Based on ISOIEC 27701
Scope of application:
ISO27701 is a privacy extension to ISO27001 and ISO27002. ISO27001 is an information security management system standard, which focuses on the overall framework and requirements of information security, such as how to protect the confidentiality, integrity and availability of information. The ISO27002 provides specific information security controls and implementation guidance. ISO27701, on the basis of these two, it has deepened and refined privacy protection, integrated the principles, concepts and methods of privacy protection into the information security protection system, and carried out PII controllers and PII processors. More detailed and strong regulations have been made, and more targeted guidance and suggestions have been put forward for enterprises in terms of privacy protection and information security.
Which organizations apply to ISO27701:
ISO27701 apply to organizations of all types and sizes, regardless of industry, geography or the nature of their business, including public and private companies, government agencies and non-profit organizations.
