, storage vulnerability management; management authentication, authorization and interfaces; encryption and key management for storage, transferred data and data at rest; sanitization by clear, purge and destruct, logical sanitization, cryptographic erase, verification and proof; and the technology areas of direct attached storage, SANs and NAS protocols, Fibre Channel and IP storage, NFS and SMB, cloud storage and CDMI, object storage, data reduction, backups, replication and snapshots, archives and repositories, virtualization, multi-tenancy and autonomous data movement), with Annex A summarizing the labelled requirements and guidance. The storage and backup-plane companion to ISO/IEC 27001 and 27002 and the ISO reference behind backup, media and sanitization controls across the security frameworks.
ISO/IEC 27040:2024 is a compliance framework from International with 4 domains and 45 controls. The largest domains are Clause 10: Technological controls for storage – ISO/IEC 27040:2024 (38 controls), Clause 7: Organizational controls for storage – ISO/IEC 27040:2024 (3 controls), Clause 9: Physical controls for storage – ISO/IEC 27040:2024 (3 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (4)
Clause 10: Technological controls for storage – ISO/IEC 27040:2024
| Code | Title |
|---|---|
| iso-iec-27040-2024::10.10.2 | NFS-based NAS |
| iso-iec-27040-2024::10.10.3 | SMB-based NAS |
| iso-iec-27040-2024::10.11.1 | Securing cloud computing storage |
| iso-iec-27040-2024::10.11.2 | CDMI security |
| iso-iec-27040-2024::10.12 | Object-based storage |
| iso-iec-27040-2024::10.13 | Data reductions |
| iso-iec-27040-2024::10.14.2 | Storage backups |
| iso-iec-27040-2024::10.14.3 | Storage replication |
| iso-iec-27040-2024::10.14.4 | Storage snapshots |
| iso-iec-27040-2024::10.15.2 | Data archives |
| iso-iec-27040-2024::10.15.3 | Data Repositories |
| iso-iec-27040-2024::10.16.1 | Storage virtualization |
| iso-iec-27040-2024::10.16.2 | Storage for virtualized systems |
| iso-iec-27040-2024::10.17 | Secure multi-tenancy |
| iso-iec-27040-2024::10.18 | Secure autonomous data movement |
| iso-iec-27040-2024::10.2.2 | Storage security design principles |
| iso-iec-27040-2024::10.2.3 | Storage system quality attributes |
| iso-iec-27040-2024::10.2.4 | Retention, preservation, and disposal of data |
| iso-iec-27040-2024::10.3.1 | System hardening |
| iso-iec-27040-2024::10.3.2 | Security auditing, accounting, and monitoring |
| iso-iec-27040-2024::10.3.3 | Storage vulnerability management |
| iso-iec-27040-2024::10.4.2 | Authentication and authorization |
| iso-iec-27040-2024::10.4.3 | Secure the management interfaces |
| iso-iec-27040-2024::10.5.2 | Encryption and key management issues |
| iso-iec-27040-2024::10.5.3 | Encryption of storage |
| iso-iec-27040-2024::10.5.4 | Encrypting transferred data |
| iso-iec-27040-2024::10.5.5 | Encrypting data at rest |
| iso-iec-27040-2024::10.6.2 | Selection of sanitization methods |
| iso-iec-27040-2024::10.6.3 | Media-based sanitization |
| iso-iec-27040-2024::10.6.4 | Logical sanitization |
| iso-iec-27040-2024::10.6.5 | Cryptographic erase |
| iso-iec-27040-2024::10.6.6 | Verification of storage sanitization |
| iso-iec-27040-2024::10.6.7 | Proof of sanitization |
| iso-iec-27040-2024::10.7 | Direct attached storage |
| iso-iec-27040-2024::10.8.2 | Storage area networks |
| iso-iec-27040-2024::10.8.3 | Network Attached Storage protocols |
| iso-iec-27040-2024::10.9.1 | Fibre Channel (FC) storage |
| iso-iec-27040-2024::10.9.2 | IP storage |
Clause 7: Organizational controls for storage – ISO/IEC 27040:2024
| Code | Title |
|---|---|
| iso-iec-27040-2024::7.2 | Align storage and policy |
| iso-iec-27040-2024::7.3 | Business continuity management |
| iso-iec-27040-2024::7.4 | Compliance |
Clause 8: People controls for storage – ISO/IEC 27040:2024
| Code | Title |
|---|---|
| iso-iec-27040-2024::8 | People controls for storage |
Clause 9: Physical controls for storage – ISO/IEC 27040:2024
| Code | Title |
|---|---|
| iso-iec-27040-2024::9.2 | Physically secure storage |
| iso-iec-27040-2024::9.3 | Protect physical interfaces to storage |
| iso-iec-27040-2024::9.4 | Isolation of storage systems |
What is ISO/IEC 27040:2024 and who does it apply to?
ISO/IEC 27040:2024 is a compliance framework from International with 4 domains and 45 controls. ISO/IEC 27040:2024 gives requirements and guidance for the security of data storage: protection of data while stored in ICT systems and in transit across the links associated with storage, covering devices and media, their management, applications and services, and user activity through the lifetime of devices and media and after end of use. Structured on the ISO/IEC 27002:2022 themes: organizational controls (aligning storage with policy, business continuity, compliance), people controls, physical controls (physically secure storage, protected physical interfaces, isolation of storage systems) and technological controls (secure design principles, quality attributes, retention and disposal; system hardening, logging and monitoring, storage vulnerability management; management authentication, authorization and interfaces; encryption and key management for storage, transferred data and data at rest; sanitization by clear, purge and destruct, logical sanitization, cryptographic erase, verification and proof; and the technology areas of direct attached storage, SANs and NAS protocols, Fibre Channel and IP storage, NFS and SMB, cloud storage and CDMI, object storage, data reduction, backups, replication and snapshots, archives and repositories, virtualization, multi-tenancy and autonomous data movement), with Annex A summarizing the labelled requirements and guidance. The storage and backup-plane companion to ISO/IEC 27001 and 27002 and the ISO reference behind backup, media and sanitization controls across the security frameworks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO/IEC 27040:2024 actually require?
ISO/IEC 27040:2024 has 45 controls organised across 4 domains. The largest domains are Clause 10: Technological controls for storage – ISO/IEC 27040:2024 (38 controls), Clause 7: Organizational controls for storage – ISO/IEC 27040:2024 (3 controls), Clause 9: Physical controls for storage – ISO/IEC 27040:2024 (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO/IEC 27040:2024 do I already cover?
ISO/IEC 27040:2024 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement ISO/IEC 27040:2024?
Start your ISO/IEC 27040:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27040:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.
Get Started Free →Free forever — no credit card required