Back to Frameworks

ISO/IEC 27040:2024

International
v2024 (second edition)
4 domains
45 controls

ISO/IEC 27040:2024 gives requirements and guidance for the security of data storage: protection of data while stored in ICT systems and in transit across the links associated with storage, covering devices and media, their management, applications and services, and user activity through the lifetime of devices and media and after end of use. Structured on the ISO/IEC 27002:2022 themes: organizational controls (aligning storage with policy, business continuity, compliance), people controls, physical controls (physically secure storage, protected physical interfaces, isolation of storage systems) and technological controls (secure design principles, quality attributes, retention and disposal; system hardening, logging and monitoring, storage vulnerability management; management authentication, authorization and interfaces; encryption and key management for storage, transferred data and data at rest; sanitization by clear, purge and destruct, logical sanitization, cryptographic erase, verification and proof; and the technology areas of direct attached storage, SANs and NAS protocols, Fibre Channel and IP storage, NFS and SMB, cloud storage and CDMI, object storage, data reduction, backups, replication and snapshots, archives and repositories, virtualization, multi-tenancy and autonomous data movement), with Annex A summarizing the labelled requirements and guidance. The storage and backup-plane companion to ISO/IEC 27001 and 27002 and the ISO reference behind backup, media and sanitization controls across the security frameworks.

Verified

ISO/IEC 27040:2024 is a compliance framework from International with 4 domains and 45 controls. The largest domains are Clause 10: Technological controls for storage – ISO/IEC 27040:2024 (38 controls), Clause 7: Organizational controls for storage – ISO/IEC 27040:2024 (3 controls), Clause 9: Physical controls for storage – ISO/IEC 27040:2024 (3 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard Blokdyk

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (4)

Clause 10: Technological controls for storage – ISO/IEC 27040:2024

38 controls
Controls in the Clause 10: Technological controls for storage – ISO/IEC 27040:2024 domain of ISO/IEC 27040:202438 controls
CodeTitle
iso-iec-27040-2024::10.10.2NFS-based NAS
iso-iec-27040-2024::10.10.3SMB-based NAS
iso-iec-27040-2024::10.11.1Securing cloud computing storage
iso-iec-27040-2024::10.11.2CDMI security
iso-iec-27040-2024::10.12Object-based storage
iso-iec-27040-2024::10.13Data reductions
iso-iec-27040-2024::10.14.2Storage backups
iso-iec-27040-2024::10.14.3Storage replication
iso-iec-27040-2024::10.14.4Storage snapshots
iso-iec-27040-2024::10.15.2Data archives
iso-iec-27040-2024::10.15.3Data Repositories
iso-iec-27040-2024::10.16.1Storage virtualization
iso-iec-27040-2024::10.16.2Storage for virtualized systems
iso-iec-27040-2024::10.17Secure multi-tenancy
iso-iec-27040-2024::10.18Secure autonomous data movement
iso-iec-27040-2024::10.2.2Storage security design principles
iso-iec-27040-2024::10.2.3Storage system quality attributes
iso-iec-27040-2024::10.2.4Retention, preservation, and disposal of data
iso-iec-27040-2024::10.3.1System hardening
iso-iec-27040-2024::10.3.2Security auditing, accounting, and monitoring
iso-iec-27040-2024::10.3.3Storage vulnerability management
iso-iec-27040-2024::10.4.2Authentication and authorization
iso-iec-27040-2024::10.4.3Secure the management interfaces
iso-iec-27040-2024::10.5.2Encryption and key management issues
iso-iec-27040-2024::10.5.3Encryption of storage
iso-iec-27040-2024::10.5.4Encrypting transferred data
iso-iec-27040-2024::10.5.5Encrypting data at rest
iso-iec-27040-2024::10.6.2Selection of sanitization methods
iso-iec-27040-2024::10.6.3Media-based sanitization
iso-iec-27040-2024::10.6.4Logical sanitization
iso-iec-27040-2024::10.6.5Cryptographic erase
iso-iec-27040-2024::10.6.6Verification of storage sanitization
iso-iec-27040-2024::10.6.7Proof of sanitization
iso-iec-27040-2024::10.7Direct attached storage
iso-iec-27040-2024::10.8.2Storage area networks
iso-iec-27040-2024::10.8.3Network Attached Storage protocols
iso-iec-27040-2024::10.9.1Fibre Channel (FC) storage
iso-iec-27040-2024::10.9.2IP storage

Clause 7: Organizational controls for storage – ISO/IEC 27040:2024

3 controls
Controls in the Clause 7: Organizational controls for storage – ISO/IEC 27040:2024 domain of ISO/IEC 27040:20243 controls
CodeTitle
iso-iec-27040-2024::7.2Align storage and policy
iso-iec-27040-2024::7.3Business continuity management
iso-iec-27040-2024::7.4Compliance

Clause 8: People controls for storage – ISO/IEC 27040:2024

1 controls
Controls in the Clause 8: People controls for storage – ISO/IEC 27040:2024 domain of ISO/IEC 27040:20241 controls
CodeTitle
iso-iec-27040-2024::8People controls for storage

Clause 9: Physical controls for storage – ISO/IEC 27040:2024

3 controls
Controls in the Clause 9: Physical controls for storage – ISO/IEC 27040:2024 domain of ISO/IEC 27040:20243 controls
CodeTitle
iso-iec-27040-2024::9.2Physically secure storage
iso-iec-27040-2024::9.3Protect physical interfaces to storage
iso-iec-27040-2024::9.4Isolation of storage systems

What is ISO/IEC 27040:2024 and who does it apply to?

ISO/IEC 27040:2024 is a compliance framework from International with 4 domains and 45 controls. ISO/IEC 27040:2024 gives requirements and guidance for the security of data storage: protection of data while stored in ICT systems and in transit across the links associated with storage, covering devices and media, their management, applications and services, and user activity through the lifetime of devices and media and after end of use. Structured on the ISO/IEC 27002:2022 themes: organizational controls (aligning storage with policy, business continuity, compliance), people controls, physical controls (physically secure storage, protected physical interfaces, isolation of storage systems) and technological controls (secure design principles, quality attributes, retention and disposal; system hardening, logging and monitoring, storage vulnerability management; management authentication, authorization and interfaces; encryption and key management for storage, transferred data and data at rest; sanitization by clear, purge and destruct, logical sanitization, cryptographic erase, verification and proof; and the technology areas of direct attached storage, SANs and NAS protocols, Fibre Channel and IP storage, NFS and SMB, cloud storage and CDMI, object storage, data reduction, backups, replication and snapshots, archives and repositories, virtualization, multi-tenancy and autonomous data movement), with Annex A summarizing the labelled requirements and guidance. The storage and backup-plane companion to ISO/IEC 27001 and 27002 and the ISO reference behind backup, media and sanitization controls across the security frameworks. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ISO/IEC 27040:2024 actually require?

ISO/IEC 27040:2024 has 45 controls organised across 4 domains. The largest domains are Clause 10: Technological controls for storage – ISO/IEC 27040:2024 (38 controls), Clause 7: Organizational controls for storage – ISO/IEC 27040:2024 (3 controls), Clause 9: Physical controls for storage – ISO/IEC 27040:2024 (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ISO/IEC 27040:2024 do I already cover?

ISO/IEC 27040:2024 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I implement ISO/IEC 27040:2024?

Start your ISO/IEC 27040:2024 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27040:2024 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 45 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required