Today I would like to briefly review the standard ISO/IEC 27018:2019 Information technology Security techniques.
This document establishes generally accepted control objectives, controls and guidelines for implementing measures to protect personally identifiable information (PII) in accordance with the ISO/IEC 29100 privacy principles for public cloud computing environments.
Specifically, this document specifies guidelines based on ISO/IEC 27002, taking into account regulatory requirements for the protection of personally identifiable information that may be applicable in the context of a public cloud service provider’s information security risk environment.
This document is applicable to all types and sizes of organisations, including public and private companies, government agencies and non-profit organisations that provide information processing services as PII processors via cloud computing under contract with other organisations.
The recommendations in this paper may also be relevant to organisations acting as PII controllers. However, PII controllers may be subject to additional PII protection laws, regulations and obligations that do not apply to PII processors.
A summary of the structure and content of the standard can be found here.












