Overview
ISO/IEC TR 23186:2018 defines a framework of trust for processing multi‑sourced data in cloud computing environments. It sets out high‑level elements that help stakeholders demonstrate and verify trustworthy handling of data aggregated from multiple, diverse sources. The report focuses on practical mechanisms for data use obligations and controls, data provenance, chain of custody, security and privacy, and immutable proof of compliance - all intended to build confidence among cloud service users, customers and providers when combining and processing multi‑sourced datasets.
Key Topics
- Trust elements: Defines core components that contribute to trust in multi‑sourced data processing (see sections on data use obligations, provenance, chain of custody, security and immutable proof).
- Data use obligations and controls: Describes how contractual, regulatory and policy constraints on data should be expressed and enforced.
- Data provenance, quality and integrity: Focuses on recording origin, transformations and quality indicators so consumers can assess dataset fitness for purpose.
- Chain of custody: Addresses demonstrable possession, movement and handling of datasets across systems and time.
- Security and privacy: Considers protection measures for Personally Identifiable Information (PII) and organizational confidential data during joint processing.
- Immutable proof of compliance: Recommends mechanisms for tamper‑evident evidence that obligations were met (e.g., auditable trails).
- Scenarios and agreements: Includes example use cases (traffic safety modelling, home automation, automotive operations) and guidance for embedding trust elements into agreements between parties.
Applications
ISO/IEC TR 23186:2018 is practical for organizations that assemble, share or process combined datasets in cloud environments:
- Building trust for AI/ML models that require fused datasets from public, private or IoT sources.
- Enabling industry clouds and data collaboratives (transportation planning, smart cities, health analytics).
- Specifying evidence and controls for compliance audits, contractual data sharing and privacy impact assessments.
- Informing design of data governance, provenance logging and secure data pipelines in cloud services.
Who should use this standard
- Cloud service providers and platform architects
- Data controllers, data custodians and integrators
- Compliance, legal and privacy teams
- AI/ML engineers and data scientists working with fused datasets
- IoT, automotive and smart‑city solution designers
Related standards
- ISO/IEC 17788 - Cloud computing - Overview and vocabulary (normative reference in TR 23186)
- Terminology and concepts referenced from ISO/IEC privacy and information standards (e.g., definitions of PII and chain of custody)
ISO/IEC TR 23186:2018 provides a practical trust framework to help organizations manage risk, demonstrate compliance and increase confidence when processing multi‑sourced data in cloud environments.