|
|
Line 1: |
Line 1: |
| [[File:ISO.png]] | | <parsererror style="display: block; white-space: pre; border: 2px solid #c77; padding: 0 1em 0 1em; margin: 1em; background-color: #fdd; color: black"> |
| | === This page contains the following errors: === |
| | <div style="font-family:monospace;font-size:12px">error on line 1 at column 24910: attributes construct error </div> |
| | === Below is a rendering of the page up to the first error. === |
| | </parsererror> |
| | [[File:ISO red.jpg|left|300px]][[File:IEC logo.png|right|300px]] |
|
| |
|
| == <span style="font-size:larger">Introduction</span> == | | == <span style="font-size:larger">Introduction</span> == |
Line 520: |
Line 525: |
| | Also an ITU reference (ITU-T X.gpim) | | | Also an ITU reference (ITU-T X.gpim) |
| |} | | |} |
| <span style="font-size:larger"></span>
| |
| === <span style="font-size: 16px; line-height: 21.9px;">29184 IS Online privacy notices and consent</span> ===
| |
|
| |
|
| {| style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;" cellpadding="1" cellspacing="1" border="1"
| |
| |- style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | Editor<br/>
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | <span style="line-height: 20.8px;">Nat Sakimura, Srinivas Poorsala, Jan Schallaboeck</span><br/>
| |
| |- style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | Scope
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" |
| |
| This document is a specification for the content and the structure of online privacy notices as well as the process of requesting consent to collect and process PII from a PII principal.
| |
|
| |
|
| This document is applicable to all situations, where a PII controller or any other entity processing PII interacts with PII principals in any online context.
| |
|
| |
|
| |- style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"
| | === <span style="font-size: 16px; line-height: 21.9px;">29184 IS Online privacy notices and consent</span> === |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | Documentation
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | <br/>
| |
| |- style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | Calendar
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" |
| |
| 1st WD provided in June 2016
| |
| | |
| 2nd WD provided in April 2017
| |
| | |
| 3rd WD provided in June 2017
| |
| | |
| 1nd CD provided in December 2017
| |
| | |
| <span style="line-height: 20.8px;">Further to Wuhan (April 2018) will go for 2nd CD</span> | |
| | |
| |- style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" | Comments
| |
| | style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;" |
| |
| <span style="line-height: 20.8px;">i</span><span style="line-height: 20.8px;">nitiated in Jaipur (Oct 2015)</span>
| |
| | |
| Follows Study Period initiated in Kuching (May 2015) User friendly online privacy notice and consent
| |
| | |
| |}
| |
| | |
| === <span style="font-size:larger">29190 IS Privacy capability assessment model</span> ===
| |
| | |
| {| style="width: 900px" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Editor
| |
| | <span style="line-height: 20.7999992370605px">Alan Shipman</span><br/>
| |
| |-
| |
| | Scope
| |
| |
| |
| This International Standard provides organizations with high-level guidance about how to assess their capability to manage privacy-related processes. <span style="line-height: 1.6">In particular, it:</span>
| |
| <ul style="line-height: 18.9090900421143px;">
| |
| <li>specifies steps in assessing processes to determine privacy capability;</li>
| |
| <li>specifies a set of levels for privacy capability assessment;</li>
| |
| <li>provides guidance on the key process areas against which privacy capability can be assessed;</li>
| |
| <li>provides guidance for those implementing process assessment;</li>
| |
| <li>provides guidance on how to integrate the privacy capability assessment into organizations operations</li>
| |
| </ul>
| |
| | |
| |-
| |
| | Documentation
| |
| | Must be purchased. [http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=45269 http://www.iso.org/iso/iso_catalogue/catalogue_tc/catalogue_detail.htm?csnumber=45269]
| |
| |-
| |
| | Calendar
| |
| | <br/>
| |
| |-
| |
| | Comments
| |
| | <br/>
| |
| |}
| |
| | |
| === <span style="font-size:larger">29191 IS Requirements for partially anonymous, partially unlinkable authentication</span> ===
| |
| | |
| {| style="width: 900px" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Editor<br/>
| |
| | Kazue Sako (NEC)
| |
| |-
| |
| | Scope
| |
| |
| |
| This International Standard defines requirements on relative anonymity with identity escrow based on the model of authentication and authorization using group signature techniques.
| |
| | |
| This document provides guidance to the use of group signatures for data minimization and user convenience.
| |
| | |
| This guideline is applicable in use cases where authentication or authorization is needed.
| |
| | |
| It allows the users to control their anonymity within a group of registered users by choosing designated escrow agents.
| |
| | |
| |-
| |
| | Documentation
| |
| | <span style="color: rgb(37, 37, 37); font-family: sans-serif; font-size: 14px; line-height: 20.7999992370605px">Must be purchased. </span> [http://www.iso.org/iso/catalogue_detail.htm?csnumber=45270 http://www.iso.org/iso/catalogue_detail.htm?csnumber=45270] (preview available)
| |
| |-
| |
| | Comments<br/>
| |
| |
| |
| Published in December 2012
| |
| | |
| Under pre-review
| |
| | |
| |}
| |
| | |
| === New Work Item: Establishing a PII deletion concept<font size="3">ion organisations</font> ===
| |
| | |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Editor
| |
| | <br/>
| |
| |-
| |
| | Scope
| |
| |
| |
| <span lang="EN-GB" style="margin: 0px;"><font face="Times" color="#000000" size="3">Specifies the conceptual framework for deletion of PII. Gives guidelines for establishing organizational policies that embrace concepts presented by specifying:</font></span>
| |
| | |
| *<span lang="EN-GB" style="margin: 0px;"><font face="Times" color="#000000" size="3">a harmonised terminology for PII deletion,</font></span>
| |
| *<span lang="EN-GB" style="margin: 0px;"><font face="Times" color="#000000" size="3">an approach for defining deletion/de-identification rules in an efficient way,</font></span>
| |
| *<span lang="EN-GB" style="margin: 0px;"><font face="Times" color="#000000" size="3">a description of required documentation, and</font></span>
| |
| *<span lang="EN-GB" style="margin: 0px;"><font face="Times" color="#000000" size="3">a definition of roles, responsibilities and processes.</font></span>
| |
| | |
| <span lang="EN-GB" style="margin: 0px;"><font face="Times" color="#000000" size="3">Document is intended to be used by organizations where PII and other personal data is being stored or processed.</font></span>
| |
| | |
| |-
| |
| | Documentation
| |
| | <br/>
| |
| |-
| |
| | Calendar
| |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| | |
| | |
| |}
| |
| | |
| == <span style="font-size: 24px;">On-going </span>S<span style="font-size: 24px;"><span style="color: rgb(0, 0, 0); font-family: sans-serif; line-height: 19.2px;">tudy Periods</span></span> ==
| |
| | |
| Study periods are the instruments through which new items of standardisation will be introduced. They typically last 6 months (until next meeting), or 12 months (2 meetings) after which, a NWIP (New Work Item Proposal) can be made<span style="line-height: 20.8px;">.</span>
| |
| | |
| === <span style="font-size: 16px;">Identify assurance framework (Started in April 2017. 18 months)</span> ===
| |
| <div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;">
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Patrick Curry, Anthony Nadalin
| |
| |-
| |
| | Objective
| |
| | analyze the outcomes of ISO/IEC 29003 and related matters, then to determine the possible next steps towards developing an International Standard (or other mechanisms) for an Identity Assurance Framework.<br/>
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| | |
| | |
| |}
| |
| </div>
| |
| === <span style="font-size: 16px;">Framework of user-centric PII handling based on privacy preference management by users (Started in April 2017, 18 months)</span> ===
| |
| <div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;">
| |
| {| style="line-height: 20.8px; width: 1112.79px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Start/duration
| |
| |
| |
| April 2017 / 18 months
| |
| | |
| |-
| |
| | Leaders
| |
| | Shinzaku Kiyomoto, Antonio Kung, Heung Youl Youm
| |
| |-
| |
| | Objective
| |
| | define frameworks of user-centric PII handling based on privacy preferences of users
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Triggered by an initiative from ITU-T for such a framework applied to the IoT. See [https://ipen.trialog.com/wiki/ITU_Activities#X.iotsec-3:.C2.A0Technical_framework_of_PII_.28Personally_Identifiable_Information.29_handling_system_in_IoT_environment https://ipen.trialog.com/wiki/ITU_Activities#X.iotsec-3:.C2.A0Technical_framework_of_PII_.28Personally_Identifiable_Information.29_handling_system_in_IoT_environment]
| |
| | |
| In Berlin (November 2017), it was decided to consider 3 options
| |
| <ul style="padding-bottom: 0px; padding-left: 40px; padding-right: 40px; padding-top: 0px;">
| |
| <li>extension of 29101</li>
| |
| <li>definition of a generic model</li>
| |
| <li>defintion of specific models</li>
| |
| </ul>
| |
| | |
| |}
| |
| </div>
| |
| === Privacy consideration in practical workflows <span style="font-weight: 400; line-height: 18.24px;">(Started in </span><span style="font-size: 16px;">April 2018)</span> ===
| |
| <div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"><div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;">
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Mickey Cohen<br/>
| |
| |-
| |
| | Objective
| |
| | Stuty the potential internationalisation of national standard DIN 66398 "Guideline for development of a concept for data deletion with derivation of deletion periods for personal identifiable information"<br/>
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| |
| |
| <span lang="EN-US" style="font-style: italic;"><font style="font-style: italic;" color="#000000">The scope of this study period is to collect contributions:</font></span>
| |
| | |
| <span lang="EN-US" style="font-style: italic;"><font style="font-style: italic;" color="#000000">(1)</font></span><font color="#000000"><span lang="EN-US" style="font-style: italic;">On workflows describing '''use-cases''' where the combination of privacy, security (including exposure period), identification quality and practical implementation need to be viewed as a whole</span></font>
| |
| | |
| <span lang="EN-US" style="font-style: italic;">(2) For a merit function(s) combining the subjects into a qualitative evaluation of the privacy</span>
| |
| | |
| |-
| |
| | Comments
| |
| |
| |
| | |
| | |
| |}
| |
| </div></div>
| |
| | |
| === <span style="font-size: 16px;">Additional Privacy-Enhancing Data De-identification standards (Started in April 2018)</span> ===
| |
| <div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"><div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;">
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Malcom Townsend
| |
| |-
| |
| | Scope
| |
| |
| |
| <span lang="EN-GB" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" color="#000000" size="3">This Study Period aims to analyze the challenges and risks associated with the implementation of data de-identification techniques described in ISO 20889, and provide a strategy and structured approach to the potential development of additional standards covering such potential topics such as requirements, risk analysis, codes of practice and so on.</font></span>
| |
| | |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| | |
| | |
| |}
| |
| </div></div>
| |
| === Development of Identify standards landscape standing document (<font style="font-weight: 400; line-height: 19.2px;" size="3">Started in April 2018)</font> ===
| |
| <div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"><div style="background-color: transparent; color: rgb(51, 51, 51); cursor: text; font-family: sans-serif,Arial,Verdana,"Trebuchet MS"; font-size: 13px; line-height: 20.8px; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;">
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Joanne Knight, Julien Bringer, Salvatore Francomacaro, Heung Youl Youm,<br/>
| |
| |-
| |
| | Objective
| |
| |
| |
| <font color="#000000"><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><span style="font-style: italic;"> </span></span></span><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" size="3">Create an initial draft of a new SD that would provide:</font></span></font>
| |
| <ul style="padding-bottom: 0px; padding-left: 40px; padding-right: 40px; padding-top: 0px;">
| |
| <li><font color="#000000"><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" size="3">The scope of the identity standards landscape</font></span></font></li>
| |
| <li><font color="#000000"><span lang="EN-NZ" style="font-family: Symbol; font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><span style="font-style: italic;"> </span></span></span><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" size="3">Introductory content identifying the role of each existing and emerging standard within the landscape, as well as its relationship to the other landscape standards. To serve as an overarching guide to users of identity-related standards</font></span></font></li>
| |
| <li><font color="#000000"><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" size="3">A process (flow chart) for the analysis of the creation or revision of identity standards, to guide alignment</font></span></font></li>
| |
| <li><font color="#000000"><span lang="EN-NZ" style="font-family: Symbol; font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><span style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><span style="font-style: italic;"> </span></span></span><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" size="3">A register of alignment issues that have been accepted as needing to be resolve</font></span></font></li>
| |
| <li><font color="#000000"><span lang="EN-NZ" style="font-style: italic; margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"><font style="font-style: italic;" face="Calibri" size="3">Develop a proposal for the process of maintaining the standing document that includes:</font></span></font></li>
| |
| </ul>
| |
| | |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| | |
| | |
| |}
| |
| </div></div>
| |
| == <span style="font-size:larger"><span style="color: rgb(0, 0, 0); font-family: sans-serif; line-height: 19.2000007629395px">Completed Study Periods</span></span> ==
| |
| | |
| The following study periods have been completed.
| |
| | |
| === <span style="line-height: 1.2; font-size: larger;">Privacy engineering framework (Started in April 2015. Completed in April 2016)</span> ===
| |
| | |
| {| style="width: 900px" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | <span style="line-height: 20.7999992370605px">Antonio Kung, Matthias Reinis</span><br/>
| |
| |-
| |
| | Objective
| |
| | Study the concept of privacy engineering and see whether new work items are needed
| |
| |-
| |
| | Documentation
| |
| | Slides presenting motivation for study period by Antonio Kung: [http://ipen.trialog.com/wiki/File:PRIPARE_Proposal_Study_Period_Privacy_Engineering_Framework_2.pdf http://ipen.trialog.com/wiki/File:PRIPARE_Proposal_Study_Period_Privacy_Engineering_Framework_2.pdf]
| |
| |-
| |
| | Timeline
| |
| | <div style="line-height: 20.7999992370605px">
| |
| *Contributions by August 15th 2015.
| |
| **<span style="line-height: 20.7999992370605px; background-color: rgb(255, 255, 0)"></span><span style="line-height: 20.7999992370605px;">Contribution from PRIPARE. [http://ipen.trialog.com/wiki/File:WG5_N94_PRIPARE_Contribution_SP_Priv_engineer_frmwk_v2.pdf http://ipen.trialog.com/wiki/File:WG5_N94_PRIPARE_Contribution_SP_Priv_engineer_frmwk_v2.pdf]</span>
| |
| *Presentation in Jaipur October 2015
| |
| **Summary made to PRIPARE project: [http://ipen.trialog.com/wiki/File:Status_SP_Privacy_Engineering_Framework_October_30th_2015.pdf <span style="background-color:#FFFF00;">http://ipen.trialog.com/wiki/File:Status_SP_Privacy_Engineering_Framework_October_30th_2015.pdf</span>]
| |
| *Contribution in 2016 with liaison to be established with ISO/IEC JTC1/SC7 Software and systems engineering
| |
| **Contribution made by PRIPARE [http://ipen.trialog.com/wiki/File:SP_Privacy_Engineering_Framework_Report_Tampa.pdf http://ipen.trialog.com/wiki/File:SP_Privacy_Engineering_Framework_Report_Tampa.pdf]
| |
| *Presentation in Tampa April 2016
| |
| *Study period completed
| |
| *Followed by ISO/IEC 27550: Privacy engineering, see above
| |
| </div>
| |
| |}
| |
| | |
| === <span style="font-size: larger;">Privacy-Preserving Attribute-based Entity Authentication (Started in October 2015. Completed in April 2016)</span> ===
| |
| | |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leader
| |
| | <span style="line-height: 20.8px;">Pascal Pailler, Nat Sakimura, Jaz Hoon Nah</span><br/>
| |
| |-
| |
| | Objective
| |
| | <br/>
| |
| |-
| |
| | Documentation
| |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| *Initiated in Jaipur (Oct 2015)
| |
| *Replaces SP privacy-respecting identity management scheme using attribute-based credentials <span style="line-height: 20.8px;">(outcome of the ABC4trust FP7 project: </span>[https://abc4trust.eu/ https://abc4trust.eu]<span style="line-height: 20.8px;">,, initiated in April 2014 in Hong Kong), with an extended scope</span>
| |
| *<span style="line-height: 20.8px;">Completed.</span>
| |
| *<span style="line-height: 20.8px;">Followed by new project : ISO/IEC 27551: Requirements for attribute-based unlinkable entity authentication (see above)</span>
| |
| | |
| |}
| |
| | |
| === <span style="font-size: larger;">Editorial inconsistencies to 29100 (Started in April 2016. Completed in October 2016)</span> ===
| |
| <div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Nat Sakimura, Mathias Reinis, Elaine Newton
| |
| |-
| |
| | Objective
| |
| |
| |
| Collecting errors and correcting inconsistencies
| |
| | |
| |-
| |
| | Documentation
| |
| | <br/>
| |
| |-
| |
| | Comments<br/>
| |
| |
| |
| *Completed, has led to a draft amendment (with limited scope)
| |
| | |
| |}
| |
| </div>
| |
| === <span style="font-size: larger;">Guidelines for privacy in Internet of Things (IoT) (Started in April 2016. Completed in April 2017)</span> ===
| |
| <div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | <span style="color: rgb(37, 37, 37); font-family: sans-serif; font-size: 14px; line-height: 20.8px;">Heung Youl Youm, Srinivas Poorsala, Antonio Kung</span><br/>
| |
| |-
| |
| | Objective
| |
| |
| |
| *assess the viability of producing guidelines for Privacy in IoT within WG5;
| |
| *to potentially provide (a) New Work Item Proposal(s) and/or input material for existing relevant projects as a recommendation to the Working Groups 5 depending on the outcome of this assessmen
| |
| | |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Initiated in Tampa (April 2016)
| |
| | |
| Initial contribution in Abu Dhabi (October 2016)
| |
| | |
| Conclusions in Hamilton (April 2017) led to the merging with Guidelines fot security in IoT (WG4). See new study period below on security and privacy for Internet of things.
| |
| | |
| Discussion also led to a new study period "Framework of user-centric PII handling based on privacy preference management by users"
| |
| <div><br/></div>
| |
| |}
| |
| </div>
| |
| === <span style="font-size: larger;">Guidelines for security and privacy for Internet of Things (IoT) (Completed in November 2017)</span> ===
| |
| <div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Start/Duration
| |
| | April 2017/6 months)
| |
| |-
| |
| | Leaders
| |
| | Eric Hibbard, Faud Khan, Tyson Macaulay, Srinivas Poorsala
| |
| |-
| |
| | Objective
| |
| | prepare the materials necessary to initiate an International Standard<br/>coming out of the SC 27 meeting in Berlin (Oct-2017)
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Is an SC27/WG4 study periods involving WG4 and WG5.
| |
| | |
| Study period is completed and new work item has been proposed ([https://ipen.trialog.com/wiki/ISO#New_Work_Item_Proposal_Security_and_Privacy_for_the_Internet_of_Things https://ipen.trialog.com/wiki/ISO#New_Work_Item_Proposal_Security_and_Privacy_for_the_Internet_of_Things]).
| |
| | |
| Kickoff expected in Wuhan in WG4
| |
| | |
| |}
| |
| </div>
| |
| === <span style="font-size: larger; line-height: 1.2;">PII Protection considerations for smartphone app providers (Started in October 2015. Completed in April 2017)</span> ===
| |
| | |
| {| style="line-height: 20.7999992370605px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leader
| |
| | Rahul Sharma, Natarajan Swaminathan, Johan Eksteen, Sai Pradeep Chilukuri<br/>
| |
| |-
| |
| | Objective
| |
| |
| |
| Study mobile application ecosystems from a privacy viewpoint
| |
| | |
| <span style="line-height: 20.7999992370605px;">Collect views of multiple stakeholders in the mobile applications space</span>
| |
| | |
| <span style="line-height: 20.7999992370605px;">Collect mobile apps privacy guidelines issued by various agencies</span>
| |
| | |
| <span style="line-height: 20.7999992370605px;">Collate a report on the findings</span>
| |
| | |
| <span style="line-height: 20.7999992370605px;">Potentially provide a new work item proposal</span>
| |
| | |
| |-
| |
| | Documentation
| |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Initiated in Jaipur (October 2015)
| |
| | |
| |}
| |
| | |
| === <span style="font-size:larger">Privacy in smart cities (Started in October 2015. Completed in November 2017)</span> ===
| |
| | |
| {| style="width: 900px" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Antonio Kung, Sanjeev Chhabra, Udbhav Tiwari<br/>
| |
| |-
| |
| | Objective
| |
| |
| |
| Connect with multiple stakeholders in the smart city space
| |
| | |
| Refer the existing work on smart cities
| |
| | |
| Collate information, feedback, inputs from the stakeholders and draft the guidelines
| |
| | |
| Potentially provide (a) new work item proposal(s) that can translate in guidelines
| |
| | |
| |-
| |
| | Documentation
| |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Initiated in Jaipur (October 2015)
| |
| | |
| Liaison to be established with ISO/IEC JTC1/SG1 (Smart cities)
| |
| | |
| Presentation in Tampa (April 2016) of intermediate state
| |
| | |
| *Liaison with EIP-SCC mentioned (see [https://eu-smartcities.eu/content/citizen-centric-approach-data-privacy-design https://eu-smartcities.eu/content/citizen-centric-approach-data-privacy-design]).
| |
| | |
| Presentation in Abu Dhabi (October 2016) of intermediate state
| |
| | |
| *Includes contribution from pripare: [https://eu-smartcities.eu/sites/all/files/PRIPARE%20recommendations%20for%20Smart%20cities.pdf https://eu-smartcities.eu/sites/all/files/PRIPARE%20recommendations%20for%20Smart%20cities.pdf]
| |
| | |
| Presentation in Hamilton (April 2017) of intermediate state
| |
| | |
| *Includes contribution from pripare [https://ipen.trialog.com/wiki/File:PRIPARE_contribution_to_SP_Privacy_in_Smart_Cities_2017.pdf https://ipen.trialog.com/wiki/File:PRIPARE_contribution_to_SP_Privacy_in_Smart_Cities_2017.pdf]
| |
| *Liaison to take place with ISO/IEC WG11 Smart cities in order to discuss the needs for privacy management guidelines
| |
| | |
| Proposal for new work item in Berlin (Nov 2017)
| |
| | |
| |}
| |
| | |
| | |
| | |
| === <span style="font-size: 16px;">Code of practice solution for different types of PII (Started in October 2016, Completed in April 2017)</span> ===
| |
| <div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | <font face="sans-serif" color="#252525"><span style="font-size: 14px;">Mathias Reinis, </span></font>Heung Youl Youm<br/>
| |
| |-
| |
| | Objective
| |
| |
| |
| Study ISO/IEC FDIS 29151 and ISO/IEC IS 27018 with the objective to find a solution that is applicable for different types of PII processors, especially compatible with the needs of a SME
| |
| | |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Terminated due to lack of contributions
| |
| | |
| |}
| |
| </div>
| |
| === <span style="font-size: 16px;">Requirements and outline for ISO/IEC 29115 revision (Started in April 2017. Concluded in April 2018)</span> ===
| |
| <div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | David Temoshok replacing Sal Francomacaro, Thomas Lenz, Patrick Curry, Andrew Hugues, Heung Youl Youm
| |
| |-
| |
| | Objective
| |
| | <br/>
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| Has resulted in a NWIP
| |
| | |
| |}
| |
| </div>
| |
| === <span style="font-size: 16px;">Application of ISO 31000 for identify-related risk (Started in April 2017. Concluded in April 2018)</span> ===
| |
| <div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Christophe Stenuit, Joanne Knight
| |
| |-
| |
| | Objective
| |
| | Gather information in order to determine the viability of creating a standard providing guidance on the application of ISO 31000:2009 to assess identity-related risks<br/>
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments<br/>
| |
| | New work item proposal
| |
| |}
| |
| </div>
| |
| === <span style="font-size: 16px;">Concept of PII Deletion (Started in November 2017. Concluded in April 2018)</span> ===
| |
| <div><div>
| |
| {| style="line-height: 20.8px; width: 900px;" cellpadding="1" cellspacing="1" border="1"
| |
| |-
| |
| | Leaders
| |
| | Volker Hammer, Srinivas Poosarla, Eduard de Jong, Alan Shipman<br/>
| |
| |-
| |
| | Objective
| |
| | Study the potential internationalisation of national standard DIN 66398 "Guideline for development of a concept for data deletion with derivation of deletion periods for personal identifiable information"<br/>
| |
| |-
| |
| |
| |
| Documentation
| |
| | |
| | <br/>
| |
| |-
| |
| | Comments
| |
| |
| |
| | |
| | |
| |}
| |
| </div></div><div></div>
| |