According to a study by Cisco, 94% of organizations say their customers won’t buy from them if data is not properly protected. In today’s business landscape, privacy is paramount—that’s where ISO 27701 comes in. As an extension of ISO 27001, ISO 27701 is the first international privacy standard to provide a certification for organizations demonstrating the privacy controls they have in place.
BARR is accredited by the ANSI National Accreditation Board (ANAB) to perform certification services to both ISO/IEC 27001 and 27701 standards. Take a look at everything you need to know about ISO 27701 below.
Established in 2005, ISO 27001 defines requirements for an information security management system (ISMS). The framework helps organizations manage the security of services, data, intellectual property, or any information entrusted to you by a third party.
As an extension of ISO 27001, ISO 27701 was implemented in August 2019 as a way to outline requirements for establishing, implementing, maintaining, and continually improving an organization’s privacy information management system (PIMS).
ISO 27701 provides guidance for organizations complying with international privacy regulations such as the General Data Protection Regulation (GDPR). It’s a highly effective way of demonstrating an organization’s commitment to data privacy.
Understanding the difference between security and privacy is important when looking at both ISO 27001 and ISO 27701. Security is the process or system in place to protect that data, whereas privacy refers to the individual’s ability to control the access to their personal data.
Privacy depends on security, therefore ISO 27701 depends on having ISO 27001 in place—it cannot be obtained independently.
Take a look at some key differences and similarities between ISO 27001 and ISO 27701 below.
ISO 27701 is most relevant for personally identifiable information (PII) controllers and processors, but it can also be used by any organization around the world, regardless of industry or size.
Organizations should understand the context in which they handle data—as either controllers or processors. A data controller is the entity that determines the “why” and “how” for processing personal data, while the data processor is the entity that performs the data processing.
Similarly to ISO 27001, ISO 27701 uses a risk-based approach, which means organizations adopting ISO 27701 are not required to implement every possible control for every situation. Instead, BARR will work with you to identify, prioritize, and mitigate risks according to your organization’s specific needs.
You’ll want to consider ISO 27701 if your organization:
“For organizations eager to stand out in a crowded market of cloud service providers, these certifications serve as differentiators that not only demonstrate the maturity of your information security management systems, but also affirm your commitment to protecting and securing consumer and third-party data,” said BARR founder and CEO Brad Thies.
BARR serves as your trusted partner throughout each step of the way. See below for our step-by-step approach to ISO 27701 certification.
Interested in learning more about ISO 27701? Contact us today.