Information security, cybersecurity and privacy protection - Controls and guidance for personally identifiable information protection (ISO/IEC DIS 29151:2024)

ISO/IEC 29151:2017 establishes control objectives, controls and guidelines for implementing controls, to meet the requirements identified by a risk and impact assessment related to the protection of personally identifiable information (PII).
In particular, this Recommendation | International Standard specifies guidelines based on ISO/IEC 27002, taking into consideration the requirements for processing PII that may be applicable within the context of an organization's information security risk environment(s).
ISO/IEC 29151:2017 is applicable to all types and sizes of organizations acting as PII controllers (as defined in ISO/IEC 29100), including public and private companies, government entities and not-for-profit organizations that process PII.

Informationstechnik - Sicherheitsverfahren - Leitfaden für den Schutz personenbezogener Daten (ISO/IEC DIS 29151:2024)

Sécurité de l'information, cybersécurité et protection de la vie privée - Mesures de sécurité et recommandations pour la protection des données à caractère personnel (ISO/IEC DIS 29151:2024)

La présente Recommandation | Norme internationale établit des objectifs de mesure de sécurité, des mesures de sécurité et des lignes directrices pour la mise en œuvre des mesures de sécurité, afin de satisfaire aux exigences identifiées par une appréciation du risque et de l'impact liée à la protection des données à caractère personnel.
En particulier, la présente Recommandation | Norme internationale spécifie des lignes directrices basées sur l'ISO/IEC 27002, en tenant compte des exigences relatives au traitement des DCP qui peuvent être applicables dans le contexte du ou des environnements de risques de sécurité de l'information d'une organisation.
La présente Recommandation | Norme internationale s'applique à tous les types et toutes les tailles d'organisations agissant en tant que responsable de traitement de DCP (tel que défini dans l'ISO/IEC 29100), y compris les entreprises publiques et privées, les entités gouvernementales et les organisations à but non lucratif qui traitent des DCP.

Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Kontrole in smernice obnašanja pri varovanju osebnih podatkov (ISO/IEC DIS 29151:2024)

General Information

Status
Not Published
Publication Date
14-Jul-2026
Current Stage
4060 - Closure of enquiry - Enquiry
Start Date
11-Mar-2025
Due Date
11-Mar-2025
Completion Date
11-Mar-2025

Relations

Buy Standard

Draft
prEN ISO/IEC 29151:2025 - BARVE
English language
54 pages
sale 10% off
Preview
sale 10% off
Preview
e-Library read for
1 day

Standards Content (Sample)


SLOVENSKI STANDARD
01-marec-2025
Informacijska varnost, kibernetska varnost in varstvo zasebnosti - Kontrole in
smernice obnašanja pri varovanju osebnih podatkov
Information security, cybersecurity and privacy protection - Controls and guidance for
personally identifiable information protection (ISO/IEC DIS 29151:2024)
Informationstechnik - Sicherheitsverfahren - Leitfaden für den Schutz
personenbezogener Daten (ISO/IEC DIS 29151:2024)
Sécurité de l'information, cybersécurité et protection de la vie privée - Mesures de
sécurité et recommandations pour la protection des données à caractère personnel
(ISO/IEC DIS 29151:2024)
Ta slovenski standard je istoveten z: prEN ISO/IEC 29151
ICS:
35.030 Informacijska varnost IT Security
2003-01.Slovenski inštitut za standardizacijo. Razmnoževanje celote ali delov tega standarda ni dovoljeno.

DRAFT
International
Standard
ISO/IEC DIS 29151
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection – Controls
Voting begins on:
and guidance for personally
2024-12-17
identifiable information protection
Voting terminates on:
ICS: 35.030
2025-03-11
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENTS AND APPROVAL. IT
IS THEREFORE SUBJECT TO CHANGE
AND MAY NOT BE REFERRED TO AS AN
INTERNATIONAL STANDARD UNTIL
PUBLISHED AS SUCH.
This document is circulated as received from the committee secretariat.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
STANDARDS MAY ON OCCASION HAVE TO
ISO/CEN PARALLEL PROCESSING
BE CONSIDERED IN THE LIGHT OF THEIR
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
NATIONAL REGULATIONS.
RECIPIENTS OF THIS DRAFT ARE INVITED
TO SUBMIT, WITH THEIR COMMENTS,
NOTIFICATION OF ANY RELEVANT PATENT
RIGHTS OF WHICH THEY ARE AWARE AND TO
PROVIDE SUPPORTING DOCUMENTATION.
Reference number
© ISO/IEC 2024
ISO/IEC DIS 29151:2024(en)
DRAFT
ISO/IEC DIS 29151:2024(en)
International
Standard
ISO/IEC DIS 29151
ISO/IEC JTC 1/SC 27
Information security, cybersecurity
Secretariat: DIN
and privacy protection – Controls
Voting begins on:
and guidance for personally
identifiable information protection
Voting terminates on:
ICS: 35.030
THIS DOCUMENT IS A DRAFT CIRCULATED
FOR COMMENTS AND APPROVAL. IT
IS THEREFORE SUBJECT TO CHANGE
AND MAY NOT BE REFERRED TO AS AN
INTERNATIONAL STANDARD UNTIL
PUBLISHED AS SUCH.
This document is circulated as received from the committee secretariat.
IN ADDITION TO THEIR EVALUATION AS
BEING ACCEPTABLE FOR INDUSTRIAL,
© ISO/IEC 2024
TECHNOLOGICAL, COMMERCIAL AND
USER PURPOSES, DRAFT INTERNATIONAL
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
STANDARDS MAY ON OCCASION HAVE TO
ISO/CEN PARALLEL PROCESSING
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
BE CONSIDERED IN THE LIGHT OF THEIR
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
POTENTIAL TO BECOME STANDARDS TO
WHICH REFERENCE MAY BE MADE IN
or ISO’s member body in the country of the requester.
NATIONAL REGULATIONS.
ISO copyright office
RECIPIENTS OF THIS DRAFT ARE INVITED
CP 401 • Ch. de Blandonnet 8
TO SUBMIT, WITH THEIR COMMENTS,
CH-1214 Vernier, Geneva
NOTIFICATION OF ANY RELEVANT PATENT
Phone: +41 22 749 01 11
RIGHTS OF WHICH THEY ARE AWARE AND TO
PROVIDE SUPPORTING DOCUMENTATION.
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland Reference number
© ISO/IEC 2024
ISO/IEC DIS 29151:2024(en)
© ISO/IEC 2024 – All rights reserved
ii
ISO/IEC DIS 29151:2024(en)
Contents Page
Introduction .vi
1 Scope . 1
2 Normative references . 1
3 Terms and Definitions and abbreviated terms . 1
3.1 Definitions .1
3.2 Abbreviated terms .2
4 Overview . 3
4.1 Objective for the protection of PII .3
4.2 Requirement for the protection of PII .3
4.3 Controls .3
4.4 Selecting controls .3
4.5 Developing organization specific guidelines .4
4.6 Life cycle considerations .4
4.7 Structure of this document .4
5 Organizational controls . 8
5.1 Policies for information security . .8
5.2 Information security roles and responsibilities .8
5.3 Segregation of duties.9
5.4 Management responsibilities .9
5.5 Contact with authorities .9
5.6 Contact with special interest groups . .9
5.7 Threat intelligence .9
5.8 Information security in project management .10
5.9 Inventory of information and other associated assets .10
5.10 Acceptable use of information and other associated assets .10
5.11 Return of assets .11
5.12 Classification of information .11
5.13 Labelling of information .11
5.14 Information transfer .11
5.15 Access control .11
5.16 Identity management .11
5.17 Authentication information . 12
5.18 Access rights . 12
5.19 Information security in supplier relationships . 12
5.20 Addressing information security within supplier agreements . 12
5.21 Managing information security in the ICT supply chain . 13
5.22 Monitoring, review and change management of supplier services . 13
5.23 Information security for use of cloud services . 13
5.24 Information security incident management planning and preparation . 13
5.25 Assessment and decision on information security events .14
5.26 Response to information security incidents .14
5.27 Learning from information security incidents .14
5.28 Collection of evidence . . 15
5.29 Information security during disruption . 15
5.30 ICT readiness for business continuity . 15
5.31 Legal, statutory, regulatory and contractual requirements . 15
5.32 Intellectual property rights . 15
5.33 Protection of records . 15
5.34 Privacy and protection of PII . 15
5.35 Independent review of information security . 15
5.36 Conformance with policies, rules and standards for information security .16
5.37 Documented operating procedures .16
6 People controls .16

© ISO/IEC 2024 – All rights reserved
iii
ISO/IEC DIS 29151:2024(en)
6.1 Screening .16
6.2 Terms and conditions of employment .16
6.3 Information security awareness, educati
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.