Skip to content

CCPA / CPRAISO 27001 crosswalk

A control-by-control mapping between California Consumer Privacy Act (as amended by CPRA) and ISO/IEC 27001:2022. 2 mappings.

CCPA / CPRAISO 27001RelationshipNotes
§1798.100
Consumers' right to know and notice at collection
A.5.1
Policies for information security
RelatedCurated
Governance & security policy
§1798.130
Methods for handling consumer requests
A.5.9
Inventory of information and other associated assets
RelatedCurated
Asset & data inventory

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.