ISO/IEC 27400:2022
ISO/IEC 27400 provides guidelines for security and privacy in IoT (Internet of Things) solutions. It addresses security and privacy risks throughout the IoT device lifecycle and provides controls for IoT service providers, IoT device developers, and IoT users. Covers device security, data protection, communication security, and trustworthiness of IoT ecosystems.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Clause 1-4: Introduction and Framework
| Code | Title |
|---|---|
| 27011-1 | Scope |
| 27011-2 | Normative references |
| 27011-3 | Terms and definitions |
| 27011-4 | Structure of this document |
| 27400-1 | Scope |
| 27400-3 | Terms and definitions |
| 27400-4 | IoT overview and concepts |
Clause 5: IoT Risk Sources
| Code | Title |
|---|---|
| 27400-5.1 | IoT Security and Privacy Governance |
| 27400-5.2 | IoT Risk Assessment |
| 27400-5.3 | Network and communication risks |
| 27400-5.4 | Data and privacy risks |
Clause 6: IoT Security Controls
| Code | Title |
|---|---|
| 27400-6.1 | Secure Device Design |
| 27400-6.2 | Device Identity and Authentication |
| 27400-6.3 | Secure Update Mechanism |
| 27400-6.4 | Default Configuration Security |
| 27400-6.5 | Security monitoring and incident response |
Clause 7: IoT Privacy Controls
| Code | Title |
|---|---|
| 27400-7.1 | Network Security for IoT |
| 27400-7.2 | Gateway Security |
| 27400-7.3 | Data minimization and purpose limitation |
| 27400-7.4 | Data retention and deletion |
Clause 8: IoT Lifecycle Security
| Code | Title |
|---|---|
| 27400-8.1 | Platform and Backend Security |
| 27400-8.2 | Data Protection in IoT |
| 27400-8.3 | Maintenance and update security |
| 27400-8.4 | Decommissioning security |
Data
| Code | Title |
|---|---|
| 27400-8.2 | Data Protection in IoT |
Device
| Code | Title |
|---|---|
| 27400-6.1 | Secure Device Design |
| 27400-6.2 | Device Identity and Authentication |
| 27400-6.3 | Secure Update Mechanism |
| 27400-6.4 | Default Configuration Security |
Governance
| Code | Title |
|---|---|
| 27400-5.1 | IoT Security and Privacy Governance |
Lifecycle
| Code | Title |
|---|---|
| 27400-11.1 | Decommissioning and Disposal |
Network
| Code | Title |
|---|---|
| 27400-7.1 | Network Security for IoT |
| 27400-7.2 | Gateway Security |
Operate
| Code | Title |
|---|---|
| 27400-10.1 | Vulnerability Management for IoT |
| 27400-10.2 | Incident Response for IoT |
| 27400-10.3 | Logging and Monitoring |
Platform
| Code | Title |
|---|---|
| 27400-8.1 | Platform and Backend Security |
Privacy
| Code | Title |
|---|---|
| 27400-9.1 | Privacy by Design for IoT |
| 27400-9.2 | Consent and Transparency |
| 27400-9.3 | Data Subject Rights for IoT |
Risk
| Code | Title |
|---|---|
| 27400-5.2 | IoT Risk Assessment |
Supply Chain
| Code | Title |
|---|---|
| 27400-11.2 | Supplier and Third-Party Management |
Your Compliance Coverage
If you comply with ISO/IEC 27400:2022, you already cover:
FAA Cybersecurity Framework for Aviation
41%
13 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
38%
12 controls mapped
Compare →ILO Nursing Personnel Convention C149 (1977)
38%
12 controls mapped
Compare →+ 622 more: CSA STAR (Security, Trust, Assurance, and Risk) (38%), FTC GLBA Safeguards Rule (16 CFR Part 314) (34%)
See all 625 mapped frameworks ↓Maps to 625 other frameworks
Frequently Asked Questions
What is ISO/IEC 27400:2022?
ISO/IEC 27400:2022 is a compliance framework from International with 15 domains and 42 controls. ISO/IEC 27400 provides guidelines for security and privacy in IoT (Internet of Things) solutions. It addresses security and privacy risks throughout the IoT device lifecycle and provides controls for IoT service providers, IoT device developers, and IoT users. Covers device security, data protection, communication security, and trustworthiness of IoT ecosystems. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ISO/IEC 27400:2022 have?
ISO/IEC 27400:2022 has 42 controls organised across 15 domains. The largest domains are Clause 1-4: Introduction and Framework (7 controls), Clause 6: IoT Security Controls (5 controls), Clause 5: IoT Risk Sources (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ISO/IEC 27400:2022 map to?
ISO/IEC 27400:2022 maps to 625 other compliance frameworks. The top mapping partners are FAA Cybersecurity Framework for Aviation (41% coverage), TISAX — Trusted Information Security Assessment Exchange (38% coverage), ILO Nursing Personnel Convention C149 (1977) (38% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ISO/IEC 27400:2022 compliance?
Start your ISO/IEC 27400:2022 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO/IEC 27400:2022 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required