ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERENCE



Similar documents
PRIVACY IMPACT ASSESSMENT FROM A REGULATOR S S POINT OF VIEW

ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY COMMISSIONERS

ISO/IEC Information & ICT Security and Governance Standards in practice. Charles Provencher, Nurun Inc; Chair CAC-SC27 & CAC-CGIT

PRIME Privacy and Identity Management for Europe Vision Objectives First Results

Technology and Privacy

A Big Picture for Big Data

Attacking the roadblocks preventing aggressive adoption of Cloud Standards:

Working Group 5 Identity Management and Privacy Technologies within ISO/IEC JTC 1/SC 27 IT Security Techniques

ISO/IEC JTC 1/WG 10 Working Group on Internet of Things. Sangkeun YOO, Convenor

Comparative Analysis of SOA and Cloud Computing Architectures using Fact Based Modeling

FIA FIA. Installation Standards e-ready Building Next Generation IT infrastructures. ϕ The Cabling Partnership AGENDA

CEN and CENELEC response to the EC Consultation on Standards in the Digital Single Market: setting priorities and ensuring delivery January 2016

Information Security ISO Standards. Feb 11, Glen Bruce Director, Enterprise Risk Security & Privacy

Wayne M. Adams Board of Directors, Chairman Mark Carlson SNIA Cloud TWG Chair and Technical Council Member

Potential standardization items for the cloud computing in SC32

V Simpósio Internacional de Recife, PE - Brasil 3-5/11/2003

The standards landscape in cloud

Standards for Identity & Authentication. Catherine J. Tilton 17 September 2014

ITU WORK ON INTERNET OF THINGS

ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY COMMISSIONERS

Baba Piprani. Canada

International Software & Systems Engineering. Standards. Jim Moore The MITRE Corporation Chair, US TAG to ISO/IEC JTC1/SC7 James.W.Moore@ieee.

Cloud up to business processes

ISO/IEC JTC 1/SC 27 N15445

ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY COMMISSIONERS

ISO/IEC JTC1 SC32. Next Generation Analytics Study Group

Identity - Privacy - Security

De Nieuwe Code voor Informatiebeveiliging

Privacy Management Standards: What They Are and Why They Are Needed Now

This document is a preview generated by EVS

The Forefront of ICT International Standardization for Smart City and Smart Grid

Cloud Computing Standards: Overview and ITU-T positioning

Lifting the Fog Around Cloud Computing. Eric A. Hibbard, CISSP-ISSAP, ISSEP, ISSMP, CISA CTO Security & Privacy Hitachi Data systems

ISO/IEC JTC 1/SC 32 N 2096

XML for Manufacturing Systems Integration

Cloud Computing ISO Security and Privacy Standards: 27017, 27018, Mike Edwards (Chair UK Cloud Standards Committee)

ITU- T Focus Group Cloud Compu2ng

The role of standards in driving cloud computing adoption

Latest in Cloud Computing Standards. Eric A. Hibbard, CISSP, ISSAP, ISSEP, ISSMP, CISA CTO Security & Privacy Hitachi Data systems

Measurement and Analysis Introduction of ISO7816 (Smart Card)

Securely Connecting the World with Cyber Security Standards

M2M & Cybersecurity Workshop TIA 2013 M2M Standards and Security. Mihai Voicu CIO/CSO ILS Technology LLC

Entschuldigen Sie mich, I did not understand, parlez-vous IT Методы обеспечения защиты?

ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY COMMISSIONERS

Identity Management Initiatives in identity management and emerging standards Presented to Fondazione Ugo Bordoni Rome, Italy

ISO/IEC JTC 1 Information technology. Business plan 2014

ISO/IEC JTC 1/SC 36 N 2127

Standard Big Data Architecture and Infrastructure

Standarder for privacy

ISO/IEC JTC 1 SC 38 Cloud Works & Issues

Semantic Modeling at Sempra Utilities: Creating a Common Information Foundation

PRIME Project. Privacy and Identity Management for Europe. Minsk, November Yves Deswarte LAAS-CNRS, Toulouse, France

The Concept of Big Data Reference Model

Core Fittings C-Core and CD-Core Fittings

Focal points for expanded practical cooperation among standards organizations. The Business Requirement

Future Trends in Big Data

Terms of Reference. ITU-T Focus Group on Smart Cable Television (FG SmartCable)

IDENTIFICATION Morpho Driver s license Solution for governments and road traffic authorities

Liberty Alliance Project Presented at itapa 2003 Dr. Hellmuth Broda Sun Microsystems CTO EMEA and Liberty Alliance Management Board Delegate

Enterprise and Business Processes - How to Interoperate? The Standards View

ITU-T Security Standard Activities

Big Data Systems and Interoperability

EU Threat Landscape Threat Analysis in Research ENISA Workshop Brussels 24th February 2015

Information Security, PII and Big Data

Standardizing contactless communication between ticketing equipment and fare media Transport Ticketing 2014

Information Technology

Radio Frequency Identification (RFID)

Information Technology Metamodel Framework for Interoperability (MFI) Part 9: On Demand Model Selection

EPCglobal RFID standards & regulations. Henri Barthel OECD Paris, 5 October 2005

Pilvipalveluiden tietoturvan standardisointi

ISO Biometric Template Protection

Interna'onal Standards Ac'vi'es on Cloud Security EVA KUIPER, CISA CISSP HP ENTERPRISE SECURITY SERVICES

Achievements and ongoing work in the ITU-T standardization of the Internet of Things

ISO JTC 1 SGBD Mtg and ACM Workshop

NIST Coordination and Acceleration of Smart Grid Standards. Tom Nelson National Institute of Standards and Technology 8 December, 2010

The Emerging ISO International Standard for Certification of Software Engineering Professionals

Accelerating Cloud adoption with Security Level Agreements automation, monitoring and industry standards compliance

An overview of Health Informatics Standards

ISO/IEC & ediscovery (ISO/IEC 27050) Eric A. Hibbard, CISSP-ISSAP, ISSEP, ISSMP, CISA CTO Security & Privacy Hitachi Data systems

Haihua LI

The Emerging ISO International Standard for Certification of Software Engineering Professionals

Strong Authentication for Future Web Applications

BIOMETRICS STANDARDS AND FACE IMAGE FORMAT FOR DATA INTERCHANGE - A REVIEW

Smart Card Application Development Using Java

Cloud standards: Ready for Prime Time. CloudWatch webinar: Standards ready for prime time (part 2) 1

Status Report on Storage Security Initiatives

Transcription:

29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

Standards Briefing John Hopkinson ISSPCS-Prac CISSP ISP CDRP Security Strategist, EWA /IIT President ISSEA Chair CAC-JTC1/TCIT 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

JTC 1 is unique ISO/IEC JTC 1 It is a hybrid of both ISO and IEC 30% of customers are other standards developers It produces Base Standards It must always assume the worst case Has been developing standards related to Privacy for the last 7 to 10 years 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISO/IEC JTC 1/SC 17 Concerned with privacy related to card technology applications Includes data on smart & optical cards Not currently reviewing standards for privacy The chair authored two Privacy Impact assessments for advanced card technologies 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISO/IEC JTC 1/SC 27 Created a new WG for Privacy, projects on A Privacy Framework A Privacy Reference Architecture Privacy infrastructures Anonymity and credentials Specific Privacy Enhancing Technologies (PETs) Privacy Engineering 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISO/IEC JTC 1/SC 31 Develops standards for RFID Is starting to consider Privacy Added the Kill bit function to the ISO/IEC 18000-6 standard Memory blocks include password protection 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISO/IEC JTC 1/SC 32 Standards for data mgt and interchange including e- commerce Deal with e-business, Metadata, Database Languages, & SQL Multimedia & Application Packages Recognizes individual as a sub-type of Person, have rights which e-business standards must support 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISO/IEC JTC 1/SC 36 Standards of Learning, Education & Training Support for legal requirements Surveying members for specifics of National requirements Most important standard ISO/IEC 24751 Individualized Adaptability and Accessibility in e-learning, Education and Training 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISO/IEC JTC 1/SC 37 Develop standards for Biometrics Has started to consider Privacy Working on Cross-Jurisdictional and Societal Aspects of Implementation of Biometric Technologies Guide to the Accessibility, Privacy and Health and Safety Issues in the deployment of Biometric Systems for Commercial Application 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

Other Standards Development Several Consortia are active, including ISSEA ISTPA OASIS OMG W3C Likely several others 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

Canadian Privacy Standardization Strategy 21 & 22 Feb 2007; OPC, CSA, SCC, CGSB Privacy Standardization Roadmap What is available & What is needed Workshop Report +, Special Needs, Conformance, sharing Best Practices,Timing critical, Engagement 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE

ISSUES ISO/IEC JTC 1 and others A lack of coordination of Privacy activities No real focal point for Privacy work Lack harmonized privacy principles Need Privacy community & technical standards cooperation 29e CONFÉRE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIV ES ET DE LA VIE PRIVÉE E 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS CONFERE