ISO/IEC 27018:2025
Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
Information security, cybersecurity and privacy protection — Guidelines for protection of personally identifiable information (PII) in public clouds acting as PII processors
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 35
- Дата публикации:
- 26 августа 2025 г.
- Издание:
- ISO/IEC IS 27018 edition 3 version 1
- ICS:
- 35.030
This document establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect personally identifiable information (PII) in line with the privacy principles in ISO/IEC 29100 for the public cloud computing environment. In particular, this document specifies guidelines based on ISO/IEC 27002:2022, taking into consideration the regulatory requirements for the protection of PII which can be applicable within the context of the information security risk environment(s) of a provider of public cloud services. This document is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations, which provide information processing services as PII processors via cloud computing under contract to other organizations. The guidelines in this document can also be relevant to organizations acting as PII controllers.
Abstract
Overview
ISO/IEC 27018:2025 is an international standard that provides guidelines for protecting personally identifiable information (PII) when processed in public cloud environments by organizations acting as PII processors. It aligns privacy principles from ISO/IEC 29100 with information security controls based on ISO/IEC 27002:2022, and is applicable to public and private companies, government entities and not‑for‑profits of all sizes that provide cloud‑based information processing services. The guidance is also relevant to organizations acting as PII controllers who contract cloud providers.
Key topics and technical requirements
The standard organizes controls into practical domains and highlights control objectives and guidelines tailored to public cloud processing of PII. Major topics include:
- Organizational controls: policies, roles and responsibilities, segregation of duties, supplier and contract management, regulatory and contractual compliance, and privacy governance.
- People controls: staff screening, confidentiality agreements, training, remote working and incident reporting.
- Physical controls: data centre perimeters, secure areas, equipment siting, media handling and secure disposal.
- Technological controls: access control, identity management, privileged access, secure authentication, encryption/cryptographic use, data deletion, data masking, data leakage prevention (DLP), logging, monitoring and vulnerability management.
- Cloud‑specific considerations: security of cloud services, ICT supply chain management, cloud incident response, PII processing agreements and multi‑tenant risk mitigation.
- Operational resilience: backups, redundancy, business continuity and evidence collection for investigations.
The document specifies control layout and implementation guidance rather than prescriptive technical settings, enabling organizations to adopt measures consistent with their risk environment.
Practical applications - who should use it
ISO/IEC 27018:2025 is intended for:
- Cloud service providers (CSPs) and managed service providers acting as PII processors.
- Security architects, privacy officers and compliance teams designing cloud controls and contractual clauses.
- Procurement and legal teams drafting cloud service agreements that address PII protection.
- Auditors and assessors evaluating cloud privacy controls against internationally accepted guidelines.
Adoption helps demonstrate compliance with privacy requirements, reduce regulatory risk, strengthen customer trust, and provide a consistent framework for contractual obligations and third‑party assessments.
Related standards
- ISO/IEC 27002:2022 - information security controls guidance referenced by 27018.
- ISO/IEC 29100 - privacy framework and privacy principles used as the foundation for PII protection guidance.
Keywords: ISO/IEC 27018:2025, PII protection, public cloud, cloud privacy, cloud security, ISO/IEC 27002, ISO/IEC 29100, PII processors, data protection, cloud service providers.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27018:2025
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 29100:2020
ДействующийInformation technology. Security techniques. Privacy framework.
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…