ISO/IEC 27018
Privacy guidance for public-cloud providers acting as processors of personally identifiable information. It complements ISO/IEC 27001 and 27002; it is not a regulation, standalone certification, or claim that ControlFrame is certified.
2025 · ISO/IEC 27018:2025 · published 2025-08-26
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
ISO/IEC 27018 is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Licensed standard — purchase from ISO or a national member body and obtain software-use rights before verbatim ingestion.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- PII processing instructions · Transparency · Data-subject rights support · Public-cloud privacy controls
- Applies to
- cloud services · SaaS · technology · all sectors · global
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-28
03Version ledger
| 2019 | Superseded | date not published |
| 2025 | Current edition · supersedes 2019 | 2025-08-26 |
05Change history
06Related frameworks
- ISO/IEC 270172026
Also applies to cloud services · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.
Also applies to cloud services · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.
- CSA CCM and CAIQv4.1
Also applies to cloud services · The Cloud Security Alliance's cloud-control framework and companion assessment questionnaire for cloud providers and customers. CSA publishes 207 CCM v4.1 controls across 17 domains and 283 CAIQ questions; tracking them does not claim STAR registration, certification, or attestation.
- CSA STARSTAR Level 1 and Level 2
Also applies to cloud services · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.