CCPA / CPRA → ISO 27001 crosswalk
A control-by-control mapping between California Consumer Privacy Act (as amended by CPRA) and ISO/IEC 27001:2022. 2 mappings.
| CCPA / CPRA | ISO 27001 | Relationship | Notes |
|---|---|---|---|
| §1798.100 Consumers' right to know and notice at collection | A.5.1 Policies for information security | RelatedCurated | Governance & security policy |
| §1798.130 Methods for handling consumer requests | A.5.9 Inventory of information and other associated assets | RelatedCurated | Asset & data inventory |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.