Skip to content

    ISO/IEC 27001:2022 (ISMS clauses) to GDPR control mapping

    ISO/IEC 27001:2022 (ISMS clauses) and GDPR both map to 29 NIST SP 800-53 controls. Every one is listed below, with the controls on each side that map to it.

    Shared NIST 800-53 controls
    29
    ISO/IEC 27001:2022 (ISMS clauses) controls involved
    19
    GDPR controls involved
    7
    NIST 800-53 families touched
    20

    How this pairing is derived

    Both frameworks are mapped to NIST SP 800-53 Rev 5 in the source dataset, so the ground they share is the set of NIST controls they both reference. That set is what the table shows. It is not an authored ISO/IEC 27001:2022 (ISMS clauses) to GDPR crosswalk: two controls on the same row are related through the NIST control between them, not asserted to be equivalent to each other.

    Shared controls in full

    NIST SP 800-53 Rev 5 controls mapped by both ISO/IEC 27001:2022 (ISMS clauses) and GDPR, with the controls on each side that map to them.
    NIST 800-53 controlFamilyISO/IEC 27001:2022 (ISMS clauses) controlsGDPR controls
    AC-1Policy and ProceduresACAccess Control5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    AT-1Policy and ProceduresATAwareness and Training5.1, 5.2, 7.4, 7.5.1, 7.5.2, 7.5.3Art 24.2
    AU-1Policy and ProceduresAUAudit and Accountability5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    CA-1Policy and ProceduresCAAssessment, Authorization, and Monitoring5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    CA-7Continuous MonitoringCAAssessment, Authorization, and Monitoring10.1, 8.1Art 32.1
    CA-7(1)Independent AssessmentCAAssessment, Authorization, and Monitoring10.1, 8.1Art 32.1
    CM-1Policy and ProceduresCMConfiguration Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    CP-1Policy and ProceduresCPContingency Planning5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2, Art 32.1
    IA-1Policy and ProceduresIAIdentification and Authentication5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    IR-1Policy and ProceduresIRIncident Response5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    MA-1Policy and ProceduresMAMaintenance5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    PE-1Policy and ProceduresPEPhysical and Environmental Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    PL-1Policy and ProceduresPLPlanning4.1, 5.1, 5.2, 7.5.1, 7.5.2, 7.5.3, 9.1, 9.2.1, 9.2.2Art 24.2
    RA-1Policy and ProceduresRARisk Assessment5.1, 5.2, 6.1.1, 6.1.2, 7.5.1, 7.5.2, 7.5.3, 8.2Art 24.2, Art 32.2
    SA-1Policy and ProceduresSASystem and Services Acquisition5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    SC-1Policy and ProceduresSCSystem and Communications Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    SI-1Policy and ProceduresSISystem and Information Integrity5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    MP-1Policy and ProceduresMPMedia Protection5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2
    PS-1Policy and ProceduresPSPersonnel Security5.1, 5.2, 7.2, 7.3, 7.5.1, 7.5.2, 7.5.3Art 24.2
    PS-2Position Risk DesignationPSPersonnel Security7.2Art 32.4
    PS-9Position DescriptionsPSPersonnel Security5.3, 7.3Art 32.4
    PM-1Information Security Program PlanPMProgram Management10.1, 4.4, 5.1, 5.2, 6.1.1, 7.5.1, 7.5.2, 7.5.3, 8.1Art 24.2
    PM-8Critical Infrastructure PlanPMProgram Management4.1, 9.1, 9.2.1, 9.2.2Art 32.1
    PM-9Risk Management StrategyPMProgram Management6.1.1, 6.1.2, 8.2Art 32.2
    PM-13Security and Privacy WorkforcePMProgram Management5.3, 7.3, 7.4Art 32.4
    PM-14Testing, Training, and MonitoringPMProgram Management10.1, 8.1Art 32.1
    PM-29Risk Management Program Leadership RolesPMProgram Management5.1, 5.3, 6.1.1, 6.1.2, 8.2Art 32.2
    PT-1Policy and ProceduresPTPII Processing and Transparency5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 12.2, Art 24.2, Art 5.1, Art 9.1
    SR-1Policy and ProceduresSRSupply Chain Risk Management5.1, 5.2, 7.5.1, 7.5.2, 7.5.3Art 24.2

    Source and method

    Derived from the Top Floor framework mapping dataset: 4,123 cross-framework control mappings across 19 frameworks, every one pivoted through NIST SP 800-53 Rev 5.

    Cross-framework mappings on this page are derived from the 2026.2 release of the Secure Controls Framework, used under CC BY-ND 4.0.

    Mappings are illustrative aids for planning and are not a substitute for the official text of any framework or for an assessor’s judgment. Always verify control requirements against the authoritative publication. Where no official crosswalk exists, the mapping judgment is our own analysis.