It seems that Microsoft Azure has been confirmed as the first cloud computing platform to comply with ISO/IEC 27018 [1], the only international standard for privacy controls in the cloud. Apparently, the certification was carried out by BSI. And this is already old news from 2/16 of this year. I may have seen it, but must have let it pass.

Furthermore, I noticed this week that Dropbox also appears to have obtained ISO/IEC 27018 certification. BSI must be extremely busy. Is JIPDEC not going to do this as well? Is it impossible because it has the PrivacyMark program?

ISO/IEC 27018購入ページ
ISO/IEC 27018 purchase page. It is convenient that an ePub edition is available in addition to the PDF

ISO/IEC 27018 adds the privacy aspects not covered by ISO/IEC 27002, in accordance with the privacy framework of ISO/IEC 29100. It applies to PII Processors as defined in ISO/IEC 29100, or what are generally called “service providers.” A standard covering data controllers that are not service providers is being developed as ISO/IEC 29151. In fact, from the very beginning of the development of ISO/IEC 27018, not only the Japanese committee members but all the international committee members were saying, “Hmm… Do we need this? There isn’t anything unique to the cloud, is there?” Nevertheless, the standard was launched on the reasoning that, “Well, if we are going to address security in 27017, then this should be paired with it for consistency.” Was that at the Nairobi meeting, I wonder? The deliberations took place in SC 27/WG 5 (the WG for which I serve as the head of the Japanese committee) [1], but since there was not much to do, it was settled very quickly. Furthermore, the aforementioned 29151 is responsible for the overall framework, so there is also the question of whether this should be done before that work is complete. Therefore, when someone says, “We support ISO/IEC 27018!” I feel somewhat ambivalent, although of course it is still better than doing nothing…

 

This is the Microsoft Azure Japan Team Blog. This blog provides the latest information about Microsoft Azure as well as useful information for developers.

Source: Microsoft Azure Confirmed as the First Cloud Computing Platform to Comply with ISO/IEC 27018, the Only International Standard for Privacy Controls in the Cloud – Microsoft Azure Japan Team Blog – Site Home – MSDN Blogs

dropbox-27018

[1] ISO/IEC 27018 Information technology — Security techniques — Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors

[2] Mr. Sato of HP is the principal person responsible for the Japanese national committee.

Related posts