SIST EN ISO/IEC 29101:2021 PDF
Information technology - Security techniques - Privacy architecture framework (ISO/IEC 29101:2018)
Information technology - Security techniques - Privacy architecture framework (ISO/IEC 29101:2018)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 50
- Дата публикации:
- 15 ноября 2021 г.
- Издание:
- (ISO/IEC 29101:2018)
- ICS:
- 35.030
This document defines a privacy architecture framework that: — specifies concerns for ICT systems that process PII; — lists components for the implementation of such systems; and — provides architectural views contextualizing these components. This document is applicable to entities involved in specifying, procuring, architecting, designing, testing, maintaining, administering and operating ICT systems that process PII. It focuses primarily on ICT systems that are designed to interact with PII principals.
Abstract
Overview
EN ISO/IEC 29101:2021 (ISO/IEC 29101:2018) defines a privacy architecture framework for information and communication technology (ICT) systems that store and process personally identifiable information (PII). The standard specifies PII-related concerns, lists components for implementing privacy-aware systems, and provides multiple architectural views to contextualize those components. It is intended for organizations involved in specifying, procuring, designing, testing, operating and maintaining ICT systems - especially systems that interact directly with PII principals.
Key topics
- Scope and purpose: a high-level architecture to help implement privacy controls consistently across ICT systems that process PII.
- PII lifecycle: explicit consideration of PII phases - collection, transfer, use, storage, disposal - so privacy can be addressed at each stage.
- Actors and roles: definitions and views for PII principals, controllers and processors, and their ICT systems.
- Privacy concerns and requirements: alignment with the privacy principles in ISO/IEC 29100 and guidance on deriving privacy safeguarding requirements.
- Architectural views:
- Component view - layers such as privacy settings, identity & access management, and PII layer.
- Actor view - ICT systems for principals, controllers and processors.
- Interaction view - how components and actors exchange PII and enforce controls.
- Privacy enhancing technologies (PETs): how PETs can be used as privacy controls and integrated into architectures.
- Informative examples: annexes include examples such as PII aggregation with secure computation and pseudonymous identity/access-management systems.
Applications
EN ISO/IEC 29101 is practical for:
- Designing privacy-by-architecture solutions and embedding privacy controls in system architectures.
- Specifying requirements for procurement contracts, RFPs and vendor assessments for systems that process PII.
- Guiding software architects, system integrators and security teams on layering identity, access and PII handling.
- Supporting privacy impact assessments, testing and operational controls by mapping technical controls to PII lifecycle stages.
- Informing choices of privacy enhancing technologies (pseudonymization, secure computation, selective disclosure) as part of an architecture.
Who should use this standard
- IT architects, security architects and system designers
- Data protection officers and privacy engineers
- Procurement teams and technical evaluators
- Developers, testers and operations teams managing PII-processing systems
Related standards
- ISO/IEC 29100 - Privacy framework (privacy principles referenced throughout 29101)
- ISO/IEC/IEEE 42010 - Systems and software engineering - Architecture description
EN ISO/IEC 29101 helps organizations translate privacy principles into concrete architecture components and views, making it a practical reference for building, procuring and operating privacy-aware ICT systems that process PII.
Технические детали
- Технический комитет
- ITC - Information technology
- SKU
- SIST EN ISO/IEC 29101:2021
Похожие стандарты
Упомянутые в описании и другие стандарты SIST
SIST EN ISO/IEC 29100:2020
ДействующийInformation technology - Security techniques - Privacy framework (ISO/IEC 29100:2011, including Amd 1:2018)
Overview EN ISO/IEC 29100:2020 (ISO/IEC 29100:2011, including Amd 1:2018) defines a high-level privacy framework for the protection of personally identifiable information (PII) in information and com…
SIST EN ISO 6338:2026
ДействующийMethod to calculate GHG emissions at LNG plant (ISO 6338:2023)
Overview SIST EN ISO 6338:2026 / ISO 6338:2023 establishes a standardized method for calculating greenhouse gas (GHG) emissions at liquefied natural gas (LNG) plants, both onshore and offshore. Devel…
SIST-TP CEN ISO/ASTM TR 52958:2026
Additive manufacturing of metals - Powder bed fusion (PBF) - In-situ coaxial photodiode monitoring for lack o…
Overview SIST-TP CEN ISO/ASTM TR 52958:2026 specifies a workflow for the detection of lack of fusion flaws during the additive manufacturing of metals using powder bed fusion-laser based (PBF-LB) pro…
SIST EN ISO 41002:2026
ДействующийFacility management - Development of the facility management organization (ISO 41002:2026)
Overview SIST EN ISO 41002:2026 - Facility management - Development of the facility management organization offers strategic guidance for building and developing robust facility management (FM) organ…
SIST EN ISO 844:2026
ДействующийRigid cellular plastics - Determination of compressive properties (ISO 844:2026)
Overview SIST EN ISO 844:2026 - Rigid Cellular Plastics: Determination of Compressive Properties (ISO 844:2026) provides standardized methods for measuring the compressive properties of rigid cellula…
SIST-TS CEN ISO/TS 17664-3:2026
ДействующийProcessing of health care products - Information to be provided by the medical device manufacturer for the pr…
Overview SIST-TS CEN ISO/TS 17664-3:2026 sets out comprehensive guidance for grouping reusable medical devices based on their cleaning requirements. This technical specification, prepared collaborati…
SIST EN ISO 8980-4:2026
ДействующийOphthalmic optics - Uncut finished spectacle lenses - Part 4: Specifications and test methods for the propert…
Overview SIST EN ISO 8980-4:2026 specifies requirements and test methods for the properties of anti-reflective coatings and hydrophobic coatings applied to uncut finished spectacle lenses. Developed…
SIST EN ISO 5361:2023/A1:2026
ДействующийAnaesthetic and respiratory equipment - Tracheal tubes and connectors - Amendment 1: Reinstatement of third e…
Overview SIST EN ISO 5361:2023/A1:2026 is an amendment to the internationally recognized ISO 5361:2023 standard, which specifies requirements for anaesthetic and respiratory equipment, with a focus o…