ISO/IEC 27701:2019
Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines
Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 66
- Дата публикации:
- 5 августа 2019 г.
- Издание:
- ISO/IEC IS 27701 edition 1 version 1
- ICS:
- 35.030
This document specifies requirements and provides guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS) in the form of an extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy management within the context of the organization. This document specifies PIMS-related requirements and provides guidance for PII controllers and PII processors holding responsibility and accountability for PII processing. This document is applicable to all types and sizes of organizations, including public and private companies, government entities and not-for-profit organizations, which are PII controllers and/or PII processors processing PII within an ISMS.
Abstract
Overview
ISO/IEC 27701:2019 is a privacy extension to ISO/IEC 27001 and ISO/IEC 27002 that defines requirements and guidance for establishing, implementing, maintaining and continually improving a Privacy Information Management System (PIMS). The standard adds privacy-specific controls and processes for organizations acting as PII controllers and PII processors handling personally identifiable information (PII) within an ISMS. ISO/IEC 27701 is applicable to organizations of all types and sizes - public, private, government and not-for-profit.
Key Topics and Requirements
- PIMS integration with ISMS: Extends ISO/IEC 27001:2013 requirements and ISO/IEC 27002:2013 guidance to include privacy governance, risk management and control mapping.
- Organizational context & scope: Requirements for understanding context, interested parties, and defining the PIMS scope.
- Leadership and accountability: Roles, responsibilities and top-management commitment for privacy obligations.
- Risk-based planning: Address privacy risks and opportunities; set objectives and treatment measures aligned with information security risk processes.
- Support and competence: Resource allocation, staff awareness, training and documented information for privacy controls.
- Operational controls: Controls for access management, asset handling, cryptography, system development, supplier management, logging, backups and incident response - adapted for PII protection.
- Controller/Processor-specific guidance: Conditions for collection and processing, lawful basis and consent, privacy impact assessments (PIA), contracts with PII processors, records of processing activities.
- PII principal rights: Guidance on transparency, providing information to data subjects, mechanisms to modify/withdraw consent and to object to processing.
- Performance and continual improvement: Monitoring, internal audit, management review and corrective action tailored to PIMS.
Applications and Who Uses It
ISO/IEC 27701 is used to:
- Integrate privacy requirements into an existing ISMS for holistic security + privacy management.
- Demonstrate compliance with privacy-by-design principles to customers, partners and regulators.
- Standardize contracts and processes for PII controllers and PII processors, including cloud and third‑party service providers. Typical users:
- Chief Privacy Officers, Data Protection Officers (DPOs) and compliance teams
- Information security managers and ISO 27001 implementers
- Legal, HR and vendor management teams responsible for PII processing
Benefits
- Improved alignment between information security and privacy controls
- Clear responsibilities and evidence for audits and regulatory inquiries
- Scalable framework suitable for small firms to large enterprises
Related Standards
- ISO/IEC 27001:2013 - Information security management systems (ISMS)
- ISO/IEC 27002:2013 - Information security controls and guidance
- Data protection frameworks and laws (for example, GDPR and other regional privacy regulations) - ISO/IEC 27701 helps map privacy controls to regulatory obligations
Keywords: ISO/IEC 27701, PIMS, privacy information management, PII controllers, PII processors, ISO/IEC 27001 extension, data protection, privacy impact assessment, consent management, ISMS.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 27701:2019
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 27013:2015
ОтменёнInformation technology — Security techniques — Guidance on the integrated implementation of ISO/IEC 27001 and…
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…