What is ISO/IEC TS 19608 about?
ISO/IEC TS 19608 provides guidance for:
selecting and specifying security functional requirements (SFRs) from ISO/IEC 15408-2 to protect Personally Identifiable Information (PII);
the procedure to define both privacy and security functional requirements in a coordinated manner; and
developing privacy functional requirements as extended components based on the privacy principles defined in ISO/IEC 29100 through the paradigm described in ISO/IEC 15408-2
Who is ISO/IEC TS 19608 for ?
ISO/IEC TS 19608 on security and privacy functional requirements is useful for:
Developers who implement products or systems
Authors of Protection Profiles
Security evaluators
Why should you use ISO/IEC TS 19608 ?
ISO/IEC 29100 defines a framework of privacy principles that should be considered when developing systems or applications that deal with personally identifiable information (PII). ISO/IEC TS 19608 those principles and maps them, where possible, to the security functional requirements defined in ISO/IEC 15408-2 . Where such a mapping is not possible, ISO/IEC TS 19608 derives new security functional requirements collected in one new class that contains several families of privacy-related security functional components following the guidance for developing new classes, families, and components provided in ISO/IEC 15408-1 and ISO/IEC 15408-2 . ISO/IEC TS 19608 can also be used as guidance for developing further privacy functional requirements using the framework of ...