Search Results
125 results found with an empty search
- ISO/IEC 27013 | ISO27001security
Back Up Next ISO/IEC 27013 ISO/IEC 27013:2021 (amended ) — Information security, cybersecurity and privacy protection — Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 (third edition) Up Abstract ISO/IEC 27013 "gives guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1 for organisations intending to: (a) implement ISO/IEC 27001 when ISO/IEC 20000-1 is already implemented, or vice versa; (b) implement both ISO/IEC 27001 and ISO/IEC 20000-1 together; or (c) integrate existing management systems based on ISO/IEC 27001 and ISO/IEC 20000-1. [ISO/IEC 27013] focuses exclusively on the integrated implementation of an information security management system (ISMS) as specified in ISO/IEC 27001 and a service management system (SMS) as specified in ISO/IEC 20000-1.” [Source: ISO/IEC 27013:2021] Introduction This standard provides guidance on implementing an integrated information security and IT service management system , based on both ISO/IEC 27001 (ISMS) and ISO/IEC 20000-1 (IT service management specification, originally based on ITIL - the UK Government's IT I nfrastructure L ibrary). The benefits include: Credible provision of effective and secure information/IT services. Cost reduction, quicker implementation, better communication, increased reliability and efficiency, and easier certification process due to integration and commonality. Mutual understanding by service management and information security personnel. Scope ISO/IEC 27013 advises users on the processes and supporting documentation required to implement an integrated dual management system, for example helping them to: Implement ISO/IEC 27001 when they have already adopted ISO/IEC 20000-1 , or vice versa ; Implement both ISO/IEC 27001 and ISO/IEC 20000-1 together from scratch (brave souls!); or Align and coordinate pre-existing ISO/IEC 27001 and ISO/IEC 20000-1 management systems. The scope of this standard spans two ISO/IEC JTC 1 subcommittees. SC 27 and SC 7 collaborated to ensure that the information security and IT service management perspectives were both duly considered. Structure The standard proposes a framework for organising and prioritising activities, offering advice on: Aligning the information security and service management and improvement objectives; Coordinating multidisciplinary activities, leading to a more integrated and aligned approach (e.g . both donor standards specify incident management activities, with differing scopes for the incidents but otherwise quite similar); A collective system of processes and supporting documents (policies, procedures etc .); A common vocabulary and shared vision; Combined business benefits to customers and service providers plus additional benefits arising from the integration of both management systems; and Combined auditing of both management systems at the same time, with the consequent reduction in audit costs (we hope!). Main clauses: 4: Overview of ISO/IEC 27001 and ISO/IEC 20000-1 5: Approaches for integrated implementation 6: Integrated implementation considerations Two annexes compare the ISO/IEC 27001 and 20000 standards side-by-side A third annex compares the terms and definitions between the standards Status The first edition was published in 2012. The second edition was published in 2015 . The current third edition was published in 2021 . A 4-page amendment to the third edition was published in 2024 , updating references to the 2022 versions of ISO/IEC 27001 and 27002 , adding useful guidance on selection of information security controls for the S tatement o f A pplicability from Annex A or elsewhere (1 of the 4 pages!). Commentary Write out 1,000 times: “There is more to information security than securing IT. There is more to information security than securing IT. There is more to information security than securing IT. There is more to information security than securing IT ... ” Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27050-3 | ISO27001security
Back Up Next ISO/IEC 27050-3 ISO/IEC 27050-3:2020 — Information technology — Security techniques — Electronic discovery — Part 3: Code of practice for electronic discovery (second edition) Up Abstract ISO/IEC 27050 part 3 “provides requirements and recommendations on activities in electronic discovery, including, but not limited to, identification, preservation, collection, processing, review, analysis and production of electronically stored information (ESI). In addition, this document specifies relevant measures that span the lifecycle of the ESI from its initial creation through to final disposition. [Part 3] is relevant to both non-technical and technical personnel involved in some or all of the electronic discovery activities. It is important to note that the user is expected to be aware of any applicable jurisdictional requirements.” [Source: ISO/IEC 27050-3:2020 ] Introduction Part 3 of ISO/IEC 27050 identifies requirements and offers guidance on the seven main steps of eDiscovery noted in part 1 i.e . ESI: Identification - what information from/at a crime scene might be relevant and useful? Preservation - starting the chain of evidence. Collection - removing physical media etc, Processing - forensic bit-copies. Review - searching evidence for relevant info. Analysis - picking out the most weighty bits for court. Production - preparing to present evidence+analysis in court. Scope The structured processes involving E lectronically S tored I nformation. Structure Main clauses: 5: Electronic discovery background 6: Electronic discovery requirements and guidance Status The first edition was published in 2017 . The current second edition was published in 2020 . Commentary Part 3 is, essentially, a basic, generic how-to-do-it guide laying out the key elements that will no doubt form the basis of many digital forensics manuals. While full-time forensics specialists have their own well-practiced procedures, training, forms, tools etc. , corporate information security pro's who only get involved occasionally in this area may benefit from preparing the basics to get the process started properly, even if the management decision is soon made to call in eForensics specialists. If things are fouled-up at the beginning, they are unlikely to be recoverable later on, compromising potentially valid cases. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27041 | ISO27001security
Back Up Next ISO/IEC 27041 ISO/IEC 27041:2015 — Information technology — Security techniques — Guidance on assuring suitability and adequacy of incident investigative method (first edition) Up Abstract “ISO/IEC 27041:2015 provides guidance on mechanisms for ensuring that methods and processes used in the investigation of information security incidents are "fit for purpose". ...” [Source: ISO/IEC 27041:2015] Introduction The fundamental purpose of the ISO27k digital forensics standards is to promote good practice methods and processes for forensic capture and investigation of digital evidence. While individual investigators, organisations and jurisdictions may well retain certain methods, processes and controls, it is hoped that standardization will (eventually) lead to the adoption of similar if not identical approaches internationally, making it easier to compare, combine and contrast the results of such investigations even when performed by different people or organisations and potentially across different jurisdictions. Scope The primary focus of this standard is on assurance for the forensics processes and tools used in the investigation of digital evidence. Credibility, trustworthiness and integrity are fundamental requirements for all forensics methods: this standard promotes the assurance aspects of investigating digital evidence. The standard offers guidance on assuring the suitability and adequacy of the forensic methods used to investigate digital evidence, describing methods through which all stages of the investigation process can be shown to be appropriate (proper and suitable in themselves, and correctly performed). Structure Main clauses: 5: Method development and assurance 6: Assurance models 7: Production of evidence for assurance Annex A: Examples Status The current first edition was published in 2015 and confirmed unchanged in 2021. Commentary I am puzzled why SC 27 publishes and maintains several distinct forensics standards covering different aspects of forensics, when they are in reality complementary parts of the same process. ISO/IEC 27037 concerns the initial capturing of digital evidence. This standard offers guidance on the assurance aspects of digital forensics e.g. ensuring that the appropriate methods and tools are used properly. ISO/IEC 27042 covers what happens after digital evidence has been collected i.e. its analysis and interpretation. ISO/IEC 27043 covers the broader incident investigation activities, within which forensics usually occur. ISO/IEC 27050 (in 4 parts) concerns electronic discovery ... which is pretty much what the other standards cover. British Standard BS 10008 “Evidential weight and legal admissibility of electronically stored information (ESI), Specification.” may also be of interest. A multi-part standard would make more sense to me, with a part 1 overview explaining how the jigsaw pieces fit together. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27035-3 | ISO27001security
Back Up Next ISO/IEC 27035-3 ISO/IEC 27035-3:2020 — Information technology — Information security incident management — Part 3: Guidelines for ICT incident response operations (first edition) Up Abstract ISO/IEC 27035 part 3 “gives guidelines for information security incident response in ICT security operations. [ISO/IEC 27035-3] does this by firstly covering the operational aspects in ICT security operations from a people, processes and technology perspective. It then further focuses on information security incident response in ICT security operations including information security incident detection, reporting, triage, analysis, response, containment, eradication, recovery and conclusion ...” [Source: ISO/IEC 27035-3:2020 ] Introduction Part 3 concerns the 'security operations' elements in response to an IT incident. Scope Part 3 concerns the organisation and processes necessary for the information security function to prepare for, and respond to, IT security events and incidents. Structure Main clauses: 5: Overview 6: Common types of attacks 7: Incident detection operations 8: Incident notification operations 9: Incident triage operations 10: Incident analysis operations 11: Incident containment , eradication and recovery operations 12: Incident reporting operations Annex A: Example of the incident criteria based on information security events and incidents Status The current first edition of part 3 was published in 2020 . In 2025, the standard fell due for review by ISO/IEC JTC 1/SC 27 to decide whether it should be withdrawn, revised or retained as-is. Watch this space. Commentary The standard primarily concerns the IT Department's responses to active, deliberate cyber-attacks such as major hacks or malware infections such as ransomware. However, various other kinds of incident may require similar IT-related responses e.g .: Failed software patches, installations, reconfigurations or other changes to systems, applications, networks, services, protocols etc. Inappropriate and damaging automated activities by AI systems and agents, plus incidents relating to shadow-IT and shadow-AI (unauthorised arrangements outside IT Department's remit). Hardware failures. Business incidents or situations requiring urgent IT responses, such as takeover attempts or mergers. Environmental disasters such as storms, floods, fires, plane crashes, wars, power cuts and telecomms outages. Serious incidents involving the workforce such as pandemics, strikes or mass resignations. Failures of other important security controls, including governance and management controls e.g. serious fraud or exec-level impropriety. Supply chain incidents or those affecting related organisations e.g. other parts of a group structure or multinational enterprise. Therefore, business continuity and resilience arrangements are inevitably linked to risk, incident and security management, as well as business management. It's a complex and dynamic mesh of issues, only part of which is covered by this standard. The standard’s title contains a commonplace but unexpanded abbreviation: ICT. Plain old "IT" has included communications and networking for decades, so I'm not sure why anyone feels the need to insert the 'C'. Up Up Up This page last updated: 10 July 2026
- ISO/IEC TS 27569 | ISO27001security
Back Up Next ISO/IEC TS 27569 ISO/IEC TS 27569 — Personal identifiable information (PII) processing record information structure [PROPOSAL] Up Abstract ?? Introduction ?? Scope ?? Structure ?? Status An ISO/IEC JTC 1/SC 27/WG 5 project produced a P reliminary W ork I tem in 2025. However, the project subsequently appears to have been absorbed into the ongoing update of ISO/IEC 27560 , possibly. There is no information about it on ISO.org. Commentary I'm confused. Sorry. I am not close enough to WG5 to know what's really going on here. Up Up Up This page last updated: 10 July 2026
- ISO/IEC TS 27022 | ISO27001security
Back Up Next ISO/IEC TS 27022 ISO/IEC TS 27022:2021 — Information technology — Guidance on information security management system processes (first edition) Up Abstract ISO/IEC TS 27022 "defines a process reference model (PRM) for the domain of information security management, which is meeting the criteria defined in ISO/IEC 33004 for process reference models (see Annex A). It is intended to guide users of ISO/IEC 27001 to: incorporate the process approach as described by ISO/IEC 27000:2018, 4.3, within the ISMS; be aligned to all the work done within other standards of the ISO/IEC 27000 family from the perspective of the operation of ISMS processes; support users in the operation of an ISMS. [ISO/IEC TS 27022] is complementing the requirements-oriented perspective of ISO/IEC 27003 with an operational, process-oriented point of view.” [Source: ISO/IEC TS 27022:2021] Introduction The standard (a T echnical S pecification) “provides a process reference model (PRM) for information security management, which differentiates between ISMS processes and measures/controls initiated by them ... [and] describes the ISMS processes implied by ISO/IEC 27001.” The standard is based on a PhD thesis . Scope The standard lays out, in some detail, a P rocess R eference M odel comprising a generic suite of ISMS processes that organisations may wish to use as a basis for designing custom processes within their own ISMS. The standard “is intended to guide users of ISO/IEC 27001 to: incorporate the process approach as described by ISO/IEC 27000:2018 clause 4.3 within the ISMS be aligned to all the work done within other standards of the ISO/IEC 27000 family from the perspective of the operation of ISMS processes support users in the operation of an ISMS – the document will complement the requirements oriented perspective of ISO/IEC 27003 with an operational, process oriented point of view.” This advisory standard does not add or modify the ISMS requirements in ISO/IEC 27001 . Structure The ISMS processes described fall into 3 “categories” (types or groups) i.e. : Governance activities (confusingly titled ‘management processes’) - direction and oversight for the ISMS; Core operations e.g. information risk and security management, policy management, incident management, internal audits ...; and Support e.g. records management, communicating with interested parties about the ISMS, managing relationships with ISMS ‘customers’ ... The processes are each laid out in an Appendix, first as a table specifying: Process “category” denoting the type of process A brief description Objective/purposes Input[s] and Output[s] Activities/functions i.e. a few words for each of the main steps in the process Informative references. The table is followed by a flowchart summarising each process on one side or less. Status The current first edition was published in 2021 . An amendment updating references to ISO/IEC 27001:2022 and other ISO27k standards was in preparation in 2024 but the proposed revision of the standard was dropped due to lack of expert support. Commentary Mature organisations may already have processes for: Asset management; Audit management, both internal and external; Business continuity management (see ISO 22301: ISO/IEC 27001 is limited to continuity of information security operations during major incidents); Change management plus configuration management and version control; Continuous improvement and maturity management; Database [security] management; Exemption management (management-approved nonconformity with policies); Facilities management including power and other services for the computer room; Identity, access rights and user account management; Incident management including incident investigation and forensics; Information management in general; Information [security] risk management (partly covered by ISO/IEC 27005 ); Information security management (covered by ISO/IEC 27001 , 27002 , 27003 and others); IT! Internal audits and certification audits; Key management, plus the rest of cryptography; Log management, plus alarms and alerts; Metrics and management information management (partly covered by ISO/IEC 27004 ); Monitoring and oversight of the risk management and security arrangements; Patching, including emergency arrangements for urgent fixes; Performance and capacity management; Personnel/HR management including “onboarding” and “offboarding” (nasty neologisms!); Preventive and corrective actions; Quality management, especially quality assurance; Service management [organisations that are heavily process-oriented may be using ITIL/ISO 20000, in which case ISO/IEC 27013 is applicable]; Supplier/vendor relationship management, including telecomms, Internet and cloud services, outsourced development, contract security guards, maintenance/servicing, professional services (consulting, contracting, accounting, tax advising) etc. ; System and network [security] management; System/software development and testing ... ... and more. Providing generally-applicable advice without imposing further constraints is challenging. The processes need to be described without losing the flexibility to cater for myriad differences between organisations. In particular, the processes need to be valuable (cost-effective) in practice to justify their existence, for instance by: Removing unnecessary bureaucracy, rationalising and justifying whatever remains; Facilitating or encouraging process automation and innovation where applicable; Facilitating or encouraging use of existing processes, adapting them where necessary; Perhaps re-using effective ISMS processes elsewhere in the organisation; Managing the processes themselves e.g. management processes for monitoring, reviewing, evaluating and maintaining the ISMS processes, responding to changes, identifying and exploiting improvement opportunities etc . It would be unfortunate if ISMS processes were perceived as distinct from normal operations, rather than being integral to the organisation’s routine activities. The process for managing an information security or privacy incident, for example, is essentially the same as that for managing any other incident, hence it is generally unnecessary to create an alternative incident management process if the existing one (perhaps with a few tweaks) is effective. Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27091 | ISO27001security
Back Up Next ISO/IEC 27091 ISO/IEC 27091 — Cybersecurity and privacy — Artificial Intelligence — Privacy protection [DRAFT] Up Abstract [ISO/IEC 27091] "provides guidance for organizations to address privacy risks in artificial intelligence (AI) systems, including machine learning (ML) models. [ISO/IEC 27091] helps organizations identify privacy risks throughout the AI system lifecycle, and establishes mechanisms to evaluate the consequences and treatment of such risks. ..." [Source: ISO/IEC 27091 D raft I nternational S standard] Introduction By gathering and processing substantial quantities of information (maybe even 'big data'), AI/ML systems may erode privacy - for example by linking personal information from disparate sources back to individual people, or inferring sensitive details - unless appropriate privacy arrangements are made. Scope The standard applies to all manner of organisations that develop or use AI systems. The focus is on mitigating privacy risks by integrating suitable privacy controls into the design of AI /M achine L earning systems. Business decisions about whether it is even appropriate to design, build, use and connect AI systems and services at all, plus general considerations for information risk and security management (e.g . ensuring data accuracy plus system/services resilience, and dealing with incidents) are largely or completely out of scope. Structure Main clauses: 5: Framework for privacy analysis of AI systems - gives an overview of the classical information risk management process i.e. identify, analyse, evaluate and treat privacy risks. 6: Privacy of AI models - discusses a few well-known AI system 'privacy threats (modes of attack that are relevant to privacy e.g. membership inference, training data extraction, poisoning, model inversion, insider risk ...) with generic advice on mitigating controls (e.g. limiting access, anonymisation and pseudonimysation, input and output filtering). 7: Privacy in AI system lifecycle - privacy engineering. Annex A: Additional information for privacy analysis of AI systems. Annex B: Use case template Status The standard development project started in 2023. The standard is at D raft I nternational S tandard stage with 65 pages of comments received. It may yet be published towards the end of 2026. Commentary The standard's risk-based approach makes sense, but (as with so much AI security-related work at the moment) the scope, focus or perspective feels rather academic and constrained to me. The standard does not, in my admittedly jaundiced opinion, adequately address or acknowledge the bigger picture here e.g.: Broader aspects of information risk and security management such as strategies, policies, architectures, compliance, change and incident management, including the extent to which those activities address privacy, specifically [the standard refers to ISO/IEC 27090 for this - currently also in draft]; 'Classical' information risks, threats, attacks, vulnerabilities, impacts and consequences that just happen to involve AI, such as smart phishing, smart malware, smart fraud, smart piracy etc. using AI systems, services and tools for nefarious purposes including coercion, misinformation and disinformation - with incidental and indirect rather than central and direct privacy implications; Societal aspects such as the continued erosion of trust and control over our personal information as it is increasingly being demanded, requested, gathered, shared and exploited, incuding by various authorities, both openly and covertly, systematically, at scale; The longstanding disparity of privacy approaches between most of the world (with GDPR and OECD guidance essentially giving individuals rights to retain ownership and control of their own personal information in perpetuity), and the USA in particular (where it seems personal information can be gathered, shared and exploited commercially by whoever holds it, similarly to other types of information, with little referene to the individuals concerned); Compliance, commercial, technological and practical implications if, say, the individuals whose personal information has been used for model training decide to withdraw their consent and (uner GDPR) insist that their information is deleted and no longer used, or insist on corrections being made; Innovation and novelty of all this, meaning that collectively we have quite a journey ahead towards maturity, with anticipated and surprising incidents ('learning points') likely along the way - such as people naively building and using advanced AI systems without reference to applicable laws, regulations, policies and practices ('shadow AI'), and the race towards A rtificial G eneral I ntelligence; Commercial aspects such as the intense competition within the AI industry, and what will happen with potentially valuable AI models, big data and metadata if AI companies implode or are taken over, possibly but not necessarily just when the AI bubble bursts. However, the standard does usefully discuss the use of AI to support: Privacy consent management and control; P rivacy- E nhancing T echnologies such as cryptographic authentication, encryption and anonymisation, pseudonymisation and data minimisation (a nod towards risk avoidance); Privacy assurance such as auditing, monitoring, detecting and responding to privacy violations; Security for AI models and federated learning, including access control and identity management; N atural L anguage P rocessing for data privacy policies. Up Up Up This page last updated: 10 July 2026
- ISO/IEC TS 27115-2 | ISO27001security
Back Up Next ISO/IEC TS 27115-2 ISO/IEC TS 27115-2 — Information security, cybersecurity and privacy protection — Cybersecurity of system of systems — Part 2: Security architecture evaluation (DRAFT) Up Abstract ?? Introduction ?? Scope [ISO/IEC TS 27115-2] provides a framework to evaluate the cybersecurity of complex systems, including systems of systems, based on ISO/IEC TS 27115-1. The framework uses basic architecture concepts to support model-based, comprehensive and scalable security solutions and their evaluation. Structure ?? Status Part 2 is due out in 2028. It is currently at Approved Work Item stage. Commentary TBA Up Up Up This page last updated: 10 July 2026
- ISO/IEC 27034-1 | ISO27001security
Back Up Next ISO/IEC 27034-1 ISO/IEC 27034-1:2011 (corrected )— Information technology — Security techniques — Application security — Part 1: Overview and concepts (first edition) Up Abstract “ISO/IEC 27034 provides guidance to assist organizations in integrating security into the processes used for managing their applications. [Part 1] presents an overview of application security. It introduces definitions, concepts, principles and processes involved in application security. ISO/IEC 27034 is applicable to in-house developed applications, applications acquired from third parties, and where the development or the operation of the application is outsourced.” [Source: ISO/IEC 27034-1:2011] Introduction As with other multipartite ISO27k standards , the first part sets the scene for the remainder, providing a general introduction and outlining the remaining parts. Scope The ISO/IEC 27034 standards take a process approach to specifying, designing, developing, testing, implementing and maintaining security functions and controls in application systems. For instance application security is not defined as the state of security of an application system (the results of the process) but as “a process an organisation can perform for applying controls and measurements to its applications in order the manage the risk of using them ”. They use the concept of defining a Targeted Level of Trust (similar to a security plan) for an application, designing and building the application to meet it, and then validating the application against it. Structure Main clauses: 5: Structure of ISO/IEC 27034 6: Introduction to application security 7: ISO/IEC 27034 overall processes 8: Concepts Annex A: Mapping an existing development process to ISO/IEC 27034 Case Study Annex B: Mapping ASC with an existing standard Annex C: ISO/IEC 27005 risk management process mapped with the ASMP This part is ~80 pages long with plenty of detail. Status The current first edition of part 1 was published in 2011 . Three minor corrections plus a revised figure were published in 2014 as a technical corrigendum. The corrected standard was confirmed in 2022. A project to update the ISO/IEC 27034 standards commenced in 2024. It will take years to complete. All parts of the standard should conform with JTC 1/SC 17’s standards on software engineering, plus relevant ISO27k standards , and the terminology should align with the ISO 31000 series . A major redesign of the scope of the individual ISO/IEC 27034 standards and the set as a whole is under way, with the intention of making them more relevant and useful for SMEs, and better aligned with other software engineering standards - in particular, ISO/IEC/IEEE 12207 (software life cycle processes) and ISO/IEC/IEEE 15288 (system life cycle processes). The revision project was therefore stopped and restarted in 2025 at P reliminary W ork I nstruction stage. Commentary The ISO/IEC 27034 standards draw on concepts such as auditing and certification of application systems similar in style to the C ommon C riteria and similar schemes primarily used for government and military systems. The text tends to emphasize deliberate threats arising from external adversaries implying the importance of confidentiality controls, arguably downplaying insider and accidental threats and the need for integrity and availability controls, but the process described ostensibly takes account of the full spectrum of security risks and controls. Rewriting all the parts to adopt ISO's guidance on plain English would be challenging but could substantially extend the utility and value of these standards. Up Up Up This page last updated: 10 July 2026
- ISO/IEC TR 27550 | ISO27001security
Back Up Next ISO/IEC TR 27550 ISO/IEC TR 27550:2019 — Information technology — Security techniques — Privacy engineering for system life cycle processes (first edition) Up Abstract ISO/IEC TR 27550 "provides privacy engineering guidelines that are intended to help organisations integrate recent advances in privacy engineering into system life cycle processes. ...” [Source: ISO/IEC TR 27550:2019] Introduction ‘Privacy engineering’ involves taking account of privacy during the entire cradle-to-grave lifecycle of IT systems and the associated processes, such that privacy is and remains an integral part of their function. Scope This is an IT security standard about engineering IT systems to satisfy privacy requirements relating to the protection of personal data. Structure Main clauses: 5: Privacy engineering 6: Integration of privacy engineering in ISO/IEC/IEEE 15288 Annex A: Additional guidance for privacy engineering objectives Annex B: Additional guidance for privacy engineering practice Annex C: Catalogues Annex D: Examples of risk models and methodologies The standard: Discusses how privacy engineering supports system and security engineering, information risk management, knowledge management etc. Elaborates on conceptual principles such as privacy-by-design and privacy-by-default , important design goals noted in GDPR and elsewhere; Elaborates on the processes for identifying, evaluating and treating privacy risks in the course of IT systems design; Explains how IT systems can be engineered to support and satisfy the OECD privacy principles which form the basis of most privacy laws and regulations. Status The current first edition was published as a T echnical R eport in 2019. Commentary The procedures for operating, using, monitoring, managing and maintaining IT systems and their privacy controls are just as important as the technical controls themselves, and also benefit from being systematically developed (specified, designed, documented, mandated, operated, monitored, maintained ...): it is a good thing this standard is not limited to the technology. Up Up Up This page last updated: 10 July 2026
