Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » ISO 27001 » ISO 27001 Domains

ISO 27001 Domains

The ISO 27001 is divided into 14 domains. The reason why ISO 27001 is divided into these domains is that it gives a more structured approach towards a holistic framework, and each one of these domains handles a significant part of the objectives.

ISO 27001 Domains are: 

  • Risk Assessment and Management
  • Security Policy Development
  • Organizational Security
  • Human Resource Security 
  • Asset Management 
  • Access Control
  • Cryptography 
  • Physical and Environmental Security
  • Operations Security
  • Communications Security
  • System Acquisition
  • Development and Maintenance
  • Supplier Relationships
  • Information Security Incident Management
  • Business Continuity Management

These domains ensure personnel, data, controls, and systems security, develop incident response strategies for potential breach scenarios and help maintain consistency throughout the operations and your overall enterprise environment.

Additional reading

The Complete Guide to Vendor Management 

Vendors are both your biggest enablers and your weakest link. Around 73% of companies face either a security incident or disruption due to third-party vendors. One breach in your supply chain can cripple operations, inject ransomware into your systems, or derail your compliance in a single audit cycle. Most importantly, when vendor oversight is scattered…

Cybersecurity Monitoring: Importance, Steps and Examples

According to a report by Forbes, data breaches have surged by over 72%. The issue? Threats are outpacing security measures in terms of evolution, and volume. In a landscape where each vulnerability can lead to an exploit, cyber security monitoring can help you assess your security posture in real-time, and help you plug gaps for…

Proving Compliance: Why SOC 2 Evidence Collection Matters

TL,DR: SOC 2 evidence proves your controls operate as described during the audit period. Auditors expect policies, logs, screenshots, configurations, attestations, tickets, and control owner records. The article explains evidence types, collection mistakes, repository hygiene, and continuous audit readiness. Years ago, collecting evidence was a walk in the park. But we can’t say the same…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.