2026-09-21 · Equipo editorial KeXinMaterials

ISO 27001:2022 + ISO 27002:2022 + ISO 27017 + ISO 27018 + ISO 27701 ISMS Privacidad Familia Maletín B2B Guía

ISO 27001:2022 + ISO 27002:2022 + ISO 27017 + ISO 27018 + ISO 27701 son normas familiares ISMS + privacidad globales. Requerido para IT + cloud + PII + datos sensibles.

ISO 27001:2022 Information Security Management System (ISMS)

ISO/IEC 27001:2022 "Information security, cybersecurity and privacy protection - Information security management systems - Requirements". Edition 3 (2022). Replaces ISO 27001:2013.

ISO/IEC 27001:2022: "Information security, cybersecurity and privacy protection - Information security management systems - Requirements". Edition 3 (2022). Replaces ISO 27001:2013 + ISO 27001:2013/Cor 1:2014 + ISO 27001:2013/Cor 2:2015.

ISMS scope: Information security management system (ISMS) for any organization. Establishes + implements + operates + monitors + reviews + maintains + improves information security.

ISO 27001 structure: Clauses 4-10 (mandatory) + Annex A (normative controls). Clauses: Context + Planning + Support + Operation + Performance evaluation + Improvement.

Clause 4 Context: Understanding organization + interested parties + scope + ISMS scope definition.

Clause 5 Leadership: Top management leadership + commitment + policy + organizational roles + responsibilities.

Clause 6 Planning: Information security risk assessment + treatment + Statement of Applicability (SoA) + risk treatment plan (RTP) + information security objectives.

Clause 7 Support: Resources + competence + awareness + communication + documented information.

Clause 8 Operation: Operational planning + control + risk assessment + risk treatment implementation.

Clause 9 Performance evaluation: Monitoring + measurement + analysis + evaluation + internal audit + management review.

Clause 10 Improvement: Nonconformity + corrective action + continual improvement.

Annex A controls (ISO 27001:2022): 93 controls in 4 themes. (1) Organizational (37 controls). (2) People (8 controls). (4) Physical (14 controls). (5) Technological (34 controls).

ISO 27001 Annex A controls sample: A.5.1 Information security policies. A.6.1 Background verification. A.7.1 Physical security perimeter. A.8.1 User endpoint devices. A.8.5 Secure authentication. A.8.24 Use of cryptography.

ISO 27001 certification: Issued by accredited certification bodies (BSI + TUV + SGS + Bureau Veritas + LRQA + DNV). Audit per ISO 27001 + ISO 27002 guidance + ISO 27005 risk assessment. Certificate valid 3 years with annual surveillance + 3-year re-certification.

Geographic adoption: Adopted as ISO/IEC 27001:2022 (international). Required for EU NIS2 + EU CRA + UK Cyber Essentials + Singapore MAS TRM + JP FIEA + AU CPS 234 + IN DPDPA + BR LGPD.

B2B relevance: For B2B protective cases containing IT + OT + IoT + sensitive information (financial + medical + defense + IP), ISO 27001:2022 certification increasingly required for global enterprise procurement.

ISO 27002:2022 Information Security Controls

ISO/IEC 27002:2022 "Information security, cybersecurity and privacy protection - Information security controls". Edition 3 (2022). Companion to ISO 27001:2022.

ISO/IEC 27002:2022: "Information security, cybersecurity and privacy protection - Information security controls". Edition 3 (2022). Replaces ISO 27002:2013.

ISO 27002 scope: Implementation guidance for Annex A controls of ISO 27001:2022. Provides implementation guidance for each control + implementation examples + relevant standards.

ISO 27002 structure: 4 themes (organizational + people + physical + technological) + 93 controls with implementation guidance.

ISO 27002 organizational controls: 37 controls. Examples: A.5.1 Policies for information security. A.5.7 Threat intelligence. A.5.23 Information security for use of cloud services. A.5.30 ICT readiness for business continuity.

ISO 27002 people controls: 8 controls. Examples: A.6.1 Screening. A.6.3 Information security awareness + education + training. A.6.6 Confidentiality + non-disclosure agreements.

ISO 27002 physical controls: 14 controls. Examples: A.7.1 Physical security perimeter. A.7.2 Physical entry. A.7.9 Security of assets off-premises. A.7.11 Supporting utilities. A.7.13 Equipment maintenance.

ISO 27002 technological controls: 34 controls. Examples: A.8.2 Privileged access rights. A.8.5 Secure authentication. A.8.9 Configuration management. A.8.16 Monitoring activities. A.8.24 Use of cryptography.

ISO 27002 attribute model (NEW in 2022): Each control has 5 attributes: (1) Control type (preventive + detective + corrective). (2) Information security properties (confidentiality + integrity + availability). (3) Cybersecurity concepts (identify + protect + detect + respond + recover). (4) Operational capabilities (governance + asset management + etc.). (5) Security domains.

ISO 27002 implementation: Per ISO 27001 Statement of Applicability (SoA). Select applicable controls + justify exclusions + implement + monitor.

ISO 27002 vs NIST 800-53 mapping: ISO published crosswalk between ISO 27002:2022 + NIST SP 800-53 Rev 5. ISO 27002 has 93 controls; NIST 800-53 has 1000+ controls.

B2B relevance: ISO 27002:2022 implementation guidance essential for ISO 27001 ISMS implementation. Required for audit preparation.

ISO 27017 Cloud Security + ISO 27018 Cloud Privacy

ISO/IEC 27017:2015 (cloud security controls) + ISO/IEC 27018:2019 (cloud privacy) extend ISO 27001 + ISO 27002 to cloud services.

ISO/IEC 27017:2015: "Information technology - Security techniques - Code of practice for information security controls based on ISO/IEC 27002 for cloud services". 2015 edition. Reaffirmed 2021.

ISO 27017 scope: Cloud-specific security controls. 37 additional controls (17 new + 20 modified from ISO 27002). For cloud service providers (CSP) + cloud service customers (CSC).

ISO 27017 new controls: Cloud service customer + cloud service provider shared responsibilities. Asset inventory + return + removal. Virtual + physical network segregation. Cloud service customer access monitoring. Cloud service provider alignment with customer security policies.

ISO 27017 certification: Stand-alone or as add-on to ISO 27001. Issued by accredited certification bodies. Statement of Applicability (SoA) includes cloud-specific controls.

ISO/IEC 27018:2019: "Information technology - Security techniques - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors". 2019 edition. Reaffirmed 2024.

ISO 27018 scope: Cloud service providers (CSP) processing personally identifiable information (PII). Public clouds (B2C + B2B). Apply ISO 27002 controls + additional PII-specific controls.

ISO 27018 new controls: PII controller consent + opt-in. PII processor sub-processing. PII disclosure to third parties. PII data breach notification. PII portability. PII return + deletion at end of service.

ISO 27018 certification: Stand-alone or as add-on to ISO 27001 + ISO 27701. Issued by accredited certification bodies.

Geographic adoption: ISO 27017 + ISO 27018 international. Required for EU GDPR (privacy) + ISO 27001 certification with cloud scope.

B2B relevance: For B2B protective cases containing cloud-connected IT + IoT equipment, ISO 27017 + ISO 27018 certification demonstrates cloud security + privacy compliance for B2B customers.

ISO 27701 Privacy Information Management System (PIMS) + Combined Application

ISO/IEC 27701:2019 "Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management". PIMS (Privacy Information Management System) extension to ISO 27001.

ISO/IEC 27701:2019: "Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management - Requirements and guidelines". 2019 edition.

PIMS scope: Privacy Information Management System (PIMS). Extension to ISMS (ISO 27001). Addresses privacy + data protection requirements (PII controllers + PII processors).

ISO 27701 structure: ISO 27001 clauses 4-10 + Annex A controls (ISO 27002) + Annex B (PII controller additional controls) + Annex C (PII processor additional controls).

Annex B PII controller controls: Collection + processing + consent + opt-out + privacy notice + data subject rights. Sub-contracting + third-party sharing.

Annex C PII processor controls: PII processing per controller instructions + PII confidentiality + PII return + deletion at end of service + sub-processor approval + breach notification.

ISO 27701 + GDPR alignment: ISO 27701 PIMS implements GDPR Article 5 (principles) + Article 6 (lawful basis) + Article 28 (processor) + Article 30 (records) + Article 32 (security) + Article 33 (breach notification) requirements.

ISO 27701 + LGPD (Brazil) alignment: ISO 27701 PIMS implements LGPD principles + lawful basis + DPO + DPIA + breach notification.

ISO 27701 + CCPA (California) + CPRA (California) alignment: ISO 27701 implements CCPA/CPRA consumer rights + opt-out + privacy disclosure + data minimization.

ISO 27701 + China PIPL alignment: ISO 27701 implements PIPL principles + consent + cross-border transfer + DPO + localization.

ISO 27701 certification: Issued by accredited certification bodies. Stand-alone or as add-on to ISO 27001 certification. Certificate valid 3 years.

Geographic adoption: International. Required for EU GDPR + BR LGPD + CA PIPEDA + JP APPI + IN DPDPA + CN PIPL compliance for PII controllers + PII processors.

Combined B2B case: For B2B protective cases containing IT + cloud + PII data + sensitive information, recommend ISO 27001:2022 + ISO 27002:2022 + ISO 27017 (cloud) + ISO 27018 (cloud PII) + ISO 27701 (PIMS). Demonstrates comprehensive information security + privacy management.

B2B procurement workflow: (1) Identify information security + privacy requirements (GDPR + LGPD + PIPL + HIPAA + PCI DSS + etc.). (2) Verify ISO 27001:2022 + ISO 27701 PIMS certification. (3) Cloud-specific ISO 27017 + ISO 27018 if applicable. (4) Verify supplier risk assessment + ISMS scope + PIMS scope. (5) Contract terms: data processing agreement + breach notification + cross-border transfer + audit rights + liability.

B2B recommendation: For B2B protective cases with sensitive IT + cloud + PII, require ISO 27001:2022 + ISO 27002:2022 + ISO 27017 (if cloud) + ISO 27018 (if cloud PII) + ISO 27701 PIMS + ISO 27005 risk assessment, FOB Shenzhen/Ningbo/EXW delivery 30-45 days.

Puntos clave

  • ISO 27001:2022 ISMS Edition 3. 93 Annex A controls in 4 themes. Certification valid 3 years.
  • ISO 27002:2022 implementation guidance. NEW control attribute model (5 attributes).
  • ISO 27017:2015 cloud security. 37 cloud-specific controls (17 new + 20 modified).
  • ISO 27018:2019 cloud PII privacy. For cloud providers processing PII.
  • ISO 27701:2019 PIMS. Extends ISO 27001 to privacy management. Aligns with GDPR + LGPD + PIPL + CCPA/CPRA.
  • Geographic adoption: EU NIS2 + EU CRA + UK Cyber Essentials + SG MAS TRM + AU CPS 234 + IN DPDPA + BR LGPD + CN PIPL + JP APPI.
  • B2B recommendation: Require ISO 27001:2022 + ISO 27002:2022 + ISO 27017 (cloud) + ISO 27018 (cloud PII) + ISO 27701 PIMS, FOB Shenzhen/Ningbo/EXW.

Preguntas frecuentes

q

a

q

a

q

a

q

a

q

a

q

a

q

a