Overview - ISO/IEC 20547-4:2020 (Big data - Security and privacy)
ISO/IEC 20547-4:2020 defines the security and privacy aspects of the Big Data Reference Architecture (BDRA). It specifies how big data security and privacy (BD‑S&P) apply to BDRA roles, activities and functional components, and it provides operational guidance for securing big data systems. The standard addresses both technical and governance perspectives to ensure confidentiality, integrity, availability and privacy across the big data lifecycle.
Key topics and technical requirements
- Big data security & privacy concerns - Explains risks driven by big data characteristics (volume, velocity, variety, variability, volatility, veracity, value) and how these amplify threats such as data leakage, inference attacks and advanced persistent threats (APT) or DDoS.
- Security and privacy objectives - Establishes high‑level goals to protect data, support privacy-by-design and maintain trust across ecosystems.
- Governance, management and operations - Defines activities for BD‑S&P governance (planning, directing, monitoring), management (planning, assessing, updating) and operational tasks (solution design, evaluation and enablement).
- Roles and responsibilities - Maps security & privacy responsibilities to BDRA roles to support accountability and interoperability.
- Guidance on operations - Practical guidance at organization and ecosystem levels covering requirements definition, risk management, controls and lifecycle operations for data processing chains.
- Functional components - Describes security and privacy functional components and multi‑layer functions to be integrated into BDRA implementations.
- Threats and controls classification - Informative annexes provide examples of threat classifications (e.g., STRIDE, LINDDUN) and control classifications to support risk assessments and control selection.
Practical applications - who uses this standard
ISO/IEC 20547-4:2020 is intended for:
- Big data architects and solution designers - to embed BD‑S&P components and privacy-by-design principles.
- Security and privacy officers / compliance teams - for governance frameworks, controls selection and risk management aligned to BDRA.
- Data engineers and platform operators - to apply operational guidance for secure ingestion, storage, processing and access.
- Systems integrators and vendors - to ensure interoperable, secure big data solutions across ecosystems.
- Regulators and auditors - to evaluate big data systems against widely accepted BD‑S&P practices.
Practical uses include designing secure big data platforms, creating cross‑organization security operations, performing privacy risk assessments, and mapping controls to BDRA roles and lifecycle stages.
Related standards
- ISO/IEC 20546 - Big data - Overview and vocabulary
- ISO/IEC 20547-3 - Big data reference architecture - Part 3: Reference architecture
- ISO/IEC/IEEE 15288 - Systems and software engineering - System life cycle processes
Keywords: ISO/IEC 20547-4:2020, BDRA, big data security, privacy, BD‑S&P, big data reference architecture, privacy-by-design, STRIDE, LINDDUN, PII.