Expert Advice Community

Guest

Benefits from ISO 27018

  Quote
Guest
Guest user Created:   Apr 20, 2017 Last commented:   Apr 20, 2017

Benefits from ISO 27018

Looking for advance to describe the demarcation points between 27001 & 27018
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 20, 2017

To give you some context, my organisation is a SaaS, providing Cloud Products and Services to our customers (who typically use our software).
As an organisation, we utilise Cloud IaaS from some of the Big Vendors. So, we are a SaaS, not actually a Cloud Infrastructure Service provider.

We already understand the benefits of ISO27001, and are leaning towards establishing a program towards compliance. however, given our business profile, do you think it would be a good fit to extend our control environment to include ISO 270018.

Answer: You can think of ISO 27018 the same way as ISO 27002, a set of detailed recommendations on how to implement controls described in ISO 27001 Annex A, the difference being that ISO 27018 focuses on recommendations to protect personally identifiable information (PII) in cloud environments. It can be used both by cloud services providers, which can use the standards recommendations to improve their security controls, and cloud custom ers, that can use the standard to help them verify is potential or current providers have proper controls to protect their PII information.

Considering this, for your second question I can say yes, as a Cloud IaaS customer, your organization can benefit by extending you control environment to include recommendations from ISO 27018 with the purpose to have a better basis to evaluate security controls for PII implemented by your cloud providers.
This article will provide you further explanation about ISO 27018:

- ISO 27001 vs. ISO 27018 – Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 20, 2017

Apr 20, 2017

Suggested Topics