Information technology - Security techniques - Code of practice for personally identifiable information protection (ISO/IEC 29151:2017)

ISO/IEC 29151:2017 establishes control objectives, controls and guidelines for implementing controls, to meet the
requirements identified by a risk and impact assessment related to the protection of personally identifiable information
In particular, this Recommendation | International Standard specifies guidelines based on ISO/IEC 27002, taking into
consideration the requirements for processing PII that may be applicable within the context of an organization's
information security risk environment(s).
ISO/IEC 29151:2017 is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100),
including public and private companies, government entities and not-for-profit organizations that process PII.

Informationstechnik - Sicherheitsverfahren - Leitfaden für den Schutz personenbezogener Daten (ISO/IEC 29151:2017)

Diese Empfehlung | Internationale Norm erstellt Maßnahmenzielsetzungen, Maßnahmen und Leitfäden für die Implementierung von Maßnahmen, um die im Rahmen einer Risiko- und Wirkungsbeurteilung in Verbindung mit dem Schutz personenbezogener Daten (pbD) ermittelten Anforderungen zu erfüllen.
Diese Empfehlung | Internationale Norm legt insbesondere Leitfäden auf der Grundlage von ISO/IEC 27002 unter Berücksichtigung der Anforderungen an die Verarbeitung von pbD, die im Kontext zu der Informationssicherheits-Risikoumgebung einer oder mehrerer Organisation(en) anwendbar sein können, fest.
Diese Empfehlung | Internationale Norm ist für alle Arten und Größen von Organisationen, die als Auftragsdatenverarbeiter fungieren (wie in ISO/IEC 29100 definiert), einschließlich öffentlicher und privater Unternehmen, Regierungsbehörden und gemeinnütziger Organisationen anzuwenden.

Technologies de l'information - Techniques de sécurité - Code de bonne pratique pour la protection des données à caractère personnel (ISO/IEC 29151:2017)

Informacijska tehnologija - Varnostne tehnike - Pravila obnašanja pri varovanju osebnih podatkov (ISO/IEC 29151:2017)

Standard ISO/IEC 29151:2017 vzpostavlja cilje kontrol, kontrole in smernice za izvajanje kontrol za namene izpolnjevanja zahtev, določenih z oceno tveganj in učinkov v zvezi z varovanjem osebnih podatkov (PII).
To priporočilo | mednarodni standard določa predvsem smernice, ki temeljijo na standardu ISO/IEC 27002, ob upoštevanju zahtev za obdelavo osebnih podatkov, ki se lahko uporabljajo v okviru okolij za obvladovanje tveganj na področju informacijske varnosti v organizacijah.
Standard ISO/IEC 29151:2017 se uporablja za organizacije vseh vrst in velikosti, ki nastopajo kot upravljavci osebnih podatkov (kot je opredeljeno v standardu ISO/IEC 29100), vključno z javnimi in zasebnimi podjetji, vladnimi subjekti in neprofitnimi organizacijami, ki obdelujejo osebne podatke.

General Information

Publication Date
Withdrawal Date
Current Stage
6060 - Definitive text made available (DAV) - Publishing
Start Date
Due Date
Completion Date


Informacijska tehnologija - Varnostne tehnike - Pravila obnašanja pri varovanju
osebnih podatkov (ISO/IEC 29151:2017)
Information technology - Security techniques - Code of practice for personally identifiable
information protection (ISO/IEC 29151:2017)
Informationstechnik - Sicherheitsverfahren - Leitfaden für den Schutz
personenbezogener Daten (ISO/IEC 29151:2017)
Technologies de l'information - Techniques de sécurité - Code de bonne pratique pour la
protection des données à caractère personnel (ISO/IEC 29151:2017)
Ta slovenski standard je istoveten z: EN ISO/IEC 29151:2022
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.


April 2022
ICS 35.030
English version
Information technology - Security techniques - Code of
practice for personally identifiable information protection
(ISO/IEC 29151:2017)
Technologies de l'information - Techniques de sécurité Informationstechnik - Sicherheitsverfahren - Leitfaden
- Code de bonne pratique pour la protection des für den Schutz personenbezogener Daten (ISO/IEC
données à caractère personnel (ISO/IEC 29151:2017) 29151:2017)
First edition
Information technology — Security
techniques — Code of practice for
personally identifiable information
Technologies de l'information — Techniques de sécurité — Code de
bonne pratique pour la protection des données à caractère personnel
Reference number
ISO/IEC 29151:2017(E)
ISO/IEC 2017
ISO/IEC 29151:2017(E)
ISO/IEC 29151:2017(E)
1 Scope . 1
2 Normative references. 1
3 Definitions and abbreviated terms . 1
3.1 Definitions . 1
3.2 Abbreviated terms . 1
4 Overview . 2
4.1 Objective for the protection of PII . 2
4.2 Requirement for the protection of PII . 2
4.3 Controls . 2
4.4 Selecting controls . 2
4.5 Developing organization specific guidelines . 3
4.6 Life cycle considerations . 3
4.7 Structure of this Specification . 3
5 Information security policies . 4
5.1 Management directions for information security . 4
6 Organization of information security. 4
6.1 Internal organization . 4
6.2 Mobile devices and teleworking . 5
7 Human resource security . 6
7.1 Prior to employment . 6
7.2 During employment . 6
7.3 Termination and change of employment . 6
8 Asset management . 7
8.1 Responsibility for assets . 7
8.2 Information classification . 7
8.3 Media handling . 8
9 Access control . 9
9.1 Business requirement of access control . 9
9.2 User access management . 9
9.3 User responsibilities . 10
9.4 System and application access control . 10
10 Cryptography . 11
10.1 Cryptographic controls . 11
11 Physical and environmental security . 11
11.1 Secure areas . 11
11.2 Equipment . 12
12 Operations security . 12
12.1 Operational procedures and responsibilities . 12
12.2 Protection from malware . 13
12.3 Backup . 13
12.4 Logging and monitoring . 13
12.5 Control of operational software . 14
12.6 Technical vulnerability management . 14
12.7 Information systems audit considerations . 14
13 Communications security . 15
13.1 Network security management . 15
13.2 Information transfer. 15
14 System acquisition, development and maintenance . 15
14.1 Security requirements of information systems . 15
14.2 Security in development and support processes . 16
Rec. ITU-T X.1058 (03/2017) iii

ISO/IEC 29151:2017(E)
14.3 Test data . 16
15 Supplier relationships . 17
15.1 Information security in supplier relationships . 17
15.2 Supplier service delivery management . 18

