What is ISO/IEC 27701:2019 Privacy Information Management Systems (PIMS)
ISO/IEC 27701 includes additional requirements or/and controls to establish, implement, maintain, and improve Privacy Information Management Systems (PIMS) to highlight the importance of Information Security Management Systems (ISMS). The organization must be ISO/IEC 27001 certified, to be qualified for ISO/IEC 27701 Certification.
PIMS framework is developed to protect the privacy rights of individuals (Personally Identifiable Information). The framework is intended for companies controlling PII (PII Controllers) as well as companies processing PII (PII Processors).
Benefits of ISO/IEC 27701 Certification to your organization and your customers:
Here are a few of the numerous benefits of PIMS to PII Controllers and PII Processors:
Following are few of the benefits
The privacy regulatory environment can be bulky for an organization operating under more than one privacy jurisdictions. Different states and countries have their own privacy laws. It gets even complicated when the customers (data subjects) of an organization live in multiple jurisdictions. A standardized PIMS framework streamlines this compliance across jurisdictions.
A certified PIMS environment gives peace of mind to all stakeholders (shareholders, regulators, customers, etc.) as necessary processes and controls are in place to protect PII.
A PIMS certification is based on an international standard (including covering for GDPR, CCPA, and several other Privacy regulations). Hence, it is the witness to all concerned parties that the company complies with all privacy laws and regulations.
An ISO/IEC 27701 PIMS certification also provides assurance to your consumers (customers) that it is safe to do business with, as the company has all essential protections to safeguard their personally identifiable information (PII).
ISO/IEC 27701: Structure of the Standard
The requirements of the standard are split into the four groups as below:
Clause 5: PIMS requirements related to ISO/IEC 27001
Clause 6: PIMS requirements related to ISO/IEC 27002
Clause 7: PIMS guidance for PII Controllers
Clause 8: PIMS guidance for PII Processors
The Annexes of the standard includes:
PII Controllers: Annex A - PIMS-specific reference control objectives and controls.
PII Processors: Annex B - PIMS-specific reference control objectives and controls.
Annex C: Mapping to ISO/IEC 29100
Annex D: Mapping to the General Data Protection Regulation (GDPR)
Annex E: Mapping to ISO/IEC 27018 and ISO/IEC 29151
Annex F: How to apply ISO/IEC 27701 to ISO/IEC 27001 and ISO/IEC 27002