Overview
ISO/IEC 27561:2024 defines a standardized privacy operationalisation model and method for engineering (POMME), supporting information security, cybersecurity, and privacy protection. Developed by ISO and IEC, this guidance document translates the privacy principles of ISO/IEC 29100 into actionable privacy controls and functional capabilities within systems that process personally identifiable information (PII). POMME provides organizations and engineering teams with a structured, iterative method to operationalize privacy requirements through technical and procedural mechanisms, enhancing privacy assurance and compliance throughout the system lifecycle.
The standard is intended for engineers, system developers, privacy practitioners, solution providers, and others responsible for designing, developing, or maintaining systems involving PII. POMME supports a wide range of networked and interdependent applications and systems and is designed to work in conjunction with other privacy and security standards.
Key Topics
- Privacy Operationalisation Model (POMME): A structured framework for transforming high-level privacy principles into actionable controls, mapped to system and organizational capabilities.
- Process Integration: POMME follows a lifecycle approach aligning with standards such as ISO/IEC/IEEE 24774, ensuring privacy operationalization is embedded across development and maintenance.
- Stakeholder Engagement: Identifies and incorporates the needs of diverse privacy stakeholders, including PII principals, business owners, policy makers, system developers, and solution providers.
- Iterative Method: The privacy operationalization process is iterative, involving inventory, assessment, specification, implementation, and continuous improvement.
- Privacy Controls and Risk Assessment: Guides the specification of privacy controls, their requirements, capabilities, and the risk assessment necessary for operationalization.
Applications
Organizational and technical practitioners can use ISO/IEC 27561:2024 (POMME) to:
- System Development: Apply structured processes to operationalize privacy controls in software, products, networked platforms, and IT systems that manage PII.
- Privacy Engineering: Integrate privacy-by-design principles throughout the system lifecycle, ensuring privacy requirements are addressed from early design through deployment and maintenance.
- Risk Management: Identify and mitigate privacy risks by selecting and tailoring appropriate controls and capabilities for both internal and external system interactions, including for cloud-based or multi-organizational scenarios.
- Cross-Standard Integration: Ensure alignment with other critical privacy and information security requirements by bridging between ISO/IEC 29100 privacy principles, ISO/IEC 27000 series security controls, and ISO/IEC/IEEE engineering standards.
- Compliance and Assurance: Support regulatory and policy compliance by giving clear methods to implement, document, and audit privacy measures within complex systems.
- Enhanced Collaboration: Facilitate agreements and mutual understanding between different organizational stakeholders, especially in interconnected, distributed, or cloud environments where PII comes under multiple domains.
Related Standards
- ISO/IEC 29100: Privacy framework and foundational privacy principles.
- ISO/IEC/IEEE 24774: Guidelines for process description.
- ISO/IEC TR 27550: Principles and reference for privacy engineering practices.
- ISO/IEC 27000 series: Information security management system standards.
- ISO 31700: Consumer privacy for products and services.
- ISO/IEC/IEEE 15288: System lifecycle processes for engineering.
- ISO/IEC/IEEE 29148: Requirements for systems and software engineering.
- NIST Privacy Framework: Reference for privacy risk management (informative for mapping but not an ISO standard).
ISO/IEC 27561:2024 reinforces the integration of privacy and security, enabling organizations to address modern data protection challenges and to streamline the operationalization of privacy controls in diverse technical and business environments. By leveraging POMME, practitioners can ensure both compliance and robust privacy management across interconnected systems and evolving digital landscapes.