Overview
ISO/IEC 27038:2014 - "Information technology - Security techniques - Specification for digital redaction" defines requirements and characteristics for securely redacting digital documents. The standard covers how to permanently remove information (including metadata, images, audio/video and embedded objects) so redacted data cannot be recovered, and it specifies requirements for software redaction tools and redaction testing methods. Note: ISO/IEC 27038:2014 does not cover redaction of information stored in databases.
Key Topics
- Scope and definitions: terms such as redaction, anonymization and personally identifiable information (PII).
- Redaction principles: retain the original (unredacted) master, perform redaction on copies, ensure irreversible removal, use approved methods and controlled environments, and delete intermediary stages.
- Levels of redaction: BASIC (no contextual mitigation) and ENHANCED (addresses contextual disclosure risks, e.g., length or placement revealing content).
- Redaction processes:
- Paper intermediaries (print/redact/scan workflows).
- Digital image intermediaries (scan-based approaches).
- Simple digital redaction (plain-text workflows, character encoding considerations).
- Complex digital redaction (original complex formats, non-text elements, embedded objects).
- Contextual handling to avoid re-identification from surrounding content.
- Metadata and non-text content: review and remove hidden metadata and embedded content that could leak sensitive information.
- Software tool characteristics: features and controls expected of redaction tools (access control, auditability, irreversible removal).
- Redaction testing: requirements and methods to verify that redaction is complete and secure.
- Record keeping: maintaining logs and records of redaction actions and decisions.
- Format guidance: annex material (e.g., PDF redaction) for common file types.
Applications
ISO/IEC 27038 is practical for organizations that need to share or publish documents while protecting sensitive content:
- Legal firms and e‑discovery teams preparing documents for disclosure
- Government agencies releasing public records or freedom-of-information responses
- Records management and archives teams anonymizing files containing PII
- Compliance and privacy officers implementing PII anonymization and data protection workflows
- Software vendors developing secure redaction tools and PDF/redaction features
- IT/security teams integrating redaction into document-handling processes
Related Standards (if applicable)
- ISO/IEC 29100 - Privacy framework and definitions for PII/anonymization (cited by 27038)
- ISO/IEC 27001 / ISO/IEC 27002 - Information security management and controls (context for secure redaction practices)
Keywords: ISO/IEC 27038:2014, digital redaction, redaction tools, redaction testing, PII anonymization, PDF redaction, metadata removal, security techniques.