← Crosswalk explorer

ESG Essentials ISO/IEC 27001

5 canonical controls in Keel's library satisfy clauses of both ESG Essentials and ISO/IEC 27001. Implement each once, attach the evidence once, and it counts toward each standard. The overlap is the work you don't repeat.

5 shared controls ESG Essentials · 1.0: 17 in library ISO/IEC 27001 · 2022: 25 in library
Start free with ESG Essentials + ISO/IEC 27001 See all pairs

Controls that satisfy both

Canonical control ESG Essentials clauses ISO/IEC 27001 clauses
Information security policy
A board-approved information security policy set, reviewed at least annually and communicated to the workforce.
G.9 A.5.1
Risk assessment & treatment
A documented process to identify, analyze, evaluate, and treat information security risks on a defined cadence.
G.6 A.5.7
Third-party / vendor risk management
Due diligence, contractual safeguards, and ongoing monitoring of vendors that handle your data.
G.7, E.7, S.6 A.5.19
Security awareness training
Ongoing security awareness training for all personnel, with completion tracking.
S.5 A.6.3
Personal data privacy
Personal data of employees and customers is protected with clear, honored privacy practices.
S.8 A.5.34

Clause identifiers (ESG Essentials and ISO/IEC 27001) are referenced factually for mapping. Keel is not affiliated with or endorsed by the bodies that publish these standards. Control descriptions are Keel's own; a framework's full authored control count is on its framework page.

Why this is one project, not two

On a crosswalk-native model, ISO/IEC 27001 mostly lights up controls you already built for ESG Essentials. You're not re-uploading the same screenshot for a second audit. You apply the framework and see the genuine delta worth working. That's the whole idea behind collect once, comply everywhere.