What is ISO/IEC TS 19608 about?
ISO/IEC TS 19608 provides guidance for:
- selecting and specifying security functional requirements (SFRs) from ISO/IEC 15408-2 to protect Personally Identifiable Information (PII);
- the procedure to define both privacy and security functional requirements in a coordinated manner; and
- developing privacy functional requirements as extended components based on the privacy principles defined in ISO/IEC 29100 through the paradigm described in ISO/IEC 15408-2
Who is ISO/IEC TS 19608 for?
ISO/IEC TS 19608 on security and privacy functional requirements is useful for:
- Developers who implement products or systems
- Authors of Protection Profiles
- Security evaluators
Why should you use ISO/IEC TS 19608?
ISO/IEC 29100 defines a framework of privacy principles that should be considered when developing systems or applications that deal with personally identifiable information (PII).
ISO/IEC TS 19608 those principles and maps them, where possible, to the security functional requirements defined in
ISO/IEC 15408-2. Where such a mapping is not possible,
ISO/IEC TS 19608 derives new security functional requirements collected in one new class that contains several families of privacy-related security functional components following the guidance for developing new classes, families, and components provided in
ISO/IEC 15408-1 and
ISO/IEC 15408-2.
ISO/IEC TS 19608 can also be used as guidance for developing further privacy functional requirements using the framework of
ISO/IEC 15408. The class, families, and components defined in
ISO/IEC TS 19608 can be extended for cases where the components defined here are not sufficient to express specific privacy functional requirements