ISO standard for protecting personal data

September 2019 News & Events, Information Security

We are more connected than ever, bringing with it the joys, and risks, of our digital world. Cybersecurity is a growing concern, with attacks against business almost doubling over the last few years ( www.securitysa.com/*wf18a – redirects to http://reports.weforum.org/global-risks-2018/executive-summary/) and is an increasingly significant threat to global stability.

Unsurprisingly, laws and regulations are rapidly being put in place to reduce these risks and protect our digital privacy. How can organisations keep on top of these requirements and protect themselves at the same time? The world’s first international standard to help organisations manage privacy information and meet regulatory requirements has just been published.

Protecting our digital privacy is a significant business concern. According to IBM the average cost of a data breach is USD 3.6 million, and legal obligations are increasingly stringent ( www.securitysa.com/*ibm1 – redirects to https://www.ibm.com/downloads/cas/ZYKLN2E3).

As we get more connected, governments all over the world are introducing various privacy regulations, such as the European Union’s General Data Protection Regulation (GDPR), which organisations must adhere to. The new ISO standards will help businesses meet such requirements, whatever jurisdiction they work in.

ISO/IEC 27701, Security Techniques – Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management – Requirements and Guidelines, specifies the requirements for establishing, implementing, maintaining and continually improving a privacy-specific information security management system. In other words, a management system for protecting personal data (PIMS).

Formerly referred to as ISO/IEC 27552 during its development, it builds on ISO/IEC 27001, Information Technology – Security Techniques – Information Security Management Systems – Requirements, providing the necessary extra requirements when it comes to privacy.

Dr Andreas Wolf, Chair of the ISO technical committee that developed the standard, said almost every organisation processes personally identifiable information (PII), and protecting it is not only a legal requirement but a societal need.

“ISO/IEC 27701 defines processes and provides guidance for protecting PII on an ongoing, ever evolving basis. Because being a management system, it defines processes for continuous improvement on data protection, particularly important in a world where technology doesn’t stand still.”

ISO/IEC 27701 was developed by Working Group 5 of ISO technical committee ISO/IEC JTC1/SC 27, Information Security, Cybersecurity and Privacy Protection (the secretariat of which is held by DIN, ISO’s member for Germany), which is made up of experts from all over the world from data protection authorities, security agencies, academia and industry.

Matthieu Grall of the Commission Nationale de l’Informatique et des Libertés, the French independent watchdog for the protection of personal data, was an active participant of SC 27 and a contributor to the development of the standard. With increasingly stringent data protection requirements and laws, he said there is a real need for this standard.

“Despite the risks of not complying to these regulations, we know that many organisations are simply not ready and need guidance. With the number of complaints and fines related to privacy and data protection on the rise, the need for this standard is now obvious.

“Moreover, organisations need to bring trust to their authorities, partners, customers and employers. Such a standard will contribute strongly to this trust.”

For more information, go to www.iso.org





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Protect the integrity of critical video evidence
Surveillance News & Events
SWEAR has announced the Community Video Integrity Project, a new initiative designed to help cities and public agencies proactively protect the integrity of critical video and establish a verifiable record of authenticity from the moment it is captured.

Read more...
Keenfinity creates two security businesses
News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
The Keenfinity Group, today announced the creation of two dedicated businesses from its former Intrusion & Access portfolio. Radionix will focus exclusively on intrusion alarm systems, while MiCOS will become a dedicated access control company.

Read more...
Genetec global leader in video management software
Genetec News & Events Surveillance
Independent analyst firms rank Genetec as global leader in video management software. Research shows continued market share gains for Genetec as both the VMS and VSaaS markets continue to expand worldwide.

Read more...
DeepAlert Launches COMMAND
News & Events Surveillance
Cloud-based, AI-powered surveillance monitoring platform cuts operator alert fatigue and response times, and becomes DeepAlert's primary monitoring platform for security companies and control rooms worldwide.

Read more...
ONVIF strengthens authenticity of video surveillance footage
Surveillance News & Events
Amid a rising tide of manipulated and AI-generated footage, the add-on will equip the surveillance industry with a shared, standards-based way to establish where video came from and whether it has remained unaltered.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Integrating the industry
News & Events Infrastructure
With private security, neighbourhood watches, CCTV, drones, control rooms and community safety networks expanding across the country, the next frontier may not be more technology, but connecting what already exists.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.