A.5.31 Organizational
Legal, statutory, regulatory and contractual requirements
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (11)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PL-4mostlyaligns with — Both controls require that external legal, regulatory, and contractual obligations be explicitly incorporated into the rules and procedures that govern how information security is implemented and managed.
- RA-3mostlyaligns with — Both controls mandate that applicable legal, statutory, regulatory, and contractual requirements be identified and considered as part of the risk-assessment process used to determine security needs.
- CA-6partialaligns with — Both controls require that compliance with external legal and regulatory obligations be verified and maintained as a prerequisite for granting or sustaining system authorization.
- SA-4partialaligns with — Both controls require that legal, regulatory, and contractual security requirements be explicitly included in acquisition and supplier agreements.
- SC-12partialaligns with — Both controls require that cryptographic implementations be evaluated against jurisdiction-specific legal and regulatory constraints before deployment or cross-border transfer.
- SR-3partialaligns with — Both controls require that contractual and regulatory obligations be flowed down to suppliers and verified as part of supply-chain security management.
Aligned NIST CSF 2.0 outcomes (10)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- GV.OC-03fullcovers — The ISO control's explicit mandate to identify, document, and maintain compliance with all legal, regulatory, and contractual cybersecurity obligations directly fulfills the CSF outcome of understanding and addressing those same requirements.
- GV.RM-03mostlyaligns with — The control's directive to factor external requirements into risk assessments and risk-treatment decisions aligns with the CSF outcome of integrating cybersecurity risk activities into enterprise risk management processes.
- GV.SC-05mostlyaligns with — By requiring that supplier contracts incorporate information-security obligations, the ISO control ensures the CSF outcome of embedding cybersecurity risk requirements into third-party agreements is achieved.
- GV.PO-01partialaligns with — The requirement to consider legal and contractual obligations when developing policies and procedures aligns with the CSF outcome of establishing risk-management policy based on organizational context and external requirements.
- ID.RA-07partialaligns with — Regular review of legislation and regulations to detect changes and new obligations supports the CSF outcome of assessing the risk impact of changes and exceptions.
Related OWASP ASVS 5.0 requirements (6)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (6)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-213mostlyprevents — Legal and contractual requirements often impose stricter sensitivity rules than developer policy.
- CWE-200partialprevents — Requiring explicit consideration of legislation and contracts that govern data handling makes it less likely that sensitive information will be disclosed in ways that violate those external rules.
- CWE-284partialprevents — By forcing the organization to identify and embed external legal and contractual obligations into policies, risk assessments and control design, the control reduces the chance that access-control decisions will be made without regard to statutory or contractual restrictions on who may access information.
- CWE-327partialprevents — The explicit call-out of cryptography-related legal constraints (import/export, key escrow, digital-signature validity) reduces the likelihood that an organization will adopt broken or non-compliant cryptographic algorithms that violate those rules.
- CWE-732partialprevents — Mapping statutory and contractual requirements into the classification and control-selection process helps ensure that permissions assigned to critical resources reflect externally mandated restrictions rather than ad-hoc decisions.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.