ISO/IEC 29101:2018 PDF
Information technology — Security techniques — Privacy architecture framework
Information technology — Security techniques — Privacy architecture framework
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 42
- Дата публикации:
- 28 ноября 2018 г.
- Издание:
- ISO/IEC IS 29101 edition 2 version 1
- ICS:
- 35.030
This document defines a privacy architecture framework that: — specifies concerns for ICT systems that process PII; — lists components for the implementation of such systems; and — provides architectural views contextualizing these components. This document is applicable to entities involved in specifying, procuring, architecting, designing, testing, maintaining, administering and operating ICT systems that process PII. It focuses primarily on ICT systems that are designed to interact with PII principals.
Abstract
Overview
ISO/IEC 29101:2018 - Privacy architecture framework defines a high-level architecture for safeguarding personally identifiable information (PII) in information and communication technology (ICT) systems. It specifies the concerns that must be considered when processing PII, lists components for implementing privacy-aware systems, and provides multiple architectural views (component, actor/deployment, interaction) to contextualize those components. The standard is intended for entities involved in specifying, procuring, architecting, designing, testing, maintaining, administering and operating ICT systems that interact with PII principals.
Key technical topics and requirements
- Privacy concerns and principles: Builds on ISO/IEC 29100 by mapping privacy principles and defining privacy safeguarding requirements specific to ICT systems that process PII.
- PII lifecycle coverage: Addresses lifecycle phases including collection, transfer, use, storage, and disposal of PII.
- Architecture layers and components: Organizes privacy-related functionality into layers (for example, privacy settings, identity and access management, and the PII layer) and describes components relevant to each layer.
- Actors and deployment views: Describes ICT systems from the perspectives of the PII principal, PII controller, and PII processor, and shows how PII flows between these actors.
- Interaction view: Illustrates component-to-component interactions and how privacy controls operate across system boundaries.
- Privacy-enhancing technologies (PETs): Shows how PETs can be used as privacy controls within the architecture.
- Correspondence and mapping: Provides mapping tables tying concerns to viewpoints and components to help implementers trace requirements to architecture.
- Standards alignment: Uses ISO/IEC/IEEE 42010 for architecture description and explicitly ties to privacy management practices and information security engineering.
Practical applications - who uses this standard
- System architects and privacy engineers - design privacy-aware ICT architectures and select appropriate components/PETs.
- Security architects and developers - integrate identity, access management and data protection controls into system designs.
- Procurement and vendors - specify and evaluate privacy requirements in product RFPs and procurements.
- Compliance officers and auditors - map organizational privacy safeguarding requirements to technical architecture.
- Operations and IT administrators - implement, test, and maintain privacy controls across deployment environments.
Related standards and further reading
- ISO/IEC 29100 - Privacy framework (principles and stakeholders)
- ISO/IEC/IEEE 42010 - Systems and software engineering - Architecture description
- Use ISO/IEC 29101 to bridge privacy policy/management decisions with concrete architectural controls and PETs when building or evaluating systems that process PII.
Keywords: ISO/IEC 29101:2018, privacy architecture framework, PII, PETs, ICT systems, privacy safeguarding, identity and access management, privacy engineering.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29101:2018
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
SIST EN ISO/IEC 29100:2020
ДействующийInformation technology - Security techniques - Privacy framework (ISO/IEC 29100:2011, including Amd 1:2018)
Overview EN ISO/IEC 29100:2020 (ISO/IEC 29100:2011, including Amd 1:2018) defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and com…
SIST EN ISO/IEC 29101:2021
ДействующийInformation technology - Security techniques - Privacy architecture framework (ISO/IEC 29101:2018)
Overview EN ISO/IEC 29101:2021 (ISO/IEC 29101:2018) defines a privacy architecture framework for information and communication technology (ICT) systems that store and process personally identifiable…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…