ISO 27701: 2019: Security techniques — Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management — Requirements and guidelines

The standard covers privacy information management system (PIMS) and is therefore classified as a management system, expanding the specifications ISO/IEC 27001 and ISO/IEC 27002.

The standard was developed by the WG 5 group of the technical committee, which writes the ISO/IEC JTCI/SC 27: Information security, cybersecurity and privacy protection standard. Delegates from Microsoft, BSI Group, and the French committee for the supervision of private information protection participated in the technical committee.

ISO 27701: 2019 is based on ISO/IEC 29100: 2011: Information technology — Security techniques — Privacy framework; ISO 29151: 2017: Information technology — Security techniques — Code of practice for personally identifiable information protection; ISO/IEC 19944: 2017: Information technology — Cloud computing — Cloud services and devices: Data flow, data categories and data use; and ISO/IEC 29134: 2017: Information technology — Security techniques — Guidelines for privacy impact assessment.

Note the definition of the terms: customer, controller, and processor.

The standard includes chapters on:

The road to certification

To initiate the process, we recommend purchasing the standard at the Standards Institution of Israel Information Center.

Certification follows the successful implementation an organization's in-house quality management system pursuant to the requirements of the standard. To start this process, it is recommended to purchase the standard at the Standards Institution of Israel Information Center, study the requirements, and participate in appropriate training. It is also possible to consult with the quality management experts and undergo an audit by Standards Institution of Israel to check for shortcomings.

The process ought to be seen as an opportunity for improvement via the organization team which will receive management commitment and involvement. At the end of the process, independent Standards Institution of Israel auditors will perform an audit that confirms that the organization's management system is compatible to the specifications of the standard.

Click here to obtain a quote

The Standards Institution of Israel – the right choice for you!



Other quality management standards

For further details
To register