ISO/IEC 27701:2019: An Introduction to Privacy Information Management

  • 1h 11m 25s
  • Alan Shipman, Steve Watkins
  • IT Governance
  • 2022

An ideal primer for anyone implementing a PIMS based on ISO/IEC 27701

ISO/IEC 27701:2019 is a privacy extension to the international information security management standard, ISO/IEC 27001. It has been designed to integrate with ISO 27001 to extend an existing ISMS (information security management system) with additional requirements, enabling an organization to establish, implement, maintain, and continually improve its PIMS.

ISO 27701 provides guidance on the protection of privacy, including how organizations should manage personal information, and helps demonstrate compliance with privacy regulations around the world, such as the EU's GDPR (General Data Protection Regulation).

ISO/IEC 27701:2019: An introduction to privacy information management offers a concise introduction to the Standard, aiding those organizations looking to improve their privacy information management regime, particularly where ISO/IEC 27701:2019 is involved. It is intended for:

  • Individuals looking for general information about privacy information management
  • Organizations implementing, or considering improving, a PIMS, particularly where the use of ISO/IEC 27701:2019 is being considered

It will enable you to understand the basics of privacy information management, including:

  • What privacy information management means
  • How to manage privacy information successfully using a PIMS aligned to ISO/IEC 27701
  • Key areas of investment for a business-focused PIMS
  • How your organization can demonstrate the degree of assurance it offers with regard to privacy information management

About the Author

Alan Shipman Alan Shipman is the managing director of Group 5 Training Limited. He was the project editor for ISO/IEC 27701:2019 and is also the chair of IST/33/5, which is responsible for the UK’s contributions to the work of ISO/IEC JTC1/SC27/WG5, which deals with identity management and privacy technologies.

Steve Watkins Steve Watkins is an executive director at GRC International Group plc. He is a contracted technical assessor for UKAS, advising on its assessments of certification bodies offering ISMS/ISO 27001 and ITSMS/ISO 20000-1 accredited certification, and also undertakes information security assessments of forensic science laboratories seeking accreditation to the Forensic Science Regulator’s codes of practice and conduct.

In this Audiobook

  • Introduction
  • Chapter 1 - What is privacy information management?
  • Chapter 2 - What needs to be considered?
  • Chapter 3 - ISO/IEC 27701 and the privacy information management system requirements
  • Chapter 4 - Legal, regulatory and contractual requirements and business risk
  • Chapter 5 - Privacy information management controls
  • Chapter 6 - Certification
  • Chapter 7 - Terms and definitions