ISO 27701 and Conformance with Privacy Information Management (Part 3)

Continuum GRC ITAM software interface streamlining proactive ISO 27701 audit processes by Lazarus Alliance.

We’ve previously discussed ISO 27701 and how it refines two essential security standards and control libraries (ISO 27001 and ISO 27002). But, the entire purpose of ISO 27701 is to align IT systems with privacy requirements found under GDPR. 

Here, we’ll discuss the third section of this document that defines additional guidelines for organizations acting as data controllers in the EU.

 

Read More

ISO 27701 and Conformance with Privacy Information Management (Part 1)

Consultant presenting ISO 27701 audit findings to enhance data privacy compliance.

Private security standards like those from the International Organization for Standardization (ISO) generally seek some alignment with major regulations so that certified organizations can effectively adapt to new and rigorous standards. Accordingly, the ISO 27701 standard seeks to refine the standard ISO cybersecurity certifications to match evolving security laws in jurisdictions like the EU. 

In this article, the first of three parts, we will look at ISO 27701, how it impacts ISO 27001 controls, and how certified organizations will deploy their Information Security Management Systems.

 

Read More

What Is ISO 27018 and How Does it Apply to Cloud Providers?

Lazarus Alliance Cybervisor team evaluating ISO/IEC 27018 data protection standards.

ISO/IEC 27018 establishes commonly accepted control objectives to protect Personally Identifiable Information (PII) in line with the privacy principles in ISO/IEC 29100 for cloud providers offering public infrastructure and services. It is a critical document for these providers seeking to instill the trustworthiness of their systems in their customers and clients. Learn more about ISO 27018 and what it takes to get your cloud infrastructure up to speed.

 

Read More