Skip to main content

ISO 27001:2022 mapped to Canadian law

Canada Cyber-Safe — independent cyber and AI governance for Canadian organisations

The Canadian half of ISO 27001

ISO/IEC 27001:2022 is an international standard. It does not mention PIPEDA, it does not mention Quebec’s Law 25, and it will not tell you that your breach records must be kept for two years federally and five in Quebec. Every toolkit sold to Canadian companies is written for a British or American buyer and leaves that work to you.

This is that work. It maps the Annex A controls that carry a specific Canadian legal obligation onto the obligation itself, so an ISMS built here can evidence Canadian law rather than merely satisfy an auditor.

Read this first

This is a map, not the standard.

ISO/IEC 27001:2022 is copyrighted. Nothing here reproduces its text — the descriptions are our own plain-English summary of what each control is getting at. If you are implementing the standard you must buy it, from ISO or through the Standards Council of Canada. Certification is issued only by an accredited certification body, which we are not and do not intend to become.

Control references follow ISO/IEC 27001:2022, which replaced the 2013 edition. Certificates against the 2013 edition ceased to be valid after October 2025.

A.5 — Organizational controls

37 controls. This is where almost every Canadian legal obligation lands.

Annex A
What it asks of you
The Canadian obligation it helps you evidence
A.5.1Policies
Documented, approved information security policies that people are actually told about.
PIPEDA Principle 1Accountability requires policies and practices to be implemented and communicated. An undocumented practice cannot be evidenced.
A.5.2Roles and responsibilities
Security roles defined and allocated to named people.
PIPEDA Principle 1Requires an identified individual accountable for compliance. This is the control that closes the most common gap we find.
A.5.9Asset inventory
A maintained inventory of information and the assets holding it, each with an owner.
BothYou cannot assess sensitivity, honour an access request, or scope a breach without knowing where personal information lives.
A.5.10Acceptable use
Rules for acceptable use of information and assets, including what may not be done with it.
Law 25 & PIPEDAWhere staff paste personal information into a public AI tool, this is the control that was missing. Our free AI acceptable use template sits here.
A.5.12Classification
Information classified by sensitivity, value and legal requirement.
BothSensitivity is an explicit statutory factor in the federal “real risk of significant harm” test and Quebec’s “risk of serious injury” test. Without classification you are guessing at both.
A.5.14Information transfer
Rules and agreements covering the transfer of information inside and outside the organisation.
Law 25, s.17Before personal information is communicated outside Quebec you must assess whether it will receive adequate protection, and record the arrangement in a written agreement.
A.5.15Access control
Access to information granted on business need and reviewed.
PIPEDA Principle 7Safeguards appropriate to sensitivity. Also the control behind Quebec’s expectation that access is limited to what a role requires.
A.5.19–5.23Supplier and cloud
Security in supplier relationships, agreements, the ICT supply chain, ongoing monitoring, and cloud services.
PIPEDA Principle 4.1.3You remain responsible for personal information transferred to a third party and must use contractual or other means to give it comparable protection. Federally regulated entities also face OSFI B-10.
A.5.24–5.28Incident management
Planning, assessment, response, learning, and evidence collection for security events.
BothFederal reporting is “as soon as feasible” after you determine a breach occurred; Quebec requires notification with diligence. Neither gives you a fixed number of days, which makes prepared process the only defence.
A.5.31Legal and regulatory requirements
Identify and document the legal, statutory, regulatory and contractual requirements that apply.
BothFor a Canadian organisation this is where PIPEDA, Law 25, any provincial private-sector Act, sector rules and contractual duties are actually written down.
A.5.33Protection of records
Records protected from loss, destruction and falsification, per legal requirements.
Retention asymmetryFederal breach records: at least 24 months. Quebec confidentiality incident register: at least 5 years. Where both apply, keep for five. Most organisations hold neither.
A.5.34Privacy and protection of PII
Identify and meet requirements for the preservation of privacy and protection of personal information.
Both, directlyThe single Annex A control that maps to Canadian privacy law head-on, and the one most ISMS implementations treat as a formality.
A.5.35–5.36Review and compliance
Independent review of information security, and compliance with policies and standards.
Clause 9.2 tooIndependent review is a requirement, not a nicety — and independence means someone who does not own the thing being reviewed.

A.6 — People controls

8 controls. Small section, disproportionate share of real incidents.

Annex A
What it asks of you
The Canadian obligation it helps you evidence
A.6.1Screening
Background verification proportionate to the information the role will reach.
Employment law caveatScreening in Canada is constrained by provincial human rights and privacy law. Proportionate, not maximal.
A.6.3Awareness and training
Security awareness, education and training, updated as things change.
PIPEDA Principle 1Accountability includes training staff about policies and practices. Our free bilingual posters are the shallow end of this control.
A.6.6Confidentiality agreements
Confidentiality or non-disclosure agreements reflecting the organisation’s needs.
BothWhere staff or contractors handle personal information, this is part of demonstrating you took reasonable steps.
A.6.8Reporting security events
A route for people to report observed or suspected events, quickly.
BothYour reporting clock starts when the organisation becomes aware. A staff member who hesitates for two days has spent two days of it.

A.7 — Physical controls

14 controls. Fewer direct legal hooks, but paper and devices still cause breaches.

Annex A
What it asks of you
The Canadian obligation it helps you evidence
A.7.7Clear desk and screen
Information not left visible on desks or screens.
BothWrong-recipient and overheard-information incidents are reportable events like any other. Paper is still personal information.
A.7.10Storage media
Management of removable media through its life, including disposal.
PIPEDA Principle 5Personal information no longer needed for the identified purpose must be destroyed, erased or made anonymous.
A.7.14Secure disposal of equipment
Equipment verified as wiped before disposal or reuse.
PIPEDA Principle 5A traded-in laptop with recoverable data is a breach that was entirely avoidable and is difficult to explain afterwards.

A.8 — Technological controls

34 controls. Where the CCCS baseline overlaps most heavily.

Annex A
What it asks of you
The Canadian obligation it helps you evidence
A.8.2 / A.8.3Privileged and restricted access
Privileged access rights restricted and managed; access to information restricted by policy.
CCCS baselineTwo of the most commonly failed controls we assess. Service accounts and former contractors are where they fail.
A.8.5Secure authentication
Secure authentication technologies and procedures.
CCCS baselineMulti-factor authentication. The exemptions — service accounts, contractors, the inconvenienced executive — are what turn this from a control into a gap.
A.8.12Data leakage prevention
Measures applied to systems and networks that process sensitive information.
Law 25 & PIPEDAIncreasingly the control that governs whether personal information can be pasted into an unapproved external service.
A.8.13Information backup
Backups maintained and regularly tested.
CCCS baselineTested is the operative word. A backup never restored is a belief, not a control.
A.8.15 / A.8.16Logging and monitoring
Logs produced, protected and analysed; networks and systems monitored for anomalous behaviour.
BothWithout logs you cannot establish what was accessed, which means you cannot scope a notification and must assume the worst.
A.8.24Use of cryptography
Rules for effective use of cryptography, including key management.
PIPEDA Principle 7Encryption is not mandated by name in Canadian law, but it is the most common way of demonstrating safeguards appropriate to sensitivity.
A.8.25–A.8.29Secure development
Secure development lifecycle, requirements, architecture, coding, and testing.
Law 25, s.12.1If you build software that makes automated decisions about people, the duty to inform them and to allow representations attaches at design time, not at launch.

Where this leads

Three of the documents an ISMS needs are already on this site free: AI acceptable use (A.5.10), privacy breach response (A.5.24–5.28 and A.5.33) and third-party review (A.5.19–5.23). Our own thirty-six control set is the shorter assessment yardstick for organisations not pursuing certification.

If you are already certified, clause 9.2 requires an internal audit by someone independent of what is being audited. That is work we can do without ever becoming your certification body.

The full crosswalk across all 93 controls, together with a populated Canadian legal register and a breach register built for both retention clocks, is in our Canadian overlay pack.

Ask about an internal auditAll free resources

Standards we assess against

ISO/IEC 27001:2022 · ISO/IEC 27701:2025 · ISO 9001:2015 · ISO/IEC 42001:2023 · ISO/IEC 23894:2023 (guidance) · ISO/IEC 42005:2025 (guidance)

Français : La première heure — rédigé en français, pas une traduction automatique.

Canada Cyber-Safe is an independent assessment practice. We are not a certification body and we do not issue certificates.