27557-4.1 | General principles | 0 |
27557-4.2 | Privacy risk integration | 0 |
27557-4.3 | Individual impact consideration | 206 |
27557-5.1 | Leadership and commitment | 15 |
27557-5.2 | Integration with organizational processes | 1 |
27557-5.3 | Design of framework | 0 |
27557-5.4 | Implementation and evaluation | 2 |
27557-6.1 | Communication and consultation | 16 |
27557-6.2 | Scope, context, and criteria for privacy | 170 |
27557-6.3 | Privacy risk assessment | 159 |
27557-6.4 | Privacy risk treatment | 91 |
27557-6.5 | Monitoring and review | 3 |
27557-6.6 | Recording and reporting | 92 |
27557-7.1 | Types of privacy risk | 0 |
27557-7.2 | Organizational consequences of privacy events | 0 |
27557-7.3 | Risk-based privacy program implementation | 91 |
ISO27557-10.1 | Continual Improvement | 16 |
ISO27557-10.2 | Documentation Management | 0 |
ISO27557-4.1 | Privacy Risk Management Scope | 1 |
ISO27557-4.2 | Privacy Context Establishment | 0 |
ISO27557-5.1 | Privacy Risk Management Leadership | 0 |
ISO27557-5.2 | Privacy Risk Roles and Responsibilities | 0 |
ISO27557-6.1 | Privacy Risk Assessment Methodology | 0 |
ISO27557-6.2 | Privacy Risk Identification | 0 |
ISO27557-6.3 | Privacy Risk Analysis | 0 |
ISO27557-6.4 | Privacy Risk Evaluation | 0 |
ISO27557-7.1 | Privacy Risk Treatment Options | 0 |
ISO27557-7.2 | Privacy Control Selection | 0 |
ISO27557-7.3 | Treatment Plan Documentation | 0 |
ISO27557-7.4 | Residual Privacy Risk Acceptance | 0 |
ISO27557-8.1 | Privacy Risk Communication | 0 |
ISO27557-8.2 | Consultation with Affected Parties | 0 |
ISO27557-9.1 | Privacy Risk Monitoring | 0 |
ISO27557-9.2 | Privacy Risk Review | 0 |
ISO27557-9.3 | Effectiveness Measurement | 0 |
4 | 4 Principles of organizational privacy risk management | 0 |
5 | 5 Framework | 0 |
5.1 | 5.1 Framework: general | 0 |
5.2 | 5.2 Leadership and commitment | 0 |
5.3 | 5.3 Integration | 0 |
5.4 | 5.4 Design | 0 |
5.4.1 | 5.4.1 Understanding the organization and its context | 0 |
5.4.2 | 5.4.2 Articulating risk management commitment | 0 |
5.4.3 | 5.4.3 Assigning organizational roles, authorities, responsibilities and accountabilities | 0 |
5.4.4 | 5.4.4 Allocating resources | 0 |
5.4.5 | 5.4.5 Establishing communication and consultation | 0 |
5.5 | 5.5 Implementation | 0 |
5.6 | 5.6 Evaluation | 0 |
5.7 | 5.7 Improvement | 0 |
5.7.1 | 5.7.1 Adapting | 0 |
5.7.2 | 5.7.2 Continually improving | 0 |
6 | 6 Risk management process | 0 |
6.1 | 6.1 Process: general | 0 |
6.2 | 6.2 Communication and consultation | 0 |
6.3 | 6.3 Scope, context and criteria | 0 |
6.3.1 | 6.3.1 Scope, context and criteria: general | 0 |
6.3.2 | 6.3.2 Defining the scope | 0 |
6.3.3 | 6.3.3 External and internal context | 0 |
6.3.4 | 6.3.4 Defining risk criteria | 0 |
6.4 | 6.4 Risk assessment | 0 |
6.4.1 | 6.4.1 Risk assessment: general | 0 |
6.4.2 | 6.4.2 Risk identification | 0 |
6.4.3 | 6.4.3 Risk analysis | 0 |
6.4.4 | 6.4.4 Risk evaluation | 0 |
6.5 | 6.5 Risk treatment | 0 |
6.5.1 | 6.5.1 Risk treatment: general | 0 |
6.5.2 | 6.5.2 Selection of risk treatment options | 0 |
6.5.3 | 6.5.3 Preparing and implementing risk treatment plans | 0 |
6.6 | 6.6 Monitoring and review | 0 |
6.7 | 6.7 Recording and reporting | 0 |
ANNEXES | Annexes A to D (informative): identification of PII processing, example privacy events and causes, impact and consequence examples, severity scale template | 0 |
FRONT | Clauses 2 and 3: normative references and terms | 0 |
STANDARD | ISO/IEC 27557:2022: the standard, its scope and what is held | 0 |
STATUS | Edition status: first edition 2022, current; not certifiable; the pair to ISO/IEC 27701 and ISO/IEC 29134 | 0 |