Overview of ISO/IEC Standards by Topic

50% found this document useful (2 votes)
381 views4 pages
The document provides examples of ISO/IEC standards across several topic areas including cybersecurity, privacy, internet of things, artificial intelligence, and biometrics. In cybersecurity…

Uploaded by

multi media
  • Cybersecurity
  • Privacy
  • Internet of Things (IoT)
  • Artificial Intelligence (AI)
  • Biometrics

Examples of ISO/IEC Standards by Topic Area

Cybersecurity
1. ISO/IEC 27001
This standard describes how to manage information security programs for an organization of any size, scope,
and complexity. Organizations can undergo a certification process for conformance to ISO/IEC 27001. This
standard is used in conjunction with information security controls and is most frequently used together with
ISO/IEC 27002.

2. ISO/IEC 27002
This standard is a comprehensive catalog of information security controls that provides high-level guidance for
each control. It is frequently used with ISO/IEC 27001 but is also used by organizations as a primary set of
information security guidelines.

3. ISO/IEC 27017
Built on top of ISO/IEC 27002, this standard provides specific cloud security controls and is used either with
ISO/IEC 27001, as an extension to ISO/IEC 27002, or as standalone guidance specifically for cloud controls.

4. ISO 31000, ISO/IEC 31010, and the second version of ISO/IEC 27005 (under development)
ISO 31000 describes how to manage risk management programs for an organization of any size, scope, and
complexity; ISO/IEC 31010 provides guidance on risk assessment techniques. ISO/IEC 27005 (which is under
revision) provides guidance on how to manage information security risks based on ISO/IEC 27001 and ISO 31000.

5. ISO/IEC 29147 & ISO/IEC 30111


This standard provides guidance for systems and software development organizations regarding how to inform
customers about newly discovered vulnerabilities in the solutions that they acquired and integrated into their
digital infrastructures.

6. ISO/IEC 15408
This standard provides the basis for certifying that security functions within digital products are designed and
are functioning as expected. These requirements are used for Common Criteria Certification, which is frequently
requested for government procurement in many jurisdictions. Common Criteria certification is supported by a
number of other additional standards. ([Link]

7. ISO/IEC 27036 – Parts 1 through 4


This is a multi-part standard that provides guidance for managing risks from supplier relationships to
organization’s business, data, and systems. These documents cover general requirements, guidelines for
information and communication technology products and services, and guidelines for cloud services.

8. Note that there are a variety of ISO/IEC cryptography standards (e.g., symmetric key, public key-based).
Examples include ISO/IEC 18033-X, 9797-X. (“-X” indicates a multi-part standard.)

1
Privacy
1. ISO/IEC 27018
This standard provides cloud-specific privacy controls. These controls are an extension to the information
security controls in ISO/IEC 27002.

2. ISO/IEC 29100
This standard provides a privacy framework and defines key terms, such as personally identifiable information
(PII) controller and PII processor.

3. ISO/IEC 27701
This standard is an extension to ISO/IEC 27001 and ISO/IEC 27002 and provides controls for managing personal
information within the context of an organization. Organizations may be a “PII controller” and/or a “PII
processor” (as defined by ISO/IEC 29100).

4. ISO/IEC 20889
This standard defines terms for de-identifying personal data as well as descriptions of techniques.

5. Under development: ISO/IEC 27555


This standard provides guidelines for deleting personal data and includes descriptions of different methods.

6. Note that the risk management and cryptography standards listed under “Cybersecurity” above (4 & 8) are also
relevant standards for privacy.

Internet of Things (IoT)


1. ISO/IEC 20924
This standard provides the terms and definitions used in various IoT standards.

2. ISO/IEC 30141
This standard is a reference document that defines an IoT systems architecture that should be used when
developing an IoT system.

3. Under development: ISO/IEC 27402


This standard provides a baseline set of security and privacy requirements for all IoT devices.

4. Under development: ISO/IEC 27400


This standard provides security and privacy guidance for the various roles/stakeholders in IoT systems.

2
Artificial Intelligence (AI)

1. ISO/IEC 24028
This technical report provides information related to trustworthiness in AI systems including transparency,
explainability, controllability, threats, risks, resiliency, reliability, safety, security and privacy.

2. Under development: ISO/IEC 22989


This standard provides the foundational terms and definitions for artificial intelligence along with descriptions of
important concepts (e.g., lifecycle, trustworthiness, bias, neural networks, data).

3. Under development: ISO/IEC 24027


This technical report provides information about bias in relation to AI systems including techniques and methods
for assessing bias.

4. Under development: ISO/IEC 24368


This technical report provides a high-level overview of the area of ethics and societal concerns relative to
artificial intelligence including principles, processes and methods in this area.

5. Under development: ISO/IEC 4213


This technical specification specifies methodologies for measuring classification performance of machine
learning models, systems and algorithms.

6. Under development: ISO/IEC 5259


This multipart standard covers methods and measures for the quality of data for analytics and machine learning.
It covers determining, managing, labeling and reporting data quality.

7. Under development: ISO/IEC 5339


This standard provides a set of guidelines for identifying the context, opportunities, and processes for
developing and applying AI applications.

8. Under development: ISO/IEC 5469


This technical report describes the properties, related risk factors, available methods and processes relating to
AI functional safety.

9. Under development: ISO/IEC 6254


This technical specification describes the objectives and methods for explainability of machine learning (ML)
models and AI systems.

10. Under development: ISO/IEC 23053


This standard provides an overview of machine learning including neural networks.

11. Under development: ISO/IEC 23894


This standard provides guidance to organizations on incorporating the development and use of AI into their
overall risk management system.

3
12. Under development: ISO/IEC 38507
This standard provides guidance to organizations on what information about the development and use of AI
systems should be provided to its governing body (e.g., C-suite executives, Board of Directors) and the related
responsibilities of the governing body.

13. Under development: ISO/IEC 42001


This standard provides requirements for establishing a management system for the development and use of AI
systems in an organization along with guidance on controls that can be used to measure the effectiveness of
related management processes.

Biometrics

1. ISO/IEC 2382-37
This standard provides a systematic description of biometric terms and concepts.

2. ISO/IEC 19795-1
This standard establishes requirements for testing the accuracy and throughput of biometric systems.

3. Under development: ISO/IEC 22116


This technical report is a study of how age, ethnicity, and gender/sex impact the performance of face,
fingerprint, and iris recognition systems.

4. Under development: ISO/IEC 19795-10


This standard establishes requirements for evaluating fairness for biometric systems by quantifying biometric
system performance variation across demographic groups.

Common questions

Powered by AI

ISO/IEC 5259, a multipart standard under development, is crucial for ensuring high data quality in machine learning applications. It covers methods and measures for managing, labeling, and reporting data quality, addressing the core requirements of clean, accurate, and unbiased data for ML models. High-quality data is essential for training effective ML models, as low-quality or biased data can lead to inaccurate outcomes, perpetuating biases and affecting decision-making processes. By providing a structured approach to data quality, ISO/IEC 5259 helps optimize ML model performance and reliability .

ISO/IEC 27701 is crucial for organizations that handle personal information as it extends ISO/IEC 27001 and ISO/IEC 27002 with additional controls focused on privacy. It helps organizations implement, maintain, and continuously improve a privacy information management system (PIMS), aligning with the principles of ISO/IEC 27001's ISMS. This standard defines roles like "PII controller" and "PII processor" and provides specific privacy controls that integrate with existing security controls in ISO/IEC 27001 and ISO/IEC 27002, facilitating regulatory compliance and enhancing privacy protection .

ISO/IEC 24028 is a technical report that contributes to the trustworthiness of AI systems by providing guidance on aspects such as transparency, explainability, controllability, threats, risks, resiliency, reliability, safety, security, and privacy. These aspects are essential for establishing trust in AI systems as they ensure that the systems are not only effective but also reliable and secure, thus minimizing potential risks associated with AI implementation .

ISO/IEC 27001 provides a framework for managing information security programs and outlines requirements for organizations seeking certification. It focuses on establishing, implementing, maintaining, and continually improving an information security management system (ISMS). ISO/IEC 27002 complements ISO/IEC 27001 by offering a comprehensive catalog of information security controls, providing high-level guidance on their implementation. While ISO/IEC 27001 specifies what an organization must do to achieve information security certification, ISO/IEC 27002 explains how to do it through its detailed guidelines on information security controls .

ISO/IEC 27017 extends the guidelines of ISO/IEC 27002 by providing additional controls specifically for cloud security. It offers guidance to cloud service providers and consumers on cloud-specific security issues, such as shared environments and cloud customer data protection. This standard can be used in conjunction with ISO/IEC 27001, enhancing the cloud security aspect of an organization's ISMS, or it can serve as an extension to ISO/IEC 27002 for organizations using it as a primary guideline for cloud control implementations .

ISO/IEC 29147 provides guidelines on how software development organizations should handle vulnerability disclosure, informing customers about vulnerabilities in their products. It explains the process of receiving information about vulnerabilities and coordinating responses. ISO/IEC 30111 complements this by offering guidance on the internal process for addressing and mitigating these vulnerabilities once they are reported. Together, these standards create a framework for effectively managing vulnerabilities by coordinating between the discovery of vulnerabilities and their mitigation .

ISO/IEC 20889 plays a significant role in addressing privacy concerns related to personal data by defining terms and techniques for de-identifying personal data. The standard's relevance lies in its ability to guide organizations through processes that minimize privacy risks while handling personal data, thereby helping them comply with privacy laws and protect individual privacy. By providing a clear framework for de-identification, organizations can effectively anonymize data, reducing the potential for unauthorized identification of individuals .

ISO/IEC 22116 is a technical report under development that explores how demographic factors like age, ethnicity, and gender/sex impact the performance of biometric systems, specifically in face, fingerprint, and iris recognition. Understanding these impacts is crucial for evaluating and mitigating biases in biometric systems, ensuring they perform fairly and accurately across diverse demographic groups .

ISO/IEC 6254, under development, addresses the critical issue of explainability in machine learning (ML) and AI systems by describing the objectives and methods needed to ensure models and systems are interpretable to stakeholders. Explainability challenges include making complex AI and ML models transparent to non-experts, justifying model decisions, and identifying potential biases or errors. This standard provides a framework for developing explainable AI systems, which helps promote trust and accountability, enabling stakeholders to understand and trust AI-generated outcomes .

ISO/IEC 30141 supports the development of IoT systems by providing a reference architecture that outlines structural and functional components necessary for developing robust and secure IoT solutions. This architecture serves as a guideline for designers and developers, ensuring compatibility, interoperability, and security in IoT systems by establishing a common framework, thus facilitating the integration of diverse IoT technologies and reducing development complexities .

1 
 
Examples of ISO/IEC Standards by Topic Area 
 
Cybersecurity 
1. ISO/IEC 27001  
This standard describes how to manage i
2 
 
Privacy 
1. ISO/IEC 27018  
This standard provides cloud-specific privacy controls. These controls are an extension to t
3 
 
Artificial Intelligence (AI) 
 
1. ISO/IEC 24028 
This technical report provides information related to trustworthiness
4 
 
12. Under development:  ISO/IEC 38507  
This standard provides guidance to organizations on what information about the d

You might also like