provide compliance basis for personally identifiable information control and reduce security risks
the potential risk of personal data breaches has become a top international issue, with a number of major information security incidents drawing attention to how to protect your personal details. today, more and more personal and consumer-level applications are cloud-based applications. the cloud offers organizations and consumers a number of benefits: cost savings, increased flexibility in mobile access to information. it also raises concerns about data protection and privacy, particularly personally identifiable information (pii), which is defined as any information that can be used to identify the pii subject to which such information relates and which can be directly or indirectly associated with the pii subject.
for users, a cloud service provider (gsp) can provide its users with peace of mind and confidence that its cloud services are reliable, comply with applicable regulatory and contractual requirements, and apply best industry practices , then the cloud service provider will become the best choice for users. under the background of this actual demand, iso/iec 27018 came into being.
iso/iec 27018 is a code of conduct for the protection of personally identifiable information in public cloud services to allow gsps whose infrastructure has been certified to the standard to inform their existing and potential customers that their data is protected and will not be used for unauthorized use for any purpose that they expressly agree to. iso/iec 27018 provides generally accepted control objectives, controls and guidance on implementing measures to protect personally identifiable information (pii), aligning with the privacy principles of iso/iec 29100 and personal data privacy regulations around the world. iso/iec 27018 can ensure that cloud service providers have appropriate procedures for handling pii, and it can also help develop stronger cloud service agreements designed to provide real value and transparency to cloud service customers.
iso/iec 27018 provides additional control over pii in two ways:
1. provide guidance on how to implement specific iso/iec 27001 controls in the context of pii protection;
2. provide control of pii in cloud environment not mentioned in the existing iso/iec 27001.
in addition, iso/iec 27018 establishes clear and transparent parameters for the return, transfer and secure processing of personal information; and requires gsps to disclose the identity of any sub-processors with which they engage in data processing before a customer enters into a contract; if a gsp changes the self-processor , the gsp is required to notify customers in a timely manner, giving them the opportunity to object and terminate their agreement.
iso/iec 27018 applies to any organization, large or small, and it is critical for an organization to demonstrate compliance and show how it protects data, especially data that is not stored in one location.
○ iso/iec 27001-2013 information technology - security technology - information security management system - requirements
○ iso/iec 29100-2018 information technology - security technology - privacy architecture framework
○ iso/iec 27002-2022 information security, cyber-security and privacy protection information security control
○ gb/t 35273-2020 information security technology personal information security specification
improve customer confidence and trust
if a cloud service provider complies with this standard, it means it has a solid understanding of how to handle pii securely and is committed to protecting its customer data, which can help increase customer trust in the business.
reduce customer audits
many customers assign their stewardship to suppliers through frequent audits. iso/iec 27018 is an international standard and provides an independent, third-party evidence that an organization's cloud operations are not only controlled, but controlled in accordance with international best practice benchmarks.
tel: 86-400 821 5138
fax: 86-21 3327 5843
email:noa@noagroup.com