Philippines | EN

ISO IEC 27018 certification

Protect sensitive information and resilience in an increasingly data-driven world.
Cloud Hosting

What is ISO IEC 27018 certification?

The ISO 27018 standard specifies requirements and guidelines for personally identifiable information protection within an information security management system (ISMS). TÜV SÜD can support you with ISO 27018 certification to assure businesses storing personal identifiable information (PII) on your cloud that you take private data protection seriously. 

The guidelines for the ISO 27018 standard help ensure personally identifiable information protection for both you and your customers. It also includes provisions for confidentiality agreements with CSP/CSC staff for PII processing and training. While ISO/IEC 27018 is not mandatory, it is increasingly recognised as the industry standard.

Why ISO IEC 27018 certification is important

ISO IEC 27018 certification help you to: 

  • Follow best practices – ISO IEC 27018 audits help you to follow best practices around protection PII in the cloud. You can be confident that your environments are safe.  
  • Mitigate risk and reputational damage – Safeguard the access, storage, transmission and processing of PII data in the cloud and avoid damaging data breaches. 
  • Gain a competitive edge – As more organisations attain ISO IEC 27018 certification, those which do not may struggle to win new contracts. 
  • Clearly define responsibilities – Define which areas of PII you are responsible for and those your customers must take care of. This improves clarity and avoids misunderstandings.  
  • Win customer trust – Many new cloud customers will now demand evidence that you are able to protect PII. Showing you have ISO IEC 27018 certification could save you time and effort.

Get started with TÜV SÜD 

Start your ISO IEC 27018 certification journey with us today.

How TÜV SÜD can help you with ISO IEC 27018 certification

TÜV SÜD is trusted around the world for our cloud assessment expertise. Our global network of experts has proven knowledge of PII security assessments as per ISO IEC 27018 guidelines. As TÜV SÜD is vendor agnostic, you and your customers can trust the impartiality and independence of our assessments.

We work with both major household-name CSPs as well as a wide variety of smaller cloud service providers and can adapt our processes to your needs and requirements. A third-party certification by TÜV SÜD demonstrates your commitment to information security.

FAQ

What is the ISO 27018 certification process?

The ISO 27018 certification process is as follows:

  1. Informational Meeting:
    This meeting involves asking and answering relevant questions, jointly planning the next steps, discussing the project, and an optional pre-audit.
  2. Review of documents and on-site audit:
    This step includes reviewing the management system’s description, evaluating readiness, verifying the ability to provide required customer assistance, and implementing documented statements into the daily practice.
  3. Assessment and audit report:
    Evaluation of the management system and report of the site visit.
  4. Documentation process:
    After meeting the certification requirements, the organisation receives a document of certification.
  5. Annual Audit:
    An annual audit monitors the progress, performance, and continued implementation of the standard.
  6. Recertification process:
    Repeating steps 2 through 6 is necessary for recertification three years after initial certification.
What are the requirements for ISO 27018?

ISO/IEC 27018 expands on the implementation guidance for security controls in ISO/IEC 27002. It controls the division of duties for data protection. For ISO 27018 compliance, the additional security measures cover:

  • PII encryption requirements for transmitting and storing needs
  • A secure termination plan for any PII that is unnecessary
  • A cloud service agreement explaining the purpose of PII processing
  • Information governance assurance from a stable cloud service provider
  • Additional security measures are also required because ISO 27018 certification requires cloud providers to demonstrate their expertise in safeguarding their clients’ personally identifiable information (PII).
What is the difference between ISO 27001 and 27018?
The standards ISO/IEC 27018 and ISO/IEC 27001 support cloud service providers and help them follow the best practices for managing data. While the ISO 27018 standard is a revised framework primarily focusing on Personally Identifiable Information (PII), ISO 27001 is an information security management system (ISMS) Standard.
Who needs ISO 27018 certification?
Many companies utilise cloud-based services for different purposes, such as storage, processing power, and even application software. The ISO 27018 standard applies to all businesses and other organisations that provide cloud-based personal data processing services.

The development of supplementary implementation regulations for security controls is based on the ISO 27001, ISO 27002, and ISO 27017 standards to ensure sufficient data protection. As a result, ISO 27018 certification is advantageous for all businesses. It assures the clients of the cloud service provider that their personal information is handled and managed in a secure and compliant way.