Site icon Deming Certification Services Pvt Ltd

ISO 27018:2019 Information technology security techniques

Courtesy: ISO 27018:2019 Information technology security techniques

ISO/IEC 27018 is a security standard part of the ISO/IEC 27000 family of standards. It was the first international standard about the privacy in cloud computing services which was promoted by the industry. It was created in 2014 as an addendum to ISO/IEC 27001, the first international code of practice for cloud privacy. It helps cloud service providers who process personally identifiable information (PII) to assess risk and implement controls for protecting PII. It was published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC) under the joint ISO and IEC subcommittee, ISO/IEC JTC 1/SC 27.

Standard Versions

That standard has two versions:

Structure of the standard

The official title of the standard is “Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors”. ISO/IEC 27018:2019 has eighteen sections, plus a long annex, which cover:1. Scope2. Normative References3. Terms and definitions4. Overview5. Information security policies6. Organization of information security7. Human resource security8. Asset management9. Access control10. Cryptography11. Physical and environmental security12. Operations security13. Communications security14. System acquisition, development and maintenance15. Supplier relationships16. Information security incident management17. Information security aspects of business continuity management18. Compliance

Objectives

The objective of this document, when used in conjunction with the information security objectives and controls in ISO/IEC 27002, is to create a common set of security categories and controls that can be implemented by a public cloud computing service provider acting as a PII processor. It has the following objectives:

Exit mobile version