ISO/IEC 29151:2026 PDF
Information security, cybersecurity and privacy protection — Controls, requirements, and guidance for personally identifiable information protection
Information security, cybersecurity and privacy protection — Controls, requirements, and guidance for personally identifiable information protection
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 41
- Дата публикации:
- 24 июля 2026 г.
- Издание:
- ISO/IEC IS 29151 edition 2 version 1
- ICS:
- 35.030
This document specifies controls, purpose, and guidance for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII). In particular, this document specifies requirements and guidance based on ISO/IEC 27002, taking into consideration the controls for processing PII that can be applicable within the context of an organization's information security risk environment(s). This document is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII, in particular, organizations that do not establish or operate a privacy information management system.
Abstract
Overview
ISO/IEC 29151:2026 is a key international standard developed by ISO and IEC for information security, cybersecurity, and privacy protection. The standard specifically addresses controls, requirements, and guidance for the protection of personally identifiable information (PII) within organizations of all sizes and types, including public and private companies, government bodies, and non-profits. Built upon the framework of ISO/IEC 27002, it provides tailored controls and guidance derived from risk and impact assessments, ensuring PII is processed and protected appropriately throughout its lifecycle.
This standard is particularly relevant for organizations acting as PII controllers as defined in ISO/IEC 29100, especially those that do not operate a formal Privacy Information Management System (PIMS). As the volume of PII and the expectations for its protection continue to rise alongside increasing data breaches, ISO/IEC 29151:2026 delivers practical and comprehensive guidance to help organizations mitigate privacy risks and comply with diverse regulatory requirements.
Key Topics
ISO/IEC 29151:2026 covers a broad set of information security and privacy controls designed to protect PII. Major areas include:
- Organizational Controls: Policies, roles, responsibilities, access control, supplier management, and compliance.
- People Controls: Employee screening, security awareness, confidentiality agreements, and incident reporting.
- Physical Controls: Facility security, secure disposal of equipment, and environmental protection measures.
- Technological Controls: Data masking, access restrictions, cryptography, secure application development, and vulnerability management.
The standard also features an Extended Control Set for PII Protection in Annex A, covering principles such as:
- Consent and choice
- Purpose legitimacy and specification
- Data minimization
- Use, retention, and disclosure limitation
- Accuracy and quality
- Openness and transparency
- Accountability
- Information security and privacy compliance
These topics are directly linked to the privacy principles outlined in ISO/IEC 29100, ensuring a harmonized approach across various regulatory and operational environments.
Applications
Practical applications of ISO/IEC 29151:2026:
- Risk-Based Control Selection: Organizations perform risk and impact assessments to identify and implement the necessary controls for processing and protecting PII. Controls are adapted based on organizational context, types of PII processing, and applicable threats.
- Regulatory Compliance: Helps organizations demonstrate compliance with privacy and data protection regulations worldwide by providing a structured framework to manage and mitigate privacy risks.
- PII Lifecycle Management: Supports the management of PII across its full lifecycle, from collection and processing to retention and secure disposal.
- Cloud and Digital Services: Addresses privacy requirements in modern technology environments such as cloud computing, big data analytics, mobile devices, and IoT-ensuring PII is protected regardless of where or how it is processed.
- Vendor and Third-Party Management: Guides organizations in extending PII protection controls to supply chains and outsourced services, ensuring end-to-end security.
Related Standards
ISO/IEC 29151:2026 aligns with a broader ecosystem of international privacy and information security standards, enabling organizations to build robust compliance and risk mitigation programs. Related standards include:
- ISO/IEC 27001: Information Security Management System requirements.
- ISO/IEC 27002: Comprehensive guidelines for information security controls.
- ISO/IEC 27005: Information security risk management guidelines.
- ISO/IEC 27701: Privacy Information Management System (PIMS) requirements and guidance.
- ISO/IEC 29100: Privacy framework and terminology.
- ISO/IEC 29134: Guidelines for privacy impact assessment.
- ISO/IEC 27018: Protection of PII in cloud computing environments.
Adopting ISO/IEC 29151:2026 supports organizations in delivering proven, best-practice PII protection, improving stakeholder trust, and aligning privacy initiatives with globally recognized frameworks for information security and privacy.
Keywords: personally identifiable information protection, PII controls, privacy risk management, ISO/IEC 29151, cybersecurity, information security standards, privacy compliance.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 29151:2026
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO/IEC 27017:2021
ОтменёнInformation technology. Security techniques. Code of practice for information security controls based on ISO/…
1 Scope This Recommendation International Standard gives guidelines for information security controls applicable to the provision and use of cloud services by providing: – additional implementation g…
SIST EN ISO/IEC 29100:2020
ДействующийInformation technology - Security techniques - Privacy framework (ISO/IEC 29100:2011, including Amd 1:2018)
Overview EN ISO/IEC 29100:2020 (ISO/IEC 29100:2011, including Amd 1:2018) defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and com…
ISO/IEC 27001:2022/Amd 1:2024
ДействующийInformation security, cybersecurity and privacy protection — Information security management systems — Requir…
Overview ISO/IEC 27001:2022/Amd 1:2024 is the latest amendment to the internationally recognized ISO/IEC 27001 standard, which establishes requirements for information security management systems (IS…
SIST EN ISO/IEC 27005:2024
ДействующийInformation security, cybersecurity and privacy protection - Guidance on managing information security risks…
Overview SIST EN ISO/IEC 27005:2024 (adoption of ISO/IEC 27005:2022 as EN ISO/IEC 27005:2024) provides detailed guidance on managing information security risks to support implementation of an Informa…
SIST EN ISO/IEC 27701:2025
ДействующийInformation security, cybersecurity and privacy protection - Privacy information management systems - Require…
Overview SIST EN ISO/IEC 27701:2025 - Information security, cybersecurity and privacy protection - Privacy information management systems (PIMS) - Requirements and guidance (ISO/IEC 27701:2025) - spe…
SIST EN ISO/IEC 29134:2020
ДействующийInformation technology - Security techniques - Guidelines for privacy impact assessment (ISO/IEC 29134:2017)
Overview SIST EN ISO/IEC 29134:2020 provides internationally recognized guidelines for conducting Privacy Impact Assessments (PIAs) within information technology systems. Developed by the Internation…
SIST EN ISO/IEC 27018:2020
ДействующийInformation technology - Security techniques - Code of practice for protection of personally identifiable inf…
Overview EN ISO/IEC 27018:2020 (ISO/IEC 27018:2019) is a code of practice for protecting personally identifiable information (PII) processed in public cloud environments where the cloud provider acts…