16 January 2009

Protection of Personally Identifiable Information

Two draft standards relating to the protection of personally identifiable information have been issued for comment.

The development of a personal information management system (PIMS) encompassing all an organisation's activities can be complex. Two new draft standards provide some guidance:

These are two very different documents. The BSI draft standard is a guide to planning, implementing, monitoring, reviewing and improving a personal information management system (PIMS) to support compliance with the Data Protection Act 1998. On the other hand, the NIST draft standard is a much more readable document and describes how organisations (in this case US federal organisations) should identify, categorise and apply protection to personally identifiable information. Emphasis is also placed on reducing the PII at risk and development of incident response plans for PII breaches.

However, once released as final versions, we could see them being referenced in web project requests for information (RFIs) documents and requirements specifications, and therefore they are worth a look in advance, and possibly comment via trade and professional organisations.

Posted on: 16 January 2009 at 06:20 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Protection of Personally Identifiable Information
http://www.clerkendweller.com/2009/1/16/Protection-of-Personally-Identifiable-Information
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2009/1/16/Protection-of-Personally-Identifiable-Information
Requested by 38.107.179.224 on Tuesday, 7 February 2012 at 21:46 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2009-2012 clerkendweller.com