ISO/IEC TR 27563:2023
(Main)Security and privacy in artificial intelligence use cases — Best practices
General Information
- Abstract
This document outlines best practices on assessing security and privacy in artificial intelligence use cases, covering in particular those published in ISO/IEC TR 24030. The following aspects are addressed: — an overall assessment of security and privacy on the AI system of interest; — security and privacy concerns; — security and privacy risks; — security and privacy controls; — security and privacy assurance; and — security and privacy plans. Security and privacy are treated separately as the analysis of security and the analysis of privacy can differ.
- Status
- Published
- Publication Date
- 24-May-2023
- Drafting Committee
- ISO/IEC JTC 1/SC 27/WG 5 - Identity management and privacy technologies
- Current Stage
- 6060 - International Standard published
- Start Date
- 25-May-2023
- Due Date
- 24-Nov-2023
- Completion Date
- 25-May-2023
Overview
ISO/IEC TR 27563:2023 is a technical report published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). The standard focuses on best practices for assessing security and privacy in artificial intelligence (AI) use cases. It is particularly relevant to organizations deploying or evaluating AI systems, as it provides practical frameworks for identifying, analyzing, and mitigating security and privacy risks in AI applications. This document leverages use cases from ISO/IEC TR 24030 and covers critical areas such as risk assessment, controls, assurance, and planning, with dedicated attention to treating security and privacy as distinct analytical domains.
Key Topics
- Overall Assessment: Methods to evaluate the security and privacy of AI systems, tailored to specific use cases.
- Security and Privacy Concerns: Identification of concerns that may arise during the deployment and operation of AI, including potential vulnerabilities unique to AI architectures.
- Risk Identification: Strategies to pinpoint security and privacy risks, drawing from established frameworks like STRIDE for security and LINDDUN for privacy.
- Security and Privacy Controls: Guidance on selecting and implementing technical and organizational measures to mitigate identified risks, referencing standards such as ISO/IEC 27001, ISO/IEC 27701, and ISO/IEC 29151.
- Assurance and Planning: Recommendations on building assurance mechanisms and maintaining robust security and privacy plans, emphasizing regular review and continual improvement.
- Separate Analysis: Emphasizes conducting distinct analyses for security and privacy, recognizing their different nature in the context of AI systems.
Applications
ISO/IEC TR 27563:2023 is applicable to a wide variety of domains where AI is used, including:
- Healthcare: Assessing privacy concerns in patient data used for AI-driven diagnosis or treatment recommendations.
- Finance: Protecting sensitive financial data and ensuring compliance with privacy laws in AI-powered analytics and customer service bots.
- Manufacturing: Securing intellectual property and operational data in smart manufacturing environments powered by AI.
- Transportation: Managing risks around autonomous vehicle data and interactions with external networks.
- Public Services: Safeguarding citizen data in AI-based government services and surveillance systems.
By applying the best practices outlined in ISO/IEC TR 27563:2023, organizations can:
- Conduct comprehensive security and privacy assessments of their AI systems.
- Develop structured plans for risk mitigation, monitoring, and continual improvement.
- Align with international compliance requirements and boost stakeholder trust by demonstrating responsible AI implementation.
- Utilize templates and frameworks designed for documenting the ecosystem, identifying key stakeholders, and mapping asset impacts.
Related Standards
ISO/IEC TR 27563:2023 operates within a broader framework of international AI, security, and privacy standards, including:
- ISO/IEC TR 24030: A reference for AI use cases, providing the foundational scenarios analyzed in this report.
- ISO/IEC TR 24028: Addresses trustworthiness in AI, including transparency, explainability, and controllability considerations.
- ISO/IEC 27001 & ISO/IEC 27002: Standards for information security management systems and controls.
- ISO/IEC 27701: Guidance for privacy information management and requirements for Personally Identifiable Information (PII) controllers and processors.
- ISO/IEC 29100: Privacy framework and principles applicable to PII.
- ISO/IEC 29134: Privacy impact assessment methodology.
Organizations implementing AI solutions should consider these related standards for a comprehensive approach to AI security and privacy that meets international best practices and fosters trustworthy AI adoption.
Get Certified
Connect with accredited certification bodies for this standard

BSI Group
BSI (British Standards Institution) is the business standards company that helps organizations make excellence a habit.

NYCE
Mexican standards and certification body.
Sponsored listings
Frequently Asked Questions
ISO/IEC TR 27563:2023 is a technical report published by the International Organization for Standardization (ISO). Its full title is "Security and privacy in artificial intelligence use cases — Best practices". This standard covers: This document outlines best practices on assessing security and privacy in artificial intelligence use cases, covering in particular those published in ISO/IEC TR 24030. The following aspects are addressed: — an overall assessment of security and privacy on the AI system of interest; — security and privacy concerns; — security and privacy risks; — security and privacy controls; — security and privacy assurance; and — security and privacy plans. Security and privacy are treated separately as the analysis of security and the analysis of privacy can differ.
This document outlines best practices on assessing security and privacy in artificial intelligence use cases, covering in particular those published in ISO/IEC TR 24030. The following aspects are addressed: — an overall assessment of security and privacy on the AI system of interest; — security and privacy concerns; — security and privacy risks; — security and privacy controls; — security and privacy assurance; and — security and privacy plans. Security and privacy are treated separately as the analysis of security and the analysis of privacy can differ.
ISO/IEC TR 27563:2023 is classified under the following ICS (International Classification for Standards) categories: 35.020 - Information technology (IT) in general. The ICS classification helps identify the subject area and facilitates finding related standards.
ISO/IEC TR 27563:2023 is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.
Standards Content (Sample)
TECHNICAL ISO/IEC TR
REPORT 27563
First edition
2023-05
Security and privacy in artificial
intelligence use cases — Best practices
Sécurité et respect de la vie privée dans les cas d’usage de
l’intelligence artificielle — Bonnes pratiques
Reference number
© ISO/IEC 2023
© ISO/IEC 2023
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii
© ISO/IEC 2023 – All rights reserved
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 2
5 Analysis of security and privacy .3
5.1 General . 3
5.2 Application domains in ISO/IEC TR 24030:2021 use cases . 3
5.3 Security in ISO/IEC TR 24030:2021 use cases . 3
5.4 Privacy in ISO/IEC TR 24030:2021 use cases . 4
6 Templates for analysis .5
7 Supporting information . 6
7.1 Describe ecosystem. 6
7.2 Provide assessment of systems of interest . 7
7.3 Identify security and privacy concerns . 7
7.4 Identify security and privacy risks . 9
7.5 Identify security and privacy controls . 11
7.6 Identify security and privacy assurance concerns . 15
7.7 Identify security and privacy plan requirements . 16
Annex A (informative) Additional use cases .18
Bibliography .28
iii
© ISO/IEC 2023 – All rights reserved
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work.
The procedures used to develop this document and those intended for its further maintenance
are described in the ISO/IEC Directives, Part 1. In particular, the different approval criteria
needed for the different types of document should be noted. This document was drafted in
accordance with the editorial rules of the ISO/IEC Directives, Part 2 (see www.iso.org/directives or
www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of
any claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC
had not received notice of (a) patent(s) which may be required to implement this document. However,
implementers are cautioned that this may not represent the latest information, which may be obtained
from the patent database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall
not be held responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to
the World Trade Organization (WTO) principles in the Technical Barriers to Trade (TBT) see
www.iso.org/iso/foreword.html. In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 27, Information technology, cyber security and privacy protection.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.
iv
© ISO/IEC 2023 – All rights reserved
Introduction
Artificial intelligence (AI) and machine learning (ML) are increasingly being adopted by the digital
industry, using algorithms to make decisions that have the potential to negatively impact the privacy
of individuals and in some cases can even cause harm to some of them, unless adequate safeguards are
deployed. Such safeguards to protect privacy often depend on a variety of factors including the specific
type of process, sensitivity of data used, and potential harm likely to be caused.
This concern has been expressed by:
[1]
— Practitioners, who identified 23 principles for AI at the 2017 Asilomar conference covering
research, ethics and values, as well as longer term issues.
— Standard developers, as evidenced by the report on ethically aligned design published by the IEEE
[2]
Global Initiative on Ethics of Autonomous and Intelligent Systems .
— Policy makers, as exemplified by the appointment by the European Commission of a high-level
[3]
expert group on artificial intelligence and the subsequent publication of an assessment list .
This document provides an analysis of security and privacy of use cases provided in ISO/IEC TR 24030,
which should be used in parallel. A number of additional use cases are provided in Annex A.
This document also uses concepts from ISO/IEC TR 24028, which addresses trustworthiness in AI
systems, including approaches to establish trust (e.g. transparency, explainability, controllability), and
to achieve trustworthiness properties (e.g. resiliency, reliability, accuracy, safety, security, or privacy).
v
© ISO/IEC 2023 – All rights reserved
TECHNICAL REPORT ISO/IEC TR 27563:2023(E)
Security and privacy in artificial intelligence use cases —
Best practices
1 Scope
This document outlines best practices on assessing security and privacy in artificial intelligence use
cases, covering in particular those published in ISO/IEC TR 24030.
The following aspects are addressed:
— an overall assessment of security and privacy on the AI system of interest;
— security and privacy concerns;
— security and privacy risks;
— security and privacy controls;
— security and privacy assurance; and
— security and privacy plans.
Security and privacy are treated separately as the analysis of security and the analysis of privacy can
differ.
2 Normative references
There are no normative references in this document.
3 Terms and definitions
For the purposes of this document, the following terms and definitions apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp
— IEC Electropedia: available at https:// www .electropedia .org/
3.1
personally identifiable information
PII
information that (a) can be used to establish a link between the information and the natural person to
whom such information relates, or (b) is or can be directly or indirectly linked to a natural person
Note 1 to entry: The “natural person” in the definition is the PII principal (3.3). To determine whether a PII
principal is identifiable, account should be taken of all the means which can reasonably be used by the privacy
stakeholder holding the data, or by any other party, to establish the link between the set of PII and the natural
person.
[SOURCE: ISO/IEC 29100:2011/Amd.1:2018, 2.9]
© ISO/IEC 2023 – All rights reserved
3.2
PII controller
privacy stakeholder (or privacy stakeholders) that determines the purposes and means for processing
personally identifiable information (PII) (3.1) other than natural persons who use data for personal
purposes
Note 1 to entry: A PII controller sometimes instructs others [e.g. PII processors (3.4)] to process PII on its behalf
while the responsibility for the processing remains with the PII controller.
[SOURCE: ISO/IEC 29100:2011, 2.10]
3.3
PII principal
natural person to whom the personally identifiable information (PII) (3.1) relates
Note 1 to entry: Depending on the jurisdiction and the particular data protection and privacy legislation, the
synonym “data subject” can also be used instead of the term “PII principal”.
[SOURCE: ISO/IEC 29100:2011, 2.11]
3.4
PII processor
privacy stakeholder that processes personally identifiable information (PII) (3.1) on behalf of and in
accordance with the instructions of a PII controller (3.2)
[SOURCE: ISO/IEC 29100:2011, 2.12]
4 Abbreviated terms
CCTV closed-circuit television
GDPR General Data Protection Regulation
HCI human computing interaction
LINDDUN linkability, identifiability, non-repudiation, detectability, disclosure of information, un-
awareness, non-compliance
NIST national institute of standards and technology
OEM original equipment manufacturer
PIA privacy impact assessment
PII personally identifiable information
PoC proof of concept
SDG sustainable development goals
STRIDE spoofing identity, tampering, repudiation, information disclosure, denial of service, ele-
vation of privilege
UC use case
V2X vehicle-to-everything
© ISO/IEC 2023 – All rights reserved
5 Analysis of security and privacy
5.1 General
This document includes a security and privacy analysis of ISO/IEC TR 24030:2021 use cases. Two
electronic attachments were used:
— the first is the material used by ISO/IEC TR 24030:2021, available here: https:// standards .iso .org/
iso -iec/ tr/ 24030/ ed -1/ en/ Use+ cases -v05 _electronic _attachment _022021 .pdf,
— the second is the material used by this document, available here: https:// standards .iso .org/ iso -iec/
tr/ 27563/ ed -1/ en/ Security -privacy -24030 -ed -1 -AI -use -cases .pdf.
Annex A provides a list of new use cases.
5.2 Application domains in ISO/IEC TR 24030:2021 use cases
ISO/IEC TR 24030:2021 describes 132 use cases, belonging to 22 application domains as shown in
Figure 1.
NOTE 1 134 use cases are listed in this document, as use case 96 from ISO/IEC TR 24030 has been categorized
into 3 application domains.
NOTE 2 The number of use cases per domain, e.g. 1 energy use case compared to 29 healthcare use cases is not
an indication of the potential deployment of AI capabilities in a domain.
NOTE 3 The assignment of a use case to a domain depends on the viewpoint of experts. For instance, use case
132 (Device control using both cloud AI and embedded AI) is classified as manufacturing instead of home.
Figure 1 — Distribution of use cases by application domains
5.3 Security in ISO/IEC TR 24030:2021 use cases
Figure 2 summarizes the security analysis of ISO/IEC TR 24030 use cases in the second electronic
attachment. It shows for each application domain:
— the number of use cases for which security concerns can be negligible;
— the number of use cases for which security concerns can be limited;
— the number of use cases for which security concerns can be significant; and
© ISO/IEC 2023 – All rights reserved
— the number of use cases for which security concerns can be maximum.
NOTE 1 The assessment is based on the most critical systems of interest. For instance, use case 1 (Explainable
artificial intelligence for genomic medicine) involves two systems of interest, the genomic sequence processing
system for which security concerns can be maximum, and the genomic training system for which system
concerns can be significant. The resulting assessment is that security concerns can be maximum.
NOTE 2 The assessment result of each domain is not an indication of the potential privacy concern of AI in a
domain.
Figure 2 — Security analysis in AI use cases
5.4 Privacy in ISO/IEC TR 24030:2021 use cases
Figure 3 summarizes the privacy analysis of ISO/IEC TR 24030 use cases listed in the attachment. It
shows for each application domain:
— the number of use cases for which privacy concerns can be negligible;
— the number of use cases for which privacy concerns can be limited;
— the number of use cases for which privacy concerns can be significant;
— the number of use cases for which privacy concerns can be maximum.
NOTE 1 The assessment is based on the most critical systems of interest. For instance, use case 1 (Explainable
artificial intelligence for genomic Medicine) involves two systems of interest, the genomic sequence processing
system for which privacy concerns can be maximum, and the genomic training system for which system concerns
can be negligible. The resulting assessment is that privacy concerns can be maximum.
NOTE 2 The assessment result of each domain is not an indication of the potential privacy concern of AI in a
domain.
© ISO/IEC 2023 – All rights reserved
Figure 3 — Privacy analysis in use cases
6 Templates for analysis
The template used to collect material is shown in Table 1. It includes three types of table cells:
— title cell (e.g. use case name);
— instruction cell (e.g. describe the ecosystem);
— example cell (e.g. System of interest: < use case system of interest > ).
Example cells can include texts in brackets, e.g. < asset A > . They are intended to be replaced by a
specific text related to the use case.
NOTE 1 The proposed texts in example cells use vocabularies and concepts which are aligned with existing
security and privacy references (See [7][8][9][10][13][16][17][18][19][24][15][14]).
NOTE 2 A use case can involve several systems of interest.
© ISO/IEC 2023 – All rights reserved
Table 1 — Template for collecting material
ID < identification as provided by ISO/IEC TR 24030 >
Use case name < use case name as provided by ISO/IEC TR 24030 >
Systems of interest:
— < use case system of interest >
Describes the ecosystem: identi-
fies the systems of interest, the
Stakeholders:
Ecosystem stakeholders, and the stakehold-
— < stakeholder A >
ers’ assets that are impacted by
AI Stakeholder assets that are impacted by AI
— < asset A >
System of interest: < Use case system of interest >
— Security and privacy concerns on < use case
Assessment of system Assessment on security and pri-
system of interest > are < negligible, limited,
of interest vacy concerns
significant, maximum >
— Protection goals to consider for < asset A > asset
are < confidentiality, integrity, availability,
[8]
unlinkability, transparency, intervenability >
— The following privacy principles to consider
for a < use case system of interest > integrating
Security and privacy Highlights security and privacy
a < asset A > asset: < e.g. consent and choice, use
concerns concerns that are impacted by AI
[9]
retention and disclosure limitation >
— The following framework concepts to consider
for a < use case system of interest > integrating
a < asset A > asset: < e.g. Identify, Protect,
[21][15]
Identify-P, Govern-P >
— Privacy risks related to < asset A > asset (e.g. re-
identification of … while performing AI training
and reasoning operations)
Security and privacy Identifies security and privacy
— Security risks related to < asset A > asset
risks risks that are impacted by AI
(e.g. alteration of learning data with wrong
information, security of training operation,
security of reasoning operation, …)
— Security and privacy controls from < reference
Security and privacy Identifies security and privacy
(see [22][23][24][17][7]) > to be considered
controls controls that are impacted by AI
for < use case system of interest >
— Organization operating the < use case system
Identifies security and privacy
Security and privacy of interest > integrating < asset A > asset
assurance aspects that are im-
[19][20]
assurance to ensure that it can be audited This
pacted by AI
includes organisational and technical evidence.
— Organization operating the < use case system
Identifies security and privacy of interest > integrating < asset A > asset to
Security and privacy
[16]
plan aspects that are impacted establish a security and privacy plan that
plan
by AI will be validated and reviewed periodically for
continual improvement.
7 Supporting information
7.1 Describe ecosystem
The type of stakeholders and system of interest that can be considered are shown in Table 2.
© ISO/IEC 2023 – All rights reserved
Table 2 — Points of attention on ecosystem
Points of attention Description
Supplier (including solution providers and technology providers)
Entity that does not process PII at all
PII controller
Type of stakeholders
PII processor
PII principals
Third parties
AI system of interest (e.g. a reasoning engine)
Type of system of interest
System of interest that includes an asset to protect and uses an AI subsys-
tem
7.2 Provide assessment of systems of interest
The qualifiers that can be used are “can be negligible”, “can be limited”, “can be significant”, “can be
maximum”.
Note It is possible that concerns on security and privacy are not the same.
7.3 Identify security and privacy concerns
For each system of interest, the points of attention are shown in Table 3, Table 4, Table 5, and Table 6.
NOTE 1 Table 3 is based on based on ISO/IEC TR 27550.
NOTE 2 Table 4 is based on ISO/IEC 29100.
[15]
NOTE 3 Table 5 is based on ISO/IEC TS 27110 and the NIST privacy framework .
Table 3 — Points of attention on protection goals
Points of attention Description
Property that information is not made available or disclosed to unauthorized
Confidentiality
Security
individuals, entities, or processes
protection
Integrity Property of accuracy and completeness
goals
Availability Property of being accessible and usable upon demand by an authorized entity
Property that a PII principal can make multiple uses of resources or services
Unlinkability
without others being able to link these uses together
Privacy
Property that all privacy-relevant data processing including the legal, technical
protection Transparency
and organizational settings can be understood and reconstructed
goals
Property that PII principals, PII controllers, PII processors and supervisory
Intervenability
authorities can intervene in all privacy-relevant data processing
Table 4 — Points of attention on privacy principles
Points of attention Description
Provisions which are made to provide PII principals with the opportu-
Consent and choice nity to choose how their PII is handled and to allow a PII principal to
withdraw consent easily and free of charge
Communicating the purpose and awareness that it is expected to com-
Purpose legitimacy and specification
ply with applicable law and rely on a permissible legal basis
Limiting the collection of PII to that which is within the bounds of appli-
Collection limitation
cable law and strictly necessary for the specified purpose(s)
© ISO/IEC 2023 – All rights reserved
TTaabblle 4 e 4 ((ccoonnttiinnueuedd))
Points of attention Description
Minimize the PII which is processed and the number of privacy stake-
Data minimization
holders and people to whom PII is disclosed or who have access to it
Limiting the use, retention and disclosure (including transfer) of PII to
Use, retention and disclosure limita-
that which is necessary in order to fulfil specific, explicit and legitimate
tion
purposes
Ensuring that the PII processed is accurate, complete, up-to-date (un-
Accuracy and quality less there is a legitimate basis for keeping outdated data), adequate and
relevant for the purpose of use
Providing PII principals with clear and easily accessible information
Openness, transparency and notice about the PII controller’s policies, procedures and practices with re-
spect to the processing of PII
Giving PII principals the ability to access and review their PII, provided
Individual participation and access their identity is first authenticated with an appropriate level of assur-
ance and such access is not prohibited by applicable law
Documenting and communicating as appropriate all privacy-related
policies, procedures and practices. Assigning to a specified individual
Accountability within the organization (who can in turn delegate to others in the or-
ganization as appropriate) the task of implementing the privacy-related
policies, procedures and practices
Protecting PII under its authority with appropriate controls at the oper-
ational, functional and strategic level to ensure the integrity, confiden-
Information security tiality and availability of the PII, and to protect it against risks such as
unauthorized access, destruction, use, modification, disclosure or loss
throughout the whole of its life cycle
Verifying and demonstrating that the processing meets data protection
Privacy compliance and privacy safeguarding requirements by periodically conducting
audits using internal auditors or trusted third-party auditors
Table 5 — Points of attention on activities
Points of attention Description
Identify Ecosystems of stakeholders and threat environment
Protect Safeguards
Security Detect Discover cybersecurity events
Respond Response to cybersecurity events
Recover Restoration and communication after a cybersecurity event
Organizational understanding to manage privacy risk for individuals aris-
Identify-P
ing from data processing
Govern-P Governance controls for privacy
Develop and implement appropriate activities to enable organizations or
Privacy Control-P individuals to manage data with sufficient granularity to manage privacy
risks
Communication capabilities so that organizations and individuals have an
Communicate-P
understanding on how data are processed
Protect-P Data protection safeguards
Table 6 lists points of attention on integration of security and privacy in an ecosystem.
NOTE 4 Table 6 is based on Annex B of ISO/IEC TS 27110.
© ISO/IEC 2023 – All rights reserved
Table 6 — Points of attention on integration
Points of atten- Example of activities Example of input Example of output
tion
Specify how the cybersecurity
Work product specifying the
Interview with domain
framework activities fit with
correspondence between the
architecture experts
Reference archi- the reference architecture used
cybersecurity framework and
tectures in the business environment
Reference architecture
the ecosystem reference archi-
and its ecosystem of internal
documents
tecture
and external stakeholders
Interview with domain
Specify the mapping between Work product specifying the
experts
roles and stakeholders in the correspondence between the
Roles and stake-
domain ecosystem and the cybersecurity framework and
List of domain use cases
holders
cybersecurity framework the roles and stakeholders in the
describing roles and
activities domain ecosystem
stakeholders
Work product specifying the
Interview with domain se-
Specify the relationship with correspondence between the
curity and privacy experts
Security and pri-
the security and privacy prac- cybersecurity framework and
vacy practices
Reference security and
tices in the domain ecosystem security and privacy practices in
privacy documents
the domain ecosystem
Work product specifying the
Interview with system life
Identify how the system life correspondence between the
cycle experts
System life cycle
cycle processes integrate the cybersecurity framework and
processes
Reference system life
cybersecurity framework the system life cycle processes
cycle documents
of the domain ecosystem
Table 7 lists points of attention on AI specific security and privacy vulnerabilities.
NOTE 5 Table 7 is based on ISO/IEC TR 24028.
Table 7 — Points of attention on AI trustworthiness vulnerabilities
Points of
Vulnerability Example of threats
attention
Influencing training data to manipulate the results of a predic-
Data poisoning
tive model
Adversarial attacks Provide perturbed input data to a valid model
AI specific
Send to targeted model a high number of prediction queries
security
Model stealing and use response received (the prediction) to train another
threats
model
Affect confidentiality of data
Hardware-focused threats to
confidentiality and integrity
Affect integrity of data and computation
Not following principle of PII minimization
Upon data acquisition
Compromising data storage
AI specif- Upon data pre-processing and Using AI to infer PII from data
ic privacy modelling
Using AI to re-identify information using multiple data sourc-
threats
es
Upon model query Using model for non-authorized purpose (e.g. social service
screening, credit card scoring)
7.4 Identify security and privacy risks
For each system of interest, security and privacy risks can be identified, and resulting consequences
identified. See ISO/IEC 27005 for security and ISO/IEC 29134 for privacy.
The upper part of Figure 4 shows the relationships between security and privacy risks.
© ISO/IEC 2023 – All rights reserved
SOURCE NIST[15], reproduced with the permission of the authors.
Figure 4 — Security and privacy risks, and related functions
Table 8 and Table 9 show examples of categories of threats that can be used.
NOTE These categories of threats are based on the STRIDE and LINDDUN taxonomy.
Table 8 — Points of attention on threats
Points of attention Description
The identity of the users is established (or anonymous entities are accept-
Spoofing
ed)
Data and system resources are only changed in appropriate ways by ap-
Security Tampering
propriate people
threat
Repudiation Users cannot perform an action and later deny performing it
STRIDE
taxonomy
Information disclosure Data are only available to the users intended to access it
Denial of Service Systems are ready upon request and perform acceptably
Elevation of privilege Users are explicitly allowed or denied access to resources
© ISO/IEC 2023 – All rights reserved
TTaabblle 8 e 8 ((ccoonnttiinnueuedd))
Points of attention Description
Establishing the link between two or more actions, identities, and pieces
Linkability
of information
Establishing the link between an identity and an action or a piece of infor-
Identifiability
mation
Inability to deny having performed an action that other parties can nei-
Non-repudiation
ther confirm nor contradict
Detectability Detecting the PII principal’s activities
Privacy
threat
Disclosure of informa-
Disclosing the data content or controlled release of data content
LINDDUN
tion
taxonomy
PII principals being unaware of what PII about them is being processed
Unawareness by PII Controllers of life cycle weaknesses that can exist/
Unawareness
develop due to greater awareness of the content of the training model or
other ML techniques
PII controller fails to inform the data subject about the system’s privacy
Non-compliance policy, or does not allow the PII principal to specify consents in compli-
ance with legislation
The following categories of issues related to privacy consequences in Table 9 can be used.
Table 9 — Points of attention on issues related to privacy consequences
Points of attention Description
Unfair, discriminatory or biased outcome that would largely affect the PII prin-
Discrimination
cipals in any given situations through the processed data about them
Automatically identify and eventually track PII principals and their activities
Unsolicited Tracking
without their consent and/or knowledge
Failure to act with prudence of PII processors and PII controllers on protecting
Negligence
the information even with knowing the risks represented by the processing
Inability to inform or be transparent to PII principals regarding how their PII
Lack of transparency
are processed or handled and its purpose
Amount of PII collected by the system is not proportional to its processing
Lack of proportionality
purpose
Integration of numerous systems and databases which can affect the anonymi-
Loss of Anonymity
ty of PII principals
7.5 Identify security and privacy controls
For each system of interest, security and privacy controls can be identified.
[15]
Table 5, based on ISO/IEC TS 27110 and the NIST privacy framework can be used to guide the
identification. The lower part of Figure 4 shows examples of functions that can be used to identify
controls.
Table 10 lists control categories as proposed by ISO/IEC 27001, ISO/IEC 27701 and ISO/IEC 29151 for
information security. Table 11 lists control categories as proposed by ISO/IEC 27002.
NOTE Table 10 is based on ISO/IEC 27001:2013, Annex A.
© ISO/IEC 2023 – All rights reserved
Table 10 — Control categories for information security
Category Sub-categories
Information security policies Management direction
Internal organization
Organization of information
security
Mobile devices and teleworking
Prior to employment
Human resource security During employment
Termination and change of employment
Responsibility for assets
Asset management
Information classification
Business requirements for access control
User access management
Access control User responsibilities
System and application access control
Media
Cryptography Cryptographic controls
Secure areas
Physical and environmental
security
Equipment
Operational procedures and responsibilities
Protection from malware
Backup
Operation security Logging and monitoring
Control of operational software
Technical vulnerability management
Information systems audit considerations
Network security management
Communication security
Information transfer
Security requirements of information system
System acquisition, develop-
Security in development and support processes
ment and maintenance
Test data
Information security in supplier relationships
Suppliers relationships
Supplier service delivery management
Information security incident
Management of information security incidents and improvements
management
Information security aspects Information security continuity
of business continuity man-
Redundancies
agement
Compliance with legal and contractual requirements
Compliance
Information security reviews
© ISO/IEC 2023 – All rights reserved
Table 11 — Control categories for information security based on ISO/IEC 27002
Category themes Controls
Organizational controls Policies for information security
Screening
Terms and conditions of employment
Information security awareness education and training
Disciplinary process
People controls
Responsibilities after termination or change of employment
Confidentiality of non-disclosure agreements
Remote working
Information security event reporting
Physical security perimeters
Physical entry
Securing offices, rooms and facilities
Physical security monitoring
Protecting against physical and environmental threats
Working in secure areas
Clear desk and clear screen
Physical controls
Equipment siting and protection
Security of assets off-premises
Storage media
Supporting utilities
Cabling security
Equipment maintenance
Secure disposal or re-use of equipment
User end point devices
Privileged access rights
Information access restriction
Access to source code
Secure authentication
Capacity management
Protection against malware
Management of technical vulnerabilities
Technological controls Configuration management
Information deletion
Data masking
Data leakage prevention
Information backup
Redundancy of information processing facilities
Logging
Monitoring activities
Clock synchronization
Use of privileged utility programs
Installation of software on operational systems
© ISO/IEC 2023 – All rights reserved
TTaabblle 1e 11 1 ((ccoonnttiinnueuedd))
Category themes Controls
Networks security
Security of network services
Segregation of networks
Web filtering
Use of cryptography
Secure development life cycle
Application security requirements
Secure system architecture and engineering principle
Secure coding
Secure testing in development and acceptance
Outsourced development
Separation of development, test and production environments
Change management
Test information
Protection of information systems during audit testing
Table 12 lists control categories as proposed by ISO/IEC 27701 for PII controllers.
Table 12 — Additional supporting information for PII controllers (for information systems)
Category Supporting information
Identify and document purpose
Identify lawful basis
Determine when and how consent is to be obtained
Conditions for
collection and Obtain and record consent
processing
Privacy impact assessment
Joint PII controller
Records related to processing PII
Determining and fulfilling obligations to PII principals
Determining information for PII principals
Providing information to PII principals
Providing mechanism to modify or withdraw consent
Obligations to
Providing mechanism to object to PII processing
PII principals
Access, correction and/or erasure
PII controllers’ obligation to inform third parties
Handling requests
Automated decision making
© ISO/IEC 2023 – All rights reserved
TTaabblle 1e 12 2 ((ccoonnttiinnueuedd))
Category Supporting information
Limit collection
Limit processing
Accuracy and quality
PII minimization objectives
Privacy by de-
sign and privacy PII de-identification and deletion at the end of processing
by default
Temporary files
Retention
Disposal
PII transmission controls
Identify basis for PII transfer between jurisdictions
PII sharing,
Countries and international organizations to which PII can be transferred
transfer and
Records of transfer of PII
disclosure
Records of PII disclosure to third parties
Table 13 below lists control categories as proposed by ISO/IEC 27701 for PII processors.
Table 13 — Additional supporting information for PII processors (for information systems)
Category Supporting information
Customer agreement
Organization’s purposes
Marketing and advertising use
Conditions for collection and
processing
Infringing instruction
Customer obligations
Records related to processing PII
Obligations to PII principals Obligations to PII principals
Temporary files
Privacy by design and privacy
Return, transfer or disposal of PII
by default
PII transmission controls
Basis for PII transfer between jurisdictions
Countries and international organizations to which PII can be transferred
Records of PII disclosure to third parties
Notification of PII disclosure requests
PII sharing, transfer and disclo-
sure
Legally binding PII disclosures
Disclosure of subcontractors used to process PII
Engagement of a subcontractor to process PII
Change of subcontractor to process PII
7.6 Identify security and privacy assurance concerns
For each system of interest, security and privacy assurance points of attention can be identified.
Examples are shown in Table 14.
© ISO/IEC 2023 – All rights reserved
Table 14 — Points of attention on assurance
Points of atten-
Comment
tion
Assurance focuses on verifying that requirements concerning security privacy for AI system
are met. Evidence are defined for each requirement
Evidence for
EXAMPLE 1 A design report explains how explainability is done
security and pri-
vacy assurance
EXAMPLE 2 The AI system has an HCI for explainability
EXAMPLE 3 A privacy impact assessment report is provided
Organisational evidence
Organizational
EXAMPLE 4 A periodic review of risks is made
and technical
Technical evidence
evidence
EXAMPLE 5 Demonstrating that a specific de-identification mechanism is used
Audits can focus on system assurance or on process assurance
EXAMPLE 6 A system assurance can be the security and privacy certification of a Ma-
Assurance
chine learning (ML) capability
approach and
metrics for as-
EXAMPLE 7 A process assurance can be the audit that an AI system life cycle process is
surance
at a given integrity level
NOTE Ecosystem assurance can depend on the underlying governance approach
To be effective assurance is based on the requirements
Competence and
ecosystem for EXAMPLE 8 ISO/IEC 27001 is supported by ISO/IEC 27006
assurance
EXAMPLE 9 ISO/IEC 27701 and ISO/IEC 27002 is supported by ISO/IEC TS 27006-2
7.7 Identify security and privacy plan requirements
For each system of interest, points of attention on security and privacy plan can be identified. Examples
are shown in Table 15 and Table 16.
NOTE Table 5 is based on ISO/IEC TS 27570.
Table 15 — Points of attention on security and privacy ecosystem plan
Points of at-
Comment
tention
The governance process focuses on the establishment of security and privacy policies, and the
Governance continuous monitoring of their proper implementation in the ecosystem. These activities are
process carried out by the governing bodies of the ecosystem, as well as by the organizations in the
ecosystem which implement the security and privacy policies.
The data management process focuses on the management of security and privacy in the cre-
Data manage- ating, capturing, collecting, transforming, publishing, accessing, transferring, and archiving
ment process of data within an ecosystem. These activities are carried out by the governing bodies of an
ecosystem, as well as by the organizations in the ecosystem.
The risk management process deals with the analysis and the treatment of security and
Risk manage-
privacy risks in an ecosystem. The activities are carried out by the governing bodies of the
ment process
ecosystem, as well as by the organizations in the ecosystem.
The engineering process is a set of activities related to the life cycle of a service in an ecosys-
tem. These activities are carried out by the governing bodies of the ecosystem, as well as by
the organizations in the ecosystem concerned with the delivery, and the use of the availability
Engineering
of the ecosystem service.
process
It elaborates the conceptual principles such as privacy by design and privacy by default and
other important design goals in applicable jurisdictions. It also considers the requirements
specified in ISO/IEC TR 27550.
© ISO/IEC 2023 – All rights reserved
TTaabblle 1e 15 5 ((ccoonnttiinnueuedd))
Points of at-
Comment
tention
The citizen engagement process focuses on consultation with citizens on security and privacy
Citizen engage-
rules and policies at governance level, and on the support on the enforcement of these rules
ment process
and policies concerning the security and privacy of an ecosystem service.
Table 16 — Points of attention on security and privacy plan
Points of at-
Comment
tention
There are specific responsibilities that are associated with the certain stakeholders (e.g. PII
controllers, PII processors). It is important to have a continuous assessment of whether a
stakeholder is changing its role. For instance, it is possible that an operator of an AI system
deployed it with the understanding that no PII is collected, but further operations can lead to
a status where the AI system is collecting PII.
Continuous
determination
Here are examples of factors that can lead to this situation:
of roles
— Governance capabilities (the AI system dynamically decides to collect some type of data),
— Re-identified data (some data that is initially categorized at non-PII is now a PII)
— Error in data sharing agreements.
Virtually all use cases of ISO/IEC TR 24030 are part of an ecosystem. Organizational meas-
Organizational
ures are implemented when there it is expected that stakeholders to synchronise their
measures in the
actions. For instance, when data sets include privacy leaks, all the stakeholders using the data
ecosystem
sets can be informed and take appropriate actions.
Organizations (both processors and controllers) demonstrate accountability and responsi-
Accountability bility when processing personal information e.g. by having a data protection officer or data
prote
...



