ISO/IEC 19086-4:2019 PDF
Cloud computing — Service level agreement (SLA) framework — Part 4: Components of security and of protection of PII
Cloud computing — Service level agreement (SLA) framework — Part 4: Components of security and of protection of PII
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 20
- Дата публикации:
- 29 января 2019 г.
- Издание:
- ISO/IEC IS 19086 edition 1 version 1
- ICS:
- 35.020
This document specifies security and protection of personally identifiable information components, SLOs and SQOs for cloud service level agreements (cloud SLA) including requirements and guidance. This document is for the benefit and use of both CSPs and CSCs.
Abstract
Overview
ISO/IEC 19086-4:2019 defines the security and personally identifiable information (PII) protection components for cloud service level agreements (cloud SLA). It specifies security components, PII protection components, and associated Service Level Objectives (SLOs) and Service Quality Objectives (SQOs), together with requirements and guidance for inclusion in cloud SLAs. The standard is intended for use by both cloud service providers (CSPs) and cloud service customers (CSCs) to clarify expectations for security, privacy, and data protection in cloud contracts.
Key topics and technical requirements
ISO/IEC 19086-4 structures security and PII protection into discrete components and provides SLO/SQO guidance for each. Key technical topics include:
-
Information security components
- Information security policy, organization of information security
- Asset management, access control, cryptography
- Physical/environmental security, operations and communications security
- Systems acquisition, supplier relationships
- Incident management, business continuity, compliance
-
Protection of PII components
- Consent and choice, purpose legitimacy and specification
- Data minimization, use/retention/disclosure limitation
- Accuracy and quality, openness/transparency/notice
- Individual participation and access, accountability
-
SLOs and SQOs
- Defines measurable and qualitative objectives for cloud security and PII protection to be embedded in SLAs
- Provides guidance on how CSPs and CSCs can express, measure and agree on security/privacy commitments without prescribing specific technologies or thresholds
-
Relationship and conformance
- Explains how these components integrate with the broader ISO/IEC 19086 cloud SLA framework and offers conformance guidance for SLA drafting and assessment
Practical applications - who uses this standard
- Cloud service providers (CSPs): to define and publish SLA security/privacy commitments and design controls to meet agreed SLOs/SQOs.
- Cloud service customers (CSCs): to evaluate vendor SLAs, negotiate contractual protections for PII, and align procurement requirements with compliance needs.
- Privacy officers / compliance teams: to map contractual obligations to regulatory requirements and demonstrate accountability.
- Security architects / legal teams / procurement: to translate organizational security/privacy policies into enforceable SLA terms.
Related standards
- ISO/IEC 19086 series (the cloud SLA framework) - use ISO/IEC 19086-4 together with other parts of the framework for a complete approach to cloud SLA definition, metrics and contractual constructs.
ISO/IEC 19086-4 is a practical reference for embedding clear, measurable security and PII protections into cloud SLAs, helping organizations manage risk, compliance and vendor expectations.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 19086-4:2019
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 19086-4:2019
ДействующийCloud computing. Service level agreement (SLA) framework. Components of security and of protection of PII.
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…