ISO/IEC 29100:2024 PDF
Information technology — Security techniques — Privacy framework
Information technology — Security techniques — Privacy framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 22
- Дата публикации:
- 16 февраля 2024 г.
- Издание:
- ISO/IEC IS 29100 edition 2 version 1
- ICS:
- 35.030
This document provides a privacy framework which: — specifies a common privacy terminology; — defines the actors and their roles in processing personally identifiable information (PII); — describes privacy safeguarding considerations; — provides references to known privacy principles for information technology. This document is applicable to natural persons and organizations involved in specifying, procuring, architecting, designing, developing, testing, maintaining, administering, and operating information and communication technology systems or services where privacy controls are required for the processing of PII.
Abstract
Overview
ISO/IEC 29100:2024 - Information technology - Security techniques - Privacy framework - is an international standard that defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and communication technology (ICT) systems. The second edition updates the original 2011 publication and consolidates terminology, actor roles, safeguarding considerations, and references to established privacy principles. ISO/IEC 29100:2024 is intended for organizations and individuals involved in specifying, procuring, designing, developing, operating, and maintaining ICT systems where privacy controls are required.
Key topics and requirements
ISO/IEC 29100:2024 structures practical privacy guidance around clear topics and requirements:
- Common privacy terminology - standardized definitions for PII, anonymization, consent, identifiability, opt‑in/opt‑out, pseudonymous data, sensitive PII, metadata, and related terms.
- Actors and roles - identification of key stakeholders such as PII principals, PII controllers, PII processors, and third parties, plus their interactions and responsibilities.
- Recognizing PII - guidance on identifiers, other distinguishing characteristics, linked information, unsolicited PII and what constitutes PII in ICT contexts.
- Privacy safeguarding considerations - organizational, legal/regulatory, contractual and business factors that influence safeguarding requirements.
- Privacy principles - referenced principles include:
- Consent and choice
- Purpose legitimacy and specification
- Collection limitation and data minimization
- Use, retention and disclosure limitation
- Accuracy and quality
- Openness, transparency and notice
- Individual participation and access
- Accountability, information security and privacy compliance
- Privacy policies and controls - high‑level expectations for policies and technical/organizational controls to protect PII.
- Annex mapping - correspondence to ISO/IEC 27000 family concepts to align privacy with information security.
Applications and who should use it
ISO/IEC 29100:2024 is practical for:
- IT architects, developers and system designers building systems that process PII.
- Procurement and vendor management teams defining privacy requirements in contracts and outsourced processes.
- Privacy officers, risk assessors and compliance teams performing privacy impact assessments and defining safeguarding needs.
- Security and operations teams implementing privacy controls, access management, data retention and anonymization measures.
- Legal and governance functions aligning ICT practices with regulatory and contractual obligations.
Use cases include drafting privacy-aware requirements, shaping vendor contracts, developing privacy policies, guiding pseudonymization/anonymization decisions, and aligning information security and data protection programs.
Related standards
- ISO/IEC 29100:2024 includes an annex mapping to the ISO/IEC 27000 series and is intended to complement existing information security standards and privacy engineering initiatives.
Keywords: ISO/IEC 29100:2024, privacy framework, PII, privacy principles, data protection, privacy controls, information security, PII controller, PII processor, data minimization, consent.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29100:2024
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS EN ISO/IEC 27000:2020
ОтменёнInformation technology. Security techniques. Information security management systems. Overview and vocabulary
1 Scope This document provides the overview of information security management systems (ISMS). It also provides terms and definitions commonly used in the ISMS family of standards. This document is a…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…
ISO/ASTMTR52917-EB
ДействующийAdditive Manufacturing — Round Robin Testing — General Guidelines
This document outlines the steps with regard to aspects of design to conduct and run a round robin study (RRS) to assess the degree of variability in an additive manufacturing material or process. Th…