IHS Inc. The Source for Critical Information and Insight
Electronics |  Change  

Go
 
 

ISO 22307:2008 Targets Safeguarding Privacy of Financial Data in Computer Systems

June 18, 2008 // Published as a news service by IHS

 
Electronics & Telecom Docs
IHS sells a full selection of standards documents & collections from the industry's top organizations.
To learn more, and for a free quote, please complete the form below.
TIA Collection
NEMA Collection
CEA Collection
EIA Collection
ITU Collections
IEEE Collections
EU EMC Collections
IEC Collections
First Name:

Last Name:

Email address:
A new standard from the International Organization for Standardization (ISO) seeks to safeguard the privacy of people's financial data when it is processed by automated, networked information systems.

ISO 22307:2008 - Financial services - Privacy impact assessment, defines a methodology organizations in the private and public sectors can use to identify privacy issues and mitigate risks associated with processing the financial data of customers and consumers, business partners and citizens.

"The financial services community recognizes how important it is to protect and not abuse their customers' privacy, and not just because it may be required by law," said John M. Ferris, convener of ISO/Technical Committee (TC) 68/Subcommittee (SC) 7's working group (WG) 5, Privacy impact assessment standard.

"As systems are developed or updated, there is an opportunity to enhance business processes and to provide improved services to customers.

"However, new ways of using existing technology and new technologies also bring new or unknown risks. It is advisable that corporations handling financial information be proactive in protecting and not abusing the privacy of their consumers and partners," Ferris said.

"One way of proactively addressing privacy principles and practices is to follow a standardized privacy impact assessment process for a proposed financial system, such as the one recommended in ISO 22307."

The standard describes the privacy impact assessment (PIA) to be carried out at an early stage in the development of a proposed financial system.

As well as identifying privacy options and tools, it provides a way to ensure that the system complies with applicable laws and regulations governing customer and consumer privacy, ISO said.

ISO 22307:

  • Describes the PIA process in general.
  • Defines the common and required components of a privacy impact assessment, regardless of business systems affecting financial institutions.
  • Provides guidance, including frequently asked questions (FAQs) on PIAs and their implementation, together with a number of questionnaires designed so users can assess their needs and develop a PIA.

Source: International Organization for Standardization (ISO).

ELECTRONICS & TELECOM STANDARDS & REGULATIONS NEWS
November 24, 2009
ITU Introduces Standards Conformity, Interoperability Program
The International Telecommunication Union (ITU) will implement measures that will give purchasers of information and communication technology ... more
November 24, 2009
EU Council Approves Broad Reform of Telecoms Market
On Nov. 20, the European Union (EU) Council of Ministers unanimously approved a far-reaching telecoms reform package, first proposed by the European ... more
November 24, 2009
IEEE to Develop Five Recommended Practices for Learning Tech
The Institute of Electrical and Electronics Engineers (IEEE) will develop a series of five standards covering learning technology. ... more
November 18, 2009
Internet Directory Moves Toward Internationalized Domain Names
The Internet Corporation for Assigned Names and Numbers (ICANN), which manages the Internet's core address directory, announced on Nov. 16 that ... more
November 13, 2009
Canada, U.S., Mexico Publish Compact Fluorescent Lamp Standard
The Canadian Standards Association (CSA) teamed with Underwriters Laboratories (UL) Inc. and Mexico's National Association of Standardization ... more
Show All..