ISO/IEC 27091:202x (DIS) - Cybersecurity and Privacy for Artificial Intelligence

Draft International Standard | Version: Illustration

Introduction

0.1 General | 0.2 Relationship with Other Standards

0.1 General

This document provides guidance for organizations to address privacy risks in artificial intelligence (AI) systems and machine learning (ML) models. It extends ISO/IEC 27001 principles to AI-specific privacy concerns.

It applies to organizations developing or using AI systems that process personal data.

Example: A company using AI for customer profiling must implement privacy risk controls to avoid data breaches or unlawful processing.

0.2 Relationship with Other Standards

This standard complements ISO/IEC 27001 (ISMS) and ISO/IEC 42001 (AI Management System), focusing on privacy in AI.

Example: Use with ISO/IEC 27001 for overall cybersecurity and add AI-specific privacy measures from this standard.

1. Scope

Clause Details

This standard offers guidance on managing privacy risks in AI and ML systems, including identification, assessment, and mitigation.

Example: For an AI chatbot handling user data, assess risks like data leakage and mitigate with encryption.

2. Normative References

Clause Details

Key references include:

- ISO/IEC 27001: Information security management systems

- ISO/IEC 42001: Artificial intelligence � Management system

- EU AI Act (for context)

Example: Align privacy controls with ISO/IEC 27001 Annex A for AI-specific applications.

3. Terms and Definitions

Clause Details

Key terms:

- Privacy Risk: Risk of adverse effects on individuals' privacy from AI processing.

- AI System: Machine-based system with autonomy that infers from inputs to generate outputs.

- Machine Learning Model: AI component that learns from data.

Example: "Privacy Impact" refers to how AI inference might reveal sensitive information unintentionally.

4. Context of the Organisation

4.1 Understanding the Organisation and its Context | 4.2 Understanding the Needs and Expectations of Interested Parties | 4.3 Determining the Scope of the Privacy Management System

4.1 Understanding the Organisation and its Context

Identify external and internal issues affecting privacy in AI, like regulations and data sources.

Example: Consider GDPR for EU users and internal data policies.

4.2 Understanding the Needs and Expectations of Interested Parties

Determine stakeholders' privacy expectations, such as users and regulators.

Example: Users expect data anonymity; regulators require compliance reports.

4.3 Determining the Scope of the Privacy Management System

Define boundaries for privacy management in AI.

Example: Scope includes all AI models processing personal data but excludes non-AI systems.

5. Leadership

5.1 Leadership and Commitment | 5.2 Policy | 5.3 Organizational Roles, Responsibilities and Authorities

5.1 Leadership and Commitment

Top management must commit to privacy in AI, providing resources and direction.

Example: CEO mandates privacy-by-design in all AI projects.

5.2 Policy

Establish a privacy policy for AI, committing to compliance and risk management.

Example: Policy includes "All AI data processing will minimize privacy risks."

5.3 Organizational Roles, Responsibilities and Authorities

Assign roles for privacy management in AI.

Example: DPO oversees AI privacy compliance.

6. Planning

6.1 Actions to Address Risks and Opportunities | 6.2 Privacy Objectives and Planning to Achieve Them

6.1 Actions to Address Risks and Opportunities

Plan actions to handle privacy risks in AI.

Example: Identify risk of data inference in ML and plan mitigation like differential privacy.

6.2 Privacy Objectives and Planning to Achieve Them

Set measurable privacy objectives for AI.

Example: Objective: "Reduce privacy breach incidents to zero annually."

7. Support

7.1 Resources | 7.2 Competence | 7.3 Awareness | 7.4 Communication | 7.5 Documented Information

7.1 Resources

Provide resources for privacy management in AI.

Example: Allocate budget for privacy-enhancing technologies.

7.2 Competence

Ensure staff competence for AI privacy tasks.

Example: Train developers on privacy risks in ML.

7.3 Awareness

Make staff aware of privacy policy and implications.

Example: Workshops on AI privacy risks.

7.4 Communication

Establish communication for privacy issues.

Example: Internal reporting channel for privacy concerns.

7.5 Documented Information

Maintain documented information for privacy management.

Example: Privacy impact assessments for AI models.

8. Operation

8.1 Operational Planning and Control | 8.2 Privacy by Design and by Default

8.1 Operational Planning and Control

Plan operations to meet privacy requirements in AI.

Example: Integrate privacy checks in AI development pipeline.

8.2 Privacy by Design and by Default

Implement privacy from the start in AI systems.

Example: Use anonymization by default in data processing.

9. Performance Evaluation

9.1 Monitoring, Measurement, Analysis and Evaluation | 9.2 Internal Audit | 9.3 Management Review

9.1 Monitoring, Measurement, Analysis and Evaluation

Monitor privacy performance in AI.

Example: Track data access logs for unauthorized use.

9.2 Internal Audit

Audit privacy management system.

Example: Annual internal audit of AI data handling.

9.3 Management Review

Review privacy management effectiveness.

Example: Quarterly management review of privacy incidents.

10. Improvement

10.1 General | 10.2 Nonconformity and Corrective Action | 10.3 Continual Improvement

10.1 General

Improve privacy management system continually.

Example: Update privacy controls based on new threats.

10.2 Nonconformity and Corrective Action

Handle nonconformities and correct them.

Example: If privacy breach occurs, investigate and fix the cause.

10.3 Continual Improvement

Use evaluations to improve.

Example: Enhance privacy training after audit feedback.

Back to Home