ISO/IEC 27400:2022
ISO/IEC 27400 provides guidelines for security and privacy in IoT (Internet of Things) solutions. It addresses security and privacy risks throughout the IoT device lifecycle and provides controls for IoT service providers, IoT device developers, and IoT users. Covers device security, data protection, communication security, and trustworthiness of IoT ecosystems.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (5)
Clause 1-4: Introduction and Framework
| Code | Title |
|---|---|
| 27011-1 | Scope |
| 27011-2 | Normative references |
| 27011-3 | Terms and definitions |
| 27011-4 | Structure of this document |
| 27400-1 | Scope |
| 27400-3 | Terms and definitions |
| 27400-4 | IoT overview and concepts |
Clause 5: IoT Risk Sources
| Code | Title |
|---|---|
| 27400-5.1 | IoT-specific threat landscape |
| 27400-5.2 | Device-level risks |
| 27400-5.3 | Network and communication risks |
| 27400-5.4 | Data and privacy risks |
Clause 6: IoT Security Controls
| Code | Title |
|---|---|
| 27400-6.1 | Device identity and authentication |
| 27400-6.2 | Secure communication |
| 27400-6.3 | Software and firmware security |
| 27400-6.4 | Secure configuration and hardening |
| 27400-6.5 | Security monitoring and incident response |
Clause 7: IoT Privacy Controls
| Code | Title |
|---|---|
| 27400-7.1 | Data protection and privacy measures |
| 27400-7.2 | Consent and transparency |
| 27400-7.3 | Data minimization and purpose limitation |
| 27400-7.4 | Data retention and deletion |
Clause 8: IoT Lifecycle Security
| Code | Title |
|---|---|
| 27400-8.1 | Design and development security |
| 27400-8.2 | Deployment and operation security |
| 27400-8.3 | Maintenance and update security |
| 27400-8.4 | Decommissioning security |
Maps to 601 other frameworks
Frequently Asked Questions
What is ISO/IEC 27400:2022?
ISO/IEC 27400:2022 is a compliance framework from International with 5 domains and 24 controls. ISO/IEC 27400 provides guidelines for security and privacy in IoT (Internet of Things) solutions. It addresses security and privacy risks throughout the IoT device lifecycle and provides controls for IoT service providers, IoT device developers, and IoT users. Covers device security, data protection, communication security, and trustworthiness of IoT ecosystems. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27400:2022 have?
ISO/IEC 27400:2022 has 24 controls organised across 5 domains. The largest domains are Clause 1-4: Introduction and Framework (7 controls), Clause 6: IoT Security Controls (5 controls), Clause 5: IoT Risk Sources (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27400:2022 map to?
ISO/IEC 27400:2022 maps to 601 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (54% coverage), TISAX — Trusted Information Security Assessment Exchange (50% coverage), CSA STAR (Security, Trust, Assurance, and Risk) (50% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 27400:2022 compliance?
Start your ISO/IEC 27400:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27400:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required