Skip to content

CCPA / CPRAISO 27001 crosswalk

A control-by-control mapping between California Consumer Privacy Act (as amended by CPRA) and ISO/IEC 27001:2022. 2 mappings.

CCPA / CPRAISO 27001RelationshipNotes
§1798.100
Consumers' right to know and notice at collection
A.5.1
Policies for information security
RelatedCurated
Gouvernance et politique de sécurité
§1798.130
Methods for handling consumer requests
A.5.9
Inventory of information and other associated assets
RelatedCurated
Inventaire des actifs et des données

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.