CCPA / CPRA → ISO 27001 crosswalk
A control-by-control mapping between California Consumer Privacy Act (as amended by CPRA) and ISO/IEC 27001:2022. 2 mappings.
| CCPA / CPRA | ISO 27001 | Relationship | Notes |
|---|---|---|---|
| §1798.100 Consumers' right to know and notice at collection | A.5.1 Policies for information security | RelatedCurated | Gouvernance et politique de sécurité |
| §1798.130 Methods for handling consumer requests | A.5.9 Inventory of information and other associated assets | RelatedCurated | Inventaire des actifs et des données |
Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.