ISO/IEC 29151:2017
Information technology — Security techniques — Code of practice for personally identifiable information protection
Information technology — Security techniques — Code of practice for personally identifiable information protection
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 39
- Дата публикации:
- 18 августа 2017 г.
- Издание:
- ISO/IEC IS 29151 edition 1 version 1
- ICS:
- 35.030
ISO/IEC 29151:2017 establishes control objectives, controls and guidelines for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII). In particular, this Recommendation | International Standard specifies guidelines based on ISO/IEC 27002, taking into consideration the requirements for processing PII that may be applicable within the context of an organization's information security risk environment(s). ISO/IEC 29151:2017 is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII.
Abstract
Overview
ISO/IEC 29151:2017 - "Information technology - Security techniques - Code of practice for personally identifiable information protection" - provides a practical code of practice for protecting personally identifiable information (PII). It establishes control objectives, specific controls, and implementation guidelines to address risks and impacts identified through a risk and impact assessment. Built on the guidance of ISO/IEC 27002, ISO/IEC 29151 adapts information security controls to the special requirements of PII processing and is applicable to all types and sizes of organizations acting as PII controllers (public, private, government and not-for-profit).
Key topics and technical requirements
ISO/IEC 29151 organizes guidance in a structure that mirrors ISO/IEC 27002 and covers core information security domains (clauses 5–18), including:
- Information security policies and management direction
- Organization of information security, mobile devices and teleworking
- Human resource security (prior to, during, and after employment)
- Asset management, classification and media handling
- Access control (user management, system and application access)
- Cryptographic controls
- Physical and environmental security
- Operations security (backup, malware protection, logging, vulnerability management)
- Communications security and information transfer
- System acquisition, development and maintenance
- Supplier relationships and service delivery management
- Incident management, business continuity and compliance
The standard includes a normative Annex A: an extended control set specific to PII protection. These PII controls are aligned with ISO/IEC 29100 privacy principles and cover 12 categories such as:
- Consent and choice
- Purpose legitimacy and specification
- Collection limitation and data minimization
- Use, retention and disclosure limitation
- Accuracy, openness/transparency and notice
- Individual participation/access, accountability, and privacy compliance
Controls are selected and tailored based on an organization’s information security risk environment and privacy risk assessments.
Practical applications - who uses ISO/IEC 29151
ISO/IEC 29151 is used by organizations that collect, store or process personal data and need to:
- Strengthen privacy-by-design and PII protection practices
- Align information security controls with privacy requirements
- Develop or refine policies, procedures and technical safeguards for PII
- Demonstrate due diligence and privacy compliance to stakeholders and regulators
Typical users include corporate security and privacy teams, IT managers, compliance officers, auditors, and third-party suppliers supporting PII controllers.
Related standards
- ISO/IEC 27001 / 27002 - information security management and control guidance (foundation)
- ISO/IEC 27018 - PII protection for cloud service processors
- ISO/IEC 29100 - privacy framework and PII terminology
- ISO/IEC 29134 - privacy impact assessment guidance
ISO/IEC 29151 bridges information security and privacy practice by adapting ISO/IEC 27002 controls for PII protection, making it a practical, risk-based code of practice for protecting personal data.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29151:2017
Похожие стандарты
Стандарты, упомянутые в описании
ISO 27799:2016
ОтменёнHealth informatics — Information security management in health using ISO/IEC 27002
Overview ISO 27799:2016 - Health informatics - Information security management in health using ISO/IEC 27002 - provides sector-specific guidance to protect personal health information. It adapts and…