It seems that Microsoft Azure has been confirmed as the first cloud computing platform to comply with ISO/IEC 27018 [1], the only international standard for privacy controls in the cloud. Apparently, the certification was carried out by BSI. And this is already old news from 2/16 of this year. I may have seen it, but must have let it pass.
Furthermore, I noticed this week that Dropbox also appears to have obtained ISO/IEC 27018 certification. BSI must be extremely busy. Is JIPDEC not going to do this as well? Is it impossible because it has the PrivacyMark program?

ISO/IEC 27018 adds the privacy aspects not covered by ISO/IEC 27002, in accordance with the privacy framework of ISO/IEC 29100. It applies to PII Processors as defined in ISO/IEC 29100, or what are generally called “service providers.” A standard covering data controllers that are not service providers is being developed as ISO/IEC 29151. In fact, from the very beginning of the development of ISO/IEC 27018, not only the Japanese committee members but all the international committee members were saying, “Hmm… Do we need this? There isn’t anything unique to the cloud, is there?” Nevertheless, the standard was launched on the reasoning that, “Well, if we are going to address security in 27017, then this should be paired with it for consistency.” Was that at the Nairobi meeting, I wonder? The deliberations took place in SC 27/WG 5 (the WG for which I serve as the head of the Japanese committee) [1], but since there was not much to do, it was settled very quickly. Furthermore, the aforementioned 29151 is responsible for the overall framework, so there is also the question of whether this should be done before that work is complete. Therefore, when someone says, “We support ISO/IEC 27018!” I feel somewhat ambivalent, although of course it is still better than doing nothing…
This is the Microsoft Azure Japan Team Blog. This blog provides the latest information about Microsoft Azure as well as useful information for developers.
[1] ISO/IEC 27018 Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors
[2] Mr. Sato of HP is the principal person responsible for the Japanese national committee.
Related posts

I Received an International Standards Development Award for the ISO/IEC 29100:2024 Privacy Framework
ISO/IEC 29100:2024 Privacy frameworkAs the international editor (Project Leader) of the Privacy Framework, I received an International Standards Development Award. This standard serves as the foundation…

I Received an International Standards Development Award for ISO/IEC 29184: Online Privacy Notices and Consent
ISO/IEC 29184:2020 Information technology — Online privacy notices and consent (Japanese title: Online Privacy Notices and Consent). I received an International Standards Development Award for my…
International Standards to Consider When Designing Identity Systems
The title sounds rather grandiose, but of course there is no way I can produce a comprehensive list, so for now I will jot down whatever…


You must be logged in to post a comment.