ISO/IEC DIS 20547-4:2019(E)
Foreword ..........................................................................................................................................................................................................................................v
Introduction ................................................................................................................................................................................................................................vi
1 Scope ................................................................................................................................................................................................................................. 1
2 Normative references ...................................................................................................................................................................................... 1
..................................................................................................................................................................................... 1
4 Symbols and abbreviated terms ........................................................................................................................................................... 1
5 Overview ....................................................................................................................................................................................................................... 2
............................................................................................................................. 2
................................................................................................................................................ 4
6 Security and privacy aspects of BDRA user view ................................................................................................................ 6
6.1 Overview ...................................................................................................................................................................................................... 6
6.2 Governance activities ........................................................................................................................................................................ 6
6.2.1 Purpose .................................................................................................................................................................................... 6
6.2.2 Prepare for and plan BD-S&P governance effort .................................................................................. 7
6.2.3 Monitor, assess and control BD-S&P governance activities ........................................................ 7
................................................................................................... 7
6.2.5 Direct BD-S&P..................................................................................................................................................................... 8
6.2.6 Monitor and assess compliance with BD-S&P governance directives and
guidance .................................................................................................................................................................................. 9
6.3 Management activities ..................................................................................................................................................................10
6.3.1 Purpose ................................................................................................................................................................................. 10
6.3.2 Prepare for and plan BD-S&P management effort ........................................................................... 10
6.3.3 Monitor, assess and control the architecture management activities ............................. 11
6.3.4 Develop BD-S&P management approach ................................................................................................. 11
6.3.5 Perform management of BD-S&P ...................................................................................................................12
6.3.6 Monitor BD-S&P effectiveness ..........................................................................................................................12
6.3.7 Update the BD-S&P management plan ...................................................................................................... 13
6.4 Operation activities .......................................................................................................................................................................... 13
6.4.1 BD-S&P solution design activities .................................................................................................................. 13
6.4.2 BD-S&P solution evaluation activities ........................................................................................................ 18
6.4.3 BD-S&P solution enablement activities .....................................................................................................23
..........................................................................................................26
7 Guidance on security and privacy operations for big data .................................................................................... 29
7.1 General ........................................................................................................................................................................................................ 29
7.2 Guidance at organization level ............................................................................................................................................... 30
7.2.1 Introduction ...................................................................................................................................................................... 30
........................................................................................................... 31
7.2.3 Standard guidance on risk management .................................................................................................32
7.2.4 Standard guidance on controls ......................................................................................................................... 32
............................................................................................ 32
.....................................................................................................................................................32
7.3.1 Introduction ...................................................................................................................................................................... 32
7.3.2 Guidance on data processing chain ..............................................................................................................33
7.3.3 Guidance on risk management ......................................................................................................................... 34
.................................................................................................................... 35
8 Security and privacy functional components ......................................................................................................................37
8.1 Overview ...................................................................................................................................................................................................37
...................................................................................... 37
................................................................................................................................... 38
......................................................................................................... 39
Annex A (informative) ....................................................... 41
© ISO/IEC 2019 – All rights reserved iii
Contents Page