全球标准分享下载-全场2元
客服微信:1093451816,欢迎大家分享、下载!

BSI发布新规程,以保护消费者免受欺诈和财务滥用

英国标准协会(BSI)发布的新规程,为机构如何保护消费者免受欺诈或财务滥用可能造成的财务损害提供了建议。

由NatWest赞助的规程 PAS 17271:保护消费者免受由于欺诈或财务滥用可能造成的财务损害,为如何识别消费者可能因欺诈或财务滥用而面临特殊风险的消费者以及如何评估对个人潜在风险提供了指导。这个群体中的人暂时或长期的处于易受侵害的环境中,而这会影响其沟

通能力、理解能力、决策能力或者采取最符合自身利益行为的能力。

BSI的新规程中对欺诈及财务滥用做了以下区分——欺诈是一种犯罪行为,其目的是为了获得经济利益,如窃取身份信息或电信诈骗。财务滥用是一种控制他人财产、金钱、养老金或其他贵重物品的犯罪行为,其目的是为了获取经济利益或私人利益。财务滥用通常发生在信任的

人之间,如合伙人、亲属及朋友。

一个组织如何对待消费者的方式可能会造成不同程度的财务危害。如果系统或者程序不能发现、通知、保护及支持消费者,则弱势的消费者更可能遭受诈骗及财务滥用的危害。规程向期望改变或想要达到或保持良好规范的组织提供了详细的建议、指导及全面的清单。建议涉及

了组织原则、文化及战略。

针对已经出现诈骗或者财务滥用的情况,PAS 17271针对如何帮助和支持消费者提供指导,以及就如何将未来的风险最小化提供了指导。欺诈和财务滥用现象十分普遍。2016年,英国有超过185万起金融诈骗,因诈骗导致的支付卡、远程银行及支票的损失达到了768.8万,比

上年增长2%[1]。而专家认为这只是冰山一角,因为上报的诈骗案件只占所有诈骗案件的一小部分[2]

规程适用于英国境内所有管理英国消费者资金或其他财政资产的组织,不分类型、无论大小,尤其是银行、建筑互助协会、信用卡机构、信贷协会以及养老金机构。

BSI治理及恢复部负责人安妮.海因斯(Anne Hayes)表示“金融机构有责任帮助弱势群体。任何人都可能成为诈骗或财务滥用的受害者——但是从以往的经验中我们知道,有一些人极易受到影响。如有财务问题的人、有学习障碍的人、正在戒毒的人,而年轻人只是这些最易受影响

的人群中的一类”

发布“PAS 17271的目的是为了帮助组织保护消费者免受财务伤害。通过系统及程序的最佳规范防止并发现欺诈及财务滥用是其要旨。”

NatWest预防欺诈负责人大卫.洛(David Lowe)称“诈骗会给受害者带来毁灭性的伤害,但令人难过的是,我们发现这类犯罪的复杂程度一直在增加。支持并帮助消费者免受诈骗的侵害是我们共同的责任,这也是我们在2016年主动向BSI提出制定PAS的原因。BSI PAS为政府、

其他银行以及业内伙伴开展合作达成共同的目标提供了绝佳的平台。”

内政部安全部长本.华莱士(Ben Wallace)说“保护弱势群体不受欺诈或财务滥用的危害是本届政府的重要优先工作,我欢迎这个新的指南推动这一领域形成最佳规范。”

“这是一个展示共同防诈骗特别工作组协作性的示范,其中政府、执法部门以及相关行业通过协作来解决一些最棘手的诈骗问题,保护人民,尤其是极易成为受害者的高风险群体免受诈骗的侵害。”

“全国简单五步预防诈骗行动进一步提高了公众的防诈骗意识,公众可以采取简单的行动保护自己免受最常见诈骗侵害。”

PAS  17271的制定在NatWest的支持下完成,同时还有一个由金融机构和消费者组成的指导小组提供支持。参与PAS制定的并达成业内广泛共识的机构包括:英国巴克莱银行、英国建筑互助协会、消费者&公众权益网络、英国金融诈骗行动组、内政部联合行动小组、KMB电话

营销有限公司、英国警署、国家贸易标准、公共监护人办公室、英国桑坦德银行、苏格兰企业弹性中心、英国合作银行。

 

BSI launches new code of practice to protect vulnerable customers from fraud and financial abuse

BSI, the business standards company, has launched a new code of practice that gives recommendations to organizations for protecting vulnerable customers from financial harm that might occur as a result of fraud or financial abuse.

Sponsored by NatWest, the code of practice, PAS 17271: Protecting customers from financial harm as a result of fraud or financial abuse, gives guidance on how to recognize customers who might be at particular risk from fraud and financial abuse and how to assess the potential risks to the individual. This can include those in vulnerable circumstances, either temporarily or permanently, which can affect their ability to communicate, understand, make decisions, or take actions that are in their best interests.

The guidance in BSI’s new code of practice distinguishes between fraud – a criminal act involving deception intended to result in financial gain, such as ID theft or online scams – and financial abuse. Financial abuse is the criminal act of controlling a person’s property, money, pension book or other valuables intended to result in the financial or personal gain of the abuser. It is typically carried out by people in a position of trust, such as partners, relatives, friends of carers.

How an organization treats its customers can contribute to levels of financial harm.  Inadequate systems and procedures that fail to identity, inform, protect and support customers can make it more likely that vulnerable customers are susceptible to fraud or financial harm. The code of practice provides detailed recommendations, guidance and a comprehensive checklist to organizations that want to implement change, to achieve or maintain levels of good practice. Recommendations cover organizational principles, culture and strategy.

In cases where fraud or financial abuse has already occurred, PAS 17271 gives guidance on how to help and support customers, and how to minimize future risks. Fraud and financial abuse are widespread; in 2016, there were over 1.85 million cases of financial fraud in the UK. During 2016, financial fraud losses across payment cards, remote banking and cheques totalled £768.8 million, an increase of 2% over the prior year.[1] Experts believe this is only the tip of the iceberg, with only a fraction of all fraud cases reported.[2]

The code of practice is applicable to organizations of all types and sizes operating in the UK that manages the money or other financial assets of UK consumers – in particular banks, building societies, credit card providers, credit unions, and pension providers.

Anne Hayes, Head of Governance and Resilience at BSI, said: “Financial institutions have a responsibility to assist the vulnerable. Anyone can be a victim of fraud or financial abuse – but we know from experience that some people are uniquely at risk. Individuals with a

history of financial problems; learning difficulties; those recovering from addictions; and the young are just some of the diverse types of people most susceptible.

“PAS 17271 was created to help organizations protect customers from financial harm. The bottom line is that best practice in systems and procedures can help prevent and detect fraud and financial abuse.”

David Lowe, Head of Fraud Prevention at NatWest said: “Being victim of fraud can be devastating and sadly we are seeing the complexity and sophistication of these crimes increase. We know that it is our collective responsibility to support consumers and help prevent

them from falling victim to fraud which is why we took the initiative to sponsor a BSI PAS in 2016. The BSI PAS provides the best platform to join forces with the government, other banks and industry partners to work towards a common goal.’’

Ben Wallace, Security Minister at the Home Office, said: “Protecting vulnerable people from becoming victims of fraud or financial harm is a key priority for this Government and I really welcome this new guidance which will drive best practice in this area.

“It is an excellent example of the collaborative nature of the Joint Fraud Taskforce which sees Government, law enforcement and industry working together to tackle some of the toughest fraud issues in order to protect the public, particularly those that are at a higher risk

of becoming victims.

“The national Take Five to Stop Fraud campaign raises further awareness of how the public can take simple steps to protect themselves against the most common types of fraud.”

The development of Pas 17271 was sponsored by NatWest, with a steering group comprising financial institutions and consumer bodies. The broad consensus and buy-in from industry includes involvement in the development of the PAS by: Barclays; Building

Societies Association; Consumer & Public Interest Network; Financial Fraud Action UK; Home Office Joint Task Force; KMB Telemarketing Ltd; Metropolitan Police; National Trading Standards; Office of the Public Guardian; Santander UK plc; Scottish Business

Resilience Centre; The Co-Operative Bank plc. 

用安全部门标准解决市场分割问题

CEN和CENELEC共同参加了由爱沙尼亚总统和欧盟委员会于11月14日至15日在爱沙尼亚共和国首都塔林举行的高层活动“安全研究、创新、教育活动”(SRIEE 2017)。讨论的重点主要是如何缩小研究与市场之间的差距,使创新解决方案能够满足从业者和其他用户的需求。与会

者包括欧洲各国的研究人员、行业代表、公共安全服务提供商、从业人员(即消防部门、情报机构等)和决策者。

爱沙尼亚总理尤里.拉塔斯(Jüri Ratas)主持了开幕式,并发表欢迎致辞,致辞中强调了需要明确如何提高创新能力。

致辞后,围绕“向研究界传达从业者的未来需求”和“安全研究的未来”举行了两个高层专题讨论会。

CEN和CENELEC秘干事埃琳娜.圣地亚哥.希德(Elena Santiago Cid)受邀作为第1高层小组(从研究到实践者和最终用户)的发言人。

小组成员集中关注欧洲安全市场的分散化,以及欧洲安全部门的研究可以通过什么举措来提高竞争力,并提供一致的解决方案。

针对这些关注点,圣地亚哥女士说,采用标准能够减少市场分裂。她再次强调了标准化作为自愿性工具在有效地利用或带来创新方面所起到的重要作用需要引起关注,加上CEN和CENELEC体系的优势,能使利益相关方云集一起,达成共识。

为了在Horizo​​n2020研究项目中发挥标准化的作用,圣地亚哥女士分享了正在开展的欧盟FP7安全研究项目ZONeSEC(欧盟宽域监测框架)采用的方法,而该项目正是CEN-CENELEC研讨会(CWA)商讨“宽带监测安全系统的互通性”的项目之一。

很多重要的公共基础设施,如高速公路、能源线、管道(如输气管道)等都有广阔的空间覆盖范围广泛。ZONeSEC CWA启动会议将于12月11日在希腊雅典举行。

圣地亚哥女士总结了她为SRIEE高层小组所做的工作,并邀请了安全部门与标准化业界接触,共同制定支持该部门提高欧洲竞争力的解决方案。

 

Solving market fragmentation through standards in the Security sector 

CEN and CENELEC were present at the high-level event ‘Security Research, Innovation and Education Event’ (SRIEE 2017), organized by the Estonian presidency and the European Commission which took place in Tallinn on 14-15 November. The main focus of the discussions was how to reduce the gap between research and the market, so that innovative solutions can meet the needs of practitioners and other users. Participants included researchers, industry representatives, public security providers and practitioners (i.e. fire departments, intelligence agencies, etc.) and policy makers from across Europe.

Estonian Prime Minister Jüri Ratas opened the event and gave the welcoming speech emphasizing the need to identify ways to improve innovation uptake.

Two high-level panels focusing on "Conveying the future needs of Practitioners to the Research Community" and on "The future of security research" took place following the welcoming speech.
Elena Santiago Cid, CEN and CENELEC Director General, was invited as a speaker in High-level Panel 1 – From Research to Practitioners and End-users.

The panellists focused on the fragmentation of the European security market and what European research in the security sector can do to increase competitiveness and offer harmonized solutions.

In response to these concerns, Ms Santiago explained that market segmentation can be reduced through standards. She confirmed the important role that standardization plays as a voluntary tool that can deploy or bring innovation to the market and the strength of the CEN and CENELEC systems to bring all stakeholders together to reach consensus.

Addressing the role of standardization in Horizon2020 research projects, Ms Santiago shared the approach taken by ZONeSEC, an FP7 security research project which is in the process of initiating a CEN-CENELEC Workshop (CWA) on the ‘Interoperability of Security Systems for the Surveillance of Widezones’.

Widezones are critical public infrastructures such as highways, energy lines or pipelines (i.e. gas pipelines), etc. that spread over large areas covering wide geographic zones. The kick-off meeting of the CWA for ZONeSEC will take place in Athens on 11 December.

Concluding her contribution to the high level panel of SRIEE, Ms Santiago invited the security sector to reach out to the standardization community and join forces in developing solutions which support the competitiveness of the sector in Europe.

用安全部门标准解决市场分割问题

CEN和CENELEC共同参加了由爱沙尼亚总统和欧盟委员会于11月14日至15日在爱沙尼亚共和国首都塔林举行的高层活动“安全研究、创新、教育活动”(SRIEE 2017)。讨论的重点主要是如何缩小研究与市场之间的差距,使创新解决方案能够满足从业者和其他用户的需求。与会

者包括欧洲各国的研究人员、行业代表、公共安全服务提供商、从业人员(即消防部门、情报机构等)和决策者。

爱沙尼亚总理尤里.拉塔斯(Jüri Ratas)主持了开幕式,并发表欢迎致辞,致辞中强调了需要明确如何提高创新能力。

致辞后,围绕“向研究界传达从业者的未来需求”和“安全研究的未来”举行了两个高层专题讨论会。

CEN和CENELEC秘干事埃琳娜.圣地亚哥.希德(Elena Santiago Cid)受邀作为第1高层小组(从研究到实践者和最终用户)的发言人。

小组成员集中关注欧洲安全市场的分散化,以及欧洲安全部门的研究可以通过什么举措来提高竞争力,并提供一致的解决方案。

针对这些关注点,圣地亚哥女士说,采用标准能够减少市场分裂。她再次强调了标准化作为自愿性工具在有效地利用或带来创新方面所起到的重要作用需要引起关注,加上CEN和CENELEC体系的优势,能使利益相关方云集一起,达成共识。

为了在Horizo​​n2020研究项目中发挥标准化的作用,圣地亚哥女士分享了正在开展的欧盟FP7安全研究项目ZONeSEC(欧盟宽域监测框架)采用的方法,而该项目正是CEN-CENELEC研讨会(CWA)商讨“宽带监测安全系统的互通性”的项目之一。

很多重要的公共基础设施,如高速公路、能源线、管道(如输气管道)等都有广阔的空间覆盖范围广泛。ZONeSEC CWA启动会议将于12月11日在希腊雅典举行。

圣地亚哥女士总结了她为SRIEE高层小组所做的工作,并邀请了安全部门与标准化业界接触,共同制定支持该部门提高欧洲竞争力的解决方案。

 

Solving market fragmentation through standards in the Security sector 

CEN and CENELEC were present at the high-level event ‘Security Research, Innovation and Education Event’ (SRIEE 2017), organized by the Estonian presidency and the European Commission which took place in Tallinn on 14-15 November. The main focus of the discussions was how to reduce the gap between research and the market, so that innovative solutions can meet the needs of practitioners and other users. Participants included researchers, industry representatives, public security providers and practitioners (i.e. fire departments, intelligence agencies, etc.) and policy makers from across Europe.

Estonian Prime Minister Jüri Ratas opened the event and gave the welcoming speech emphasizing the need to identify ways to improve innovation uptake.

Two high-level panels focusing on "Conveying the future needs of Practitioners to the Research Community" and on "The future of security research" took place following the welcoming speech.
Elena Santiago Cid, CEN and CENELEC Director General, was invited as a speaker in High-level Panel 1 – From Research to Practitioners and End-users.

The panellists focused on the fragmentation of the European security market and what European research in the security sector can do to increase competitiveness and offer harmonized solutions.

In response to these concerns, Ms Santiago explained that market segmentation can be reduced through standards. She confirmed the important role that standardization plays as a voluntary tool that can deploy or bring innovation to the market and the strength of the CEN and CENELEC systems to bring all stakeholders together to reach consensus.

Addressing the role of standardization in Horizon2020 research projects, Ms Santiago shared the approach taken by ZONeSEC, an FP7 security research project which is in the process of initiating a CEN-CENELEC Workshop (CWA) on the ‘Interoperability of Security Systems for the Surveillance of Widezones’.

Widezones are critical public infrastructures such as highways, energy lines or pipelines (i.e. gas pipelines), etc. that spread over large areas covering wide geographic zones. The kick-off meeting of the CWA for ZONeSEC will take place in Athens on 11 December.

Concluding her contribution to the high level panel of SRIEE, Ms Santiago invited the security sector to reach out to the standardization community and join forces in developing solutions which support the competitiveness of the sector in Europe.

自愿执行标准覆盖范围:从3D原件设计到电力设备系统

为了传达标准在日常生活中发挥的重要作用,美国国家标准协会(ANSI)发布了在全球及国家标准范围内不同标准的简要,其中大多数标准是由ANSI成员及ANSI认可的标准制定组织所制定。以下选择其中最新的两个:

一、电力设备系统

电力设备和系统可以指广义的设备,包括开关设备、变压器和旋转机械,这些设备必须按照工业和制造商的标准和公差可靠和安全地运行。

ANSI/NETA ATS-2017,电力设备和系统验收测试标准确保测试的电气设备和系统正常运行、符合适用的标准和制造商的公差且按照设计规范进行安装。这些规范涵盖了可用于评估电力设备与系统的初始通电和最终验收的现场测试和检测。

美国国家电气测试协会(NETA)是ANSI成员和被ANSI认可的标准制定组织,发布了ANSI / NETA ATS-2017,以帮助电力设备和系统进行预通电和启动。这种类型的测试可以发现运输过程中造成的任何损坏,检查以确保按照设计进行安装且所有的部件都作为系统的一部分或者个体互相连接、正常工作。

NETA是一个为电气测试行业提供服务的机构,它提供认证第三方电气测试公司、认证电气测试技术人员、制定美国国家标准、举办动力测试—电气维护和安全会议以及出版NETA World技术期刊等服务。

二、3D组件的设计及组装程序实施

根据电子工业联合会(IPC)的统计,随着电子移动设备市场的持续增长,人们对设备小型化的需求及高性能的期望将会越来越高。因此,下一代3D组装面临多实施方面的挑战,由于技术的复杂性,对锻造厂、外包半导体组装和测试(OSAT)提供商以及原始设计制作商(ODM)的工艺专业知识也提出了要求。

IPC-7091标准,3D组件的设计及组装程序实施旨在为设计、开发、使用3D封装半导体原件或是考虑3D封装实施的人群提供有益且实用的信息。

3D半导体封装可以包括多个模具元件,其中包括一些均质元件和一些非均质元件。 封装也可能包括多个独立式被动SMT元件,其中一些是表面贴装元件,另一些是集成(嵌入)元件。

本标准由电子工业协会(IPC)制定,IPC是ANSI成员及被ANSI认可的标准制定组织。IPC是行业协会,其宗旨是规范电子设备及电子配件的组装及生产要求。

 

质量保证 新的体系标准DIN 77200首次实现安全服务行业认证

该系列标准DIN 77200“安全服务”将会持续提升看管和安全服务部门的服务质量。11月,德国标准协会(DIN)发布了该系列标准的第一部分和第三部分。第一部分规定了对安全服务从业公司的最低要求和服务质量标准,第三部分规定了被认可的认证机构如何检查这些标准。

DIN 77200-2标准对正在拟定中,其主要内容是对特殊领域安全服务从业公司的规定,比如公共集会、客运交通。预计标准草案将会在2018年夏天发布。

“新的系列子标准DIN 77200制定了明确的规定,根据这些规定安全服务从业公司可以自行申请认证”,德国安全部法务办公室(SCIK)负责人兼负责该体系标准的客户主席斯文.米德豪沃说,“它能够促进安全服务公司与其委托人的共识、使委托服务范围的定义更加透明、提升安

全服务行业的服务质量,并加强安全服务行业中的信任。”一揽子标准也涵盖出于各种不同目的的看管和安全服务,比如防范犯罪行为、职业伤害、自然灾害等带来的危险。

“新的一揽子标准DIN 77200制定了明确的规定,根据这些规定安全服务从业公司可以自行申请认证”,德国安全部法务办公室负责人兼新一揽子标准工作委员会负责人斯文.米德豪沃说,“它能够促进安全服务公司与其委托人的共识、使委托服务范围的定义更加透明、提升安全服

务行业的服务质量,并加强安全服务行业中的信任。”一揽子标准也涵盖出于各种不同目的的看管和安全服务,比如防范犯罪行为、职业伤害、自然灾害等带来的危险。

标准的第一部分DIN 77200-1包含了对安全服务行业的从业公司及其分公司在组织机构、工作程序、人员安排上的最低标准。此外,安全服务从业公司必须要证明,其委托的安全服务从业人员已经参加了§ 34a GewO课程,并顺利通过了专业能力测试。同时还应保证,他们具有

保障员工培训或继续教育的工作流程文件。标准的第三部分DIN 77200-3规定了对认证机构的要求及其工作程序,来解释如何检查标准第一部分中的要求是否得到执行。

标准信息沟通会

DIN将会组织3次信息沟通会,会上您将获得关于标准第一部分DIN 77200-1和第三部分DIN 77200-3应用的第一手重要信息。信息沟通会的主要目的在于传授知识以及实用探讨。

Gesicherte Qualität

Neue Normenreihe DIN 77200 ermöglicht erstmals die Zertifizierung von Wach- und Sicherheitsdienstleistungen

Die Normenreihe DIN 77200 „Sicherungsdienstleistungen“ soll die Qualität von Dienstleistungen im Wach- und Sicherheitsbereich nachhaltig erhöhen. Im November hat DIN die Teile eins und drei der Reihe veröffentlicht: Teil 1 beschreibt Mindestanforderungen und Qualitätskriterien für Sicherheitsdienstleister, Teil 3, wie akkreditierte Zertifizierungsstellen diese Kriterien prüfen. Der Normteil DIN 77200-2 enthält weitere Anforderungen an Sicherheitsdienstleister für besondere Leistungsbereiche, beispielsweise öffentliche Veranstaltungen und den Personenverkehr, und ist derzeit noch in Bearbeitung. Der Norm-Entwurf wird voraussichtlich im Sommer 2018 veröffentlicht.

Die neue Normenreihe DIN 77200 formuliert klare Anforderungen, nach denen sich Sicherheitsdienstleister zertifizieren lassen können“, erklärt Sven Middelhauve, Referent und Leiter der Rechtsabteilung der Securitas Deutschland und Obmann des für die Normenreihe zuständigen Arbeitsausschusses. „Sie fördert das einheitliche Verständnis zwischen Sicherheitsfirmen und deren Auftraggebern, sorgt für Transparenz bei der Definition des Auftragsumfangs, steigert die Qualität der angebotenen Leistungen und kann damit letztlich auch das Vertrauen in die Sicherheitsbranche steigern.“ Die Normenreihe deckt Wach- und Sicherheitsdienstleistungen ab, die unterschiedlichen Zwecken dienen können, beispielsweise zur Abwehr von Gefahren durch Straftaten, durch Betriebsausfälle oder Naturereignisse.

Der Normteil DIN 77200-1 enthält Mindestanforderungen an Sicherheitsdienstleister und deren Niederlassungen in Bezug auf Organisation, Prozesse und Personal. So müssen sie unter anderem nachweisen können, dass ihre mit Sicherheitsdienstleistungen beauftragten Mitarbeiter die Sachkundeprüfung nach § 34a GewO erfolgreich abgelegt haben. Ebenso müssen sie belegen, dass sie über ein schriftlich dokumentiertes Verfahren verfügen, um die Aus- und Weiterbildung der Mitarbeiter sicherzustellen. Normteil DIN 77200-3 beschreibt die Anforderungen an Zertifizierungsstellen und den Ablauf des Verfahrens, mit dem sich prüfen lässt, ob die in Teil 1 beschriebenen Kriterien eingehalten werden.

Informationsveranstaltungen zur Norm

Die DIN-Akademie bietet drei Informationsveranstaltungen an, bei denen Teilnehmer aus erster Hand wichtige Informationen rund um die Anwendung der Normenteile DIN 77200-1 und DIN 77200-3 erhalten. Wissensvermittlung, Diskussion und praktischer Austausch stehen im Fokus der Veranstaltungen.

 

ISO 50001能源管理标准新草案

自2011年以来,各组织按照ISO 50001所提供的系统方法持续改进能源绩效,包括能源效率、能源使用和消费。

与所有国际标准一样,ISO 50001定期会进行复审,以确保能继续满足能源行业迅速变化的需求。这项工作由负责能源管理和节能的ISO技术委员会(ISO/TC 301)开展,ISO技术委员会秘书处由美国国家标准协会(ANSI)和中国国家标准化管理委员会(SAC)联合承担 。在美国

佐治亚理工学院教授迪安娜.德赛(Deann Desai)和负责修订此标准的工作组召集人的帮助下,这里将为大家解释修订后作出的主要变化。 

“在即将出台的2018年修订版中,最关键的变化也许是融合了高层结构,从而提高了与其他管理体系标准的兼容性。”高层结构(HLS)是一个简单而有效的概念。”德赛教授解释说,“由于组织通常实施若干管理体系标准,因此,采用共享结构、相同的术语和定义能方便理解。对那

些采用单一(有时称为“综合”)管理系统的组织来说特别有用,这样能同时满足两个或以上管理体系标准要求。

德赛教授继续说道:“2018年修订版还有一些其他方面的改进,以帮助中小型企业(SMEs),确保他们明确能源性能关键概念。”这一点在鼓励中小企业采用管理体系标准时显得尤其重要,他们大部分认为跨国企业才能从国际标准中获得好处。但事实并非如此。全球各地的中小企

业都能采用ISO标准来建立客户信心,并降低其业务各方面的成本,满足法规要求。

大小规模的企业能否完成社会和环境目标,能源效率就是其中的关键。因此,普及ISO 50001也是德赛教授工作的重要一部分。她向我们介绍了一些在全球范围内普及ISO 50001的组织,包括清洁能源部长级会议(CEM)和联合国工业发展组织(UNIDO)。 

清洁能源部长级会议是一个全球性奖励计划,旨在表彰取得能源管理成就,并采用ISO 50001解决了能源和气候挑战的领先组织。会议邀请获得ISO 50001认证的组织提交自身案例研究以获得相关认可。如果这听起来很像你的组织,那么你别错过了,清洁能源部长级会议现正接受

各方报名参加2018年能源管理领导奖

 

New draft of ISO 50001 energy management standard

Since 2011, organizations have been able to follow a systematic approach in achieving continual improvement of energy performance, including energy efficiency, energy use and consumption, thanks to ISO 50001.

Like all International Standards, ISO 50001 has come under periodic review to ensure that it continues to meet the rapidly changing needs of the energy sector. This work is being carried out by the ISO technical committee responsible for energy management and energy savings (ISO/TC 301), whose secretariat is held by ANSI, ISO’s member for the USA, in a twinning arrangement with the ISO member for China, SAC. Here, we explain the main changes with the help of Deann Desai, Professor at the Georgia Institute of Technology and Convenor of the working group tasked with revising the standard. 

“Perhaps the most important change for the 2018 version is the incorporation of the high-level structure, which provides for improved compatibility with other management system standards.” The high-level structure (HLS) is a simple and effective concept. “Because organizations often implement a number of management system standards, the use of a shared structure, as well as many of the same terms and definitions, helps to keep things simple,” explains Prof. Desai. This is particularly useful for those organizations that choose to operate a single (sometimes called “integrated”) management system that can meet the requirements of two or more management system standards simultaneously.

Prof. Desai continues: “There are other improvements in the 2018 version to help ensure that the key concepts related to energy performance are clear for small and mid-sized businesses (SMEs).” This is important in encouraging uptake of the use of management system standards by SMEs, which sometimes assume that the benefits of International Standards mostly apply to multinational businesses. That’s not the case, with SMEs around the world using ISO standards to build customer confidence and reduce costs across all aspects of their business, including meeting regulation requirements.

With energy efficiency playing such a key role in meeting social and environmental targets for all sizes of business, promoting uptake of ISO 50001 is also an important part of Prof. Desai’s work. She tells us about a number of different initiatives that have helped increase the use of ISO 50001 around the world, including the Clean Energy Ministerial (CEM) and the United Nations Industrial Development Organization (UNIDO). 

The Clean Energy Ministerial is a global awards programme that recognizes leading organizations for their energy management achievements and use of ISO 50001 to address energy and climate challenges. Organizations certified to ISO 50001 are invited to submit case studies for recognition. If that sounds like your organization, then you should know that the Clean Energy Ministerial is now accepting entries for its 2018 Energy Management Leadership Awards.

ISO 30500在无污水道的地区促进全球健康

世界上还存在许多地方,农村或城市人口都不得不使用未与污水道连通的厕所。大多数情况下,这些城市规划者都正在努力通过投资基础设施来解决这个问题。但是对于这数百万人来说,目前面临主要问题的是缺乏排污系统,而水能传播疾病,对人类健康构成重大威胁,因

此,解决这个问题至关重要。这就是即将出台的国际标准草案的背景。

ISO 30500 无污水道卫生系统——预制综合处理装置——设计和测试一般安全和性能要求的出台是为预制综合处理装置的无污水道卫生系统的产品的设计和性能测试提供一般安全和性能要求。它将应用于所有未接入污水道的综合卫生系统1)

ISO 30500涵盖的综合系统中,从前端收集、传送、充分处理都涵括在无污水管卫生系统内,以便安全地再利用或处理所产生的固体、液体和气体。这个国际标准与同类标准的关键区别在于,其后端未连接到污水管网系统。

ISO 30500将涵盖无污水道卫生系统的安全性、功能性、可用性、可靠性和可维护性标准,以及此系统与环境保护目标的相容性。它不包括选择、安装、操作和维修程序的指导,也不包括无污水道卫生系统的管理,也不能替代制造商的说明书和用户手册。

无污水道卫生系统可用于世界各地的不同地方,包括没有排污系统的城市和农村社区,以及寻求可持续卫生解决方案的城市社区。不仅适用于包括难民营在内的临时或永久性居住所,也同样适用于偏远地区,供公众或私人使用。

一、改善公众健康只是开始

众所周知,人类的排泄物中含有大量的细菌,同时也是细菌、病毒、真菌、幼虫和其他病原体的完美栖息地。所以需要妥善处理好人类的排泄物,避免引发疾病风险。而符合ISO 30500要求的卫生系统,其输出物不会含有这些病原体。因此,该标准将有助于保护个人、社区和饮用水等资源免受污染,避免爆发潜在致命疾病。

此外,还可开发并促进经济、社会和环境可持续的独立式无污水道卫生系统。这可以通过资源消耗最小化(特别是用水)和依靠系统生产有用的副产品(如固态养分、液态养分、再生水、合成燃料的物质、其他可再用的输出物)两种途径来实现。

二、制造商获益匪浅

一般来说,国际标准是一套能降低成本的战略工具,通常通过最小化浪费、减少错误,提高生产力、促进自由和公平的全球贸易等方法实现。ISO 30500将向非污水道卫生系统制造商、政府、监管机构和最终用户保证,他们使用的无污水道设施质量上乘,安全可靠。

随着国际标准ISO 30500的出台,无污水道卫生系统的制造商将深深受惠于这套标准广泛且良好的效益。首先是经过验证且得到行业专家认可的准则,能大大节省时间和资源。产品的基本要素早已经标准确定,因此制造商有更多的时间来开发新功能,使产品能在市场上脱颖而出。

为制造商们营造一个公平的竞争环境,有着双重好处,即在全行业认可的可靠技术基础上让消费者放心,同时激发制造商们进行竞争性创新。而且,国际标准是跨境贸易的重要推动者,因为它们提供了一个国际公认的兼容性和一致性并存的体系,同时也为客户提供ISO认证的保证。因为ISO在世界范围内一直是值得信赖的品牌。

在一个可能因国家甚至地方政府的法规不同而有着巨大差异的行业中,制造商可以更加安心地创新和研发卫生系统。他们可以向公众、用户、客户推广这套系统是通过ISO 30500认证的。 

三、更好的用户保护政策

新标准还可以为国家或地方监管无污水道卫生系统打下坚实的基础。因为,与所有ISO标准一样,ISO 30500代表了最佳实践,反映了来自世界各地的监管机构、制造商和用户的共识。这使得在制定法规时,它能作为一项有用的资源,并且监管机构能够受益于专家的综合意见,

而无需直接呼叫专家,监管机构和政府能够获取并利用不断更新的信息和经验来源。

不过,最大受益者是在无污水道区域使用厕所的人。该标准提及的要求将推动创新,这意味着在尚未覆盖管道和电力等基础设施的地区,将会有设备更完善的厕所。在家庭和社区中,使用符合标准的厕所的人们可以确信他们的无污水道卫生系统是可靠、安全、卫生、无异味

的,甚至可生产供再次利用的副产品。这是一个多赢局面!

四、由专家制定

来自全球31个国家的专家早已就标准达成共识,他们代表着广泛的利益相关者,如行业、政府、学术界和非政府组织。ISO 30500草案由ISO/PC305(无污水道卫生系统项目委员会)编写,同时为标准制定作出贡献的还有两个联络组织,分别是非洲水协会(AfWA)和厕所委员

会联盟(TBC)。

ISO 30500预计将于2018年正式出台。 

 

ISO 30500 to boost global health in places without sewers

In many places around the world, rural and urban populations have to use toilets that aren’t connected to mains sewers. In many cases, city planners are working hard to address this by investing in infrastructures. But for millions of people, non-sewered systems are the only option and with waterborne diseases posing major risks to human health, it’s important to get it right. That’s where an upcoming Draft International Standard comes in.

ISO 30500, Non-sewered sanitation systems – Prefabricated integrated treatment units – General safety and performance requirements for design and testing, seeks to provide general safety and performance requirements for the product design and performance testing of non-sewered sanitation systems for prefabricated integrated treatment units. It will apply to any integrated sanitation system1) that is not attached to a sewer. 

In an integrated system like the ones covered by ISO 30500, the frontend collects, conveys and fully treats the specific input within the non-sewered sanitation system, to allow for safe reuse or disposal of the generated solid, liquid and gaseous output. The crucial distinction of this International Standard is that the backend is not connected to a networked sewer system. 

ISO 30500 will contain criteria for the safety, functionality, usability, reliability and maintainability of non-sewered sanitation systems, as well as the system’s compatibility with environmental protection goals. It excludes guidelines for selection, installation, operation and maintenance procedures, or management of non-sewered sanitation systems, and neither incorporates nor substitutes for manufacturers’ instructions and user manuals. 

Non-sewered sanitation systems can be used in a number of different places around the world. These include urban and rural communities without access to sewer systems and urban communities pursuing sustainable sanitation solutions. They are suitable for use in temporary or permanent settlements, including refugee camps, and are equally suited to both public or private use in isolated locations.

Improving public health is just the beginning

It’s a straightforward fact that human waste contains numerous germs. As the perfect habitat for bacteria, viruses, fungi, worms and other pathogens, human waste needs to be treated carefully to avoid risks to health. The outputs of sanitation systems that meet ISO 30500’s requirements will be free of these pathogens; thus the standard will help protect individuals, communities and resources such as drinking water from pollution and outbreaks of potentially lethal diseases. 

It additionally enables the development of stand-alone non-sewered sanitation systems that promote economic, social and environmental sustainability. This can be achieved by minimizing resource consumption (particularly water use) and enabling the production of useful by-products, such as liquid and solid nutrients, water for reuse, material for the generation of fuel and other reusable outputs, depending on the system. 

Benefits for manufacturers 

In general, International Standards are strategic tools that reduce costs by minimizing waste and errors, increasing productivity and facilitating free and fair global trade. ISO 30500 will give assurance to manufacturers of non-sewered sanitation systems, governments, regulators and end users that the non-sewered facilities they use are safe, reliable and of good quality. 

With the publication of ISO 30500, manufacturers of non-sewered sanitation systems gain from the wide range of well-established benefits that International Standards bring. First among these is the time and resource savings that go with following a tried-and-tested formula agreed to by industry experts. Once the fundamentals have been taken care of, it leaves more time for further development of the features that really make a product stand out in the marketplace. 

Creating a level playing field among manufacturers has the twofold advantage of reassuring consumers and stimulating competitive innovations on a technically solid, industry-wide base. At the same time, International Standards are a great facilitator of cross-border trade, as they provide an internationally recognized system that favours compatibility and consistency while giving customers the reassurance of the ISO name. That same recognition is also a help when it comes to marketing, since the ISO brand is trusted the world over.

In a sector where regulations may vary significantly by country, or even municipality, manufacturers can feel more secure with their innovation, research and development in sanitation systems. If they so choose, they can promote their systems towards the public, users and clients as being ISO 30500 certified. 

Better policy for user protection

The new standard can also provide a sound basis for the development of national or local regulation for non-sewered systems. That’s because, in common with all ISO standards, ISO 30500 represents best practices and reflects the consensus of regulators, manufacturers and users from across the world. That makes International Standards a useful resource when developing regulations, and gives regulators the benefit of the consolidated opinion of experts without having to call on their services directly. It will enable regulators and government to tap into a constantly updated source of information and experiences. 

And more than anyone else, it’s toilet users in non-sewered areas who are going to experience the widest benefits. The requirements of the standard will drive innovation, meaning better toilets will be available in areas where infrastructure such as plumbing and electricity are not feasible. In homes and communities, users of toilets that conform to the standard can be sure their non-sewered sanitation systems will be reliable, safe, hygienic, odour-free, and may even produce by-products that can be reused by the community. When this happens, everyone wins!

Developed by experts

Experts from 31 countries worldwide representing a broad range of stakeholder categories, such as industry, government, academia and non-governmental organizations, have come together to form consensus on the standard. The draft of ISO 30500 was prepared by ISO/PC 305, the project committee on non-sewered sanitation systems, with two liaison organizations, the African Water Association (AfWA) and the Toilet Board Coalition (TBC), also contributing to the standard’s development. 

ISO 30500 is expected to be published in 2018.

在最新出版的ISO焦点杂志上报道了制定良好治理标准的消息

滥用职权,谋取私利。信任崩塌,治理不力,后果不堪设想。也可能会威胁市场稳定,扭曲竞争,危害经济发展。

组织如何“治国安民”?《ISO焦点》(ISOfocus2017年11月/12月刊中讲述了要实现并维护良好治理,组织需作出哪些至关重要又错综复杂的变化,着重于能改善商业行为和政策的方法,以及ISO标准在哪些方面能助一臂之力。  

本期涵盖从风险管理和业务连续性到可持续采购等关键问题,还全面介绍了反贿赂管理体系ISO 37001标准,这在如今的管理上尤为实用。

本期2017年11月/ 12月刊更新版本中,包括了一些知名公司的推荐信,特别指出了ISO标准为何有益于业务,实施这些标准需要考虑哪些关键因素,以及在建立值得信赖的、有弹性的组织时,这些标准所起到的作用。实施至今,这套标准陆续带来了不少关键效益。

微软法律合规办公室项目总监贾德.海瑟罗斯(Judd Hesselroth)认为,ISO 37001让组织能够更有力地打击贿赂行为。他说:“我们认为ISO 37001将成为推进全球反腐工作的重要工具。对于在全球范围内开展业务的公司来说,一致的国际标准非常重要。”

组织长期生存需要有良好的治理——但是,应该采取什么形式?轻而易举、一蹴而就的解决方案是不存在的,对社会、组织、利益相关方来说,确定合适的治理方针关乎到他们的切身利益。

ISO秘书长塞尔希奥.穆吉卡(Sergio Mujica)在本期扉页中强调了良好的治理对ISO自身未来的重要性。“然而,虽然ISO已享誉国际,但这远远不够。我们要定期评估利益相关方的需求、期望和满意度,精益求精,更上一层楼。在柏林举行的上届ISO大会上修订的治理文件,其目的是为以往治理评估尚未能解决的重要问题更明晰地展现出来。”

最后,本期聚焦于最近举行的第40届ISO大会,以及今年劳伦斯.艾彻奖得主。(Lawrence D. Eicher,已故前ISO秘书长)

如果您考虑采用ISO标准,或者想要弯道超车,改善治理方法,那就不要错过最新出版的《ISO焦点》。我们希望能给你带来灵感,期待你的独特见解,迸发出思想的火花。

 

Setting standards for good governance in the latest ISO focus

Abuse of office for private gains. Trust undermined. Poor governance can have disastrous consequences. It can also threaten market integrity, distort competition and endanger economic development.

How can organizations improve good governance? In its November/December 2017 issue,ISOfocus gives an overview of the most interesting, important and complex changes needed to implement and sustain good governance. It looks at ways to improve business

practices and policies and where ISO standards can contribute.  

This edition offers coverage of key issues ranging from risk management and business continuity to sustainable procurement. It also provides a complete picture of ISO 37001 on anti-bribery management systems, particularly useful in today’s governance matters.

Updated throughout, this November/December 2017 issue contains testimonials from some of today’s most important companies, highlighting why ISO standards are good for business, what key considerations are needed for implementing them and their role in

building a trusted, resilient organization. Along the way, it illuminates many key benefits thus far overlooked.

For Judd Hesselroth, Programs Director in Microsoft’s Office of Legal Compliance, ISO 37001 equips organizations to strengthen their fight against bribery. “We think ISO 37001 is going to be an important tool for improving anti-corruption efforts worldwide,” he says. “The fact that the standard will be consistent across borders is also very important for companies doing business globally.”

Good governance is essential for an organization’s long-term survival – but what form should it take? There are no simple solutions but defining an appropriate approach to governance is fundamental to ensure favourable outcomes for society, organizations and stakeholders alike.

In the magazine’s opening comment, ISO Secretary-General Sergio Mujica underlines the importance of good governance for the future of ISO itself. “Yet, to be perceived as the best in the international class is not enough; we must be on a constant quest for progress and the regular evaluation of our stakeholders’ needs, expectations and satisfaction. Updating our set of governance documents at the last ISO General Assembly in Berlin was the occasion to do just that: provide increased clarity on important issues that were unresolved with the previous governance reviews.”

Finally, this latest issue puts the spotlight on the recently held 40th ISO General Assembly and the winner of this year’ Lawrence D. Eicher Award for excellence and superior performance.

If you’re thinking about using ISO standards or want to get ahead of the governance curve, look no further than the latest ISOfocus. We hope this issue gives you inspiration, insight and some new ideas of your own.Abuse of office for private gains. Trust undermined. Poor governance can have disastrous consequences. It can also threaten market integrity, distort competition and endanger economic development.

How can organizations improve good governance? In its November/December 2017 issue,ISOfocus gives an overview of the most interesting, important and complex changes needed to implement and sustain good governance. It looks at ways to improve business practices and policies and where ISO standards can contribute.  

This edition offers coverage of key issues ranging from risk management and business continuity to sustainable procurement. It also provides a complete picture of ISO 37001 on anti-bribery management systems, particularly useful in today’s governance matters.

Updated throughout, this November/December 2017 issue contains testimonials from some of today’s most important companies, highlighting why ISO standards are good for business, what key considerations are needed for implementing them and their role in building a trusted, resilient organization. Along the way, it illuminates many key benefits thus far overlooked.

For Judd Hesselroth, Programs Director in Microsoft’s Office of Legal Compliance, ISO 37001 equips organizations to strengthen their fight against bribery. “We think ISO 37001 is going to be an important tool for improving anti-corruption efforts worldwide,” he says. “The fact that the standard will be consistent across borders is also very important for companies doing business globally.”

Good governance is essential for an organization’s long-term survival – but what form should it take? There are no simple solutions but defining an appropriate approach to governance is fundamental to ensure favourable outcomes for society, organizations and stakeholders alike.

In the magazine’s opening comment, ISO Secretary-General Sergio Mujica underlines the importance of good governance for the future of ISO itself. “Yet, to be perceived as the best in the international class is not enough; we must be on a constant quest for progress and the regular evaluation of our stakeholders’ needs, expectations and satisfaction. Updating our set of governance documents at the last ISO General Assembly in Berlin was the occasion to do just that: provide increased clarity on important issues that were unresolved with the previous governance reviews.”

Finally, this latest issue puts the spotlight on the recently held 40th ISO General Assembly and the winner of this year’ Lawrence D. Eicher Award for excellence and superior performance.

If you’re thinking about using ISO standards or want to get ahead of the governance curve, look no further than the latest ISOfocus. We hope this issue gives you inspiration, insight and some new ideas of your own.

国际标准关注遏制个人信息被盗窃标准制定

优步因其对5700万司机和用户个人信息被盗一事的反应登上头条

 

知名度高的公司信息泄露事件促使着世界各国开始调查政策和条规的潜在改革,其中最知名的案例之一就是由欧盟发布并于2018年5月份生效的《通用数据保护法规》,对全球有着借鉴意义。

个人隐私在如今的超连接世界有了新的维度。随着医疗保险和财政服务等部门的电子化,保护个人数据的需求显得越发紧急。越来越多的组织开始处理个人数据,且数量有增无减。

世界三大标准机构IEC(国际电工委员会),ISO(国际标准化组织)和ITU(国际电信联盟)制订的《保护个人验证信息的规程》,为个人数据的监管方提供了一项国际标准。

自愿性标准 ISO/IEC 29151 | ITU-T X.1058 为致力于加强个人数据保护力度的政府和工业提供了一个有价值的参考。

它树立了数据保护控制的目标,明确了所要求的控制并为他们的实施提供了指导。同时它也表明了这些管控措施如何安排才能满足组织在评估个人数据保护的风险和影响中提出的要求。

除了ISO/IEC 27002标准的新增补规定之外,ITU X.1058的附录提供了一套扩展的个人数据控制措施。这份附录进一步细化了和“许可与选择”有关的控制目标以及相关的“个人数据负责人的参与”,即数据需要获得其认可人的参与。他们提供指导,通过审查“目的合法性”判断保留个人数据是否合适。他们鼓励追求“收集限制”、“数据最小化”和组织在个人数据相关政策上的“开放和透明”。

ISO/IEC 29151 | ITU-T X.1058  是在ISO/IEC“安全技术”标准专家小组的协助下编撰而成, ISO/IEC JTC 1/SC 27 和ITU-T Study Group 17 为信息与通讯技术的使用增添了自信与安全。

 

International Standard looks to curb theft of personal data

Uber is making headlines for its reaction to the theft of the personal data of 57 million drivers and users

Geneva, Switzerland, 27 November 2017  The July 2017 breach of Equifax, a large US credit bureau, exposed the social security numbers, birthdates and addresses of 143 million people. Yahoo last month – just prior to its acquisition by Verizon – shared new intelligence that a data breach in 2013 thought to have affected a billion users had in fact compromised all three billion Yahoo user accounts.

The increasing prevalence of high-profile data breaches has motivated countries worldwide to investigate potential reforms to policy and regulation. One of the best-known examples is the European Union’s General Data Protection Regulation to come into force in May 2018, with global implications.
Privacy has taken on new dimensions in our hyper connected world. The need to protect personal data is increasing in urgency with the digital transformation of sectors such as healthcare and financial services. More and more organizations are processing personal data, all of them dealing with an increasing amount of this data.
Personal data custodians have received new guidance from IEC, ISO and ITU – the three leading international standards bodies – in the form of an International Standard providing a ‘Code of Practice for the Protection of Personally Identifiable Information’.
The voluntary standard, ISO/IEC 29151 | ITU-T X.1058 provides a valuable point of reference to government and industry as they intensify their bid to guarantee the protection of personal data. 
It establishes the objectives of data-protection controls, specifies the controls required and provides guidelines for their implementation. It shows how arrangements of these controls can meet the requirements identified by organizations’ risk and impact assessments relevant to the protection of personal data.  
An Annex integral to ITU X.1058 provides an extended set of controls for personal data beyond the standard’s augmented provisions of ISO/IEC 27002.
The Annex details control objectives relevant to ‘consent and choice’ and the related ‘participation of personal data principals’, the people with whom data can be identified. They look at ‘purpose legitimacy’ to provide guidance as to whether or not the retention of personal data is appropriate. They encourage the pursuit of ‘collection limitation’ and ‘data minimization’ as well as the ‘openness and transparency’ of organizational policy with respect to personal data.
ISO/IEC 29151 | ITU-T X.1058   was developed in collaboration by the ISO/IEC standardization expert group for ‘security techniques’, ISO/IEC JTC 1/SC 27 and  ITU-T Study Group 17  ‘building confidence and security in the use of ICTs’.

 

国际标准关注遏制个人信息被盗窃标准制定

优步因其对5700万司机和用户个人信息被盗一事的反应登上头条

 

知名度高的公司信息泄露事件促使着世界各国开始调查政策和条规的潜在改革,其中最知名的案例之一就是由欧盟发布并于2018年5月份生效的《通用数据保护法规》,对全球有着借鉴意义。

个人隐私在如今的超连接世界有了新的维度。随着医疗保险和财政服务等部门的电子化,保护个人数据的需求显得越发紧急。越来越多的组织开始处理个人数据,且数量有增无减。

世界三大标准机构IEC(国际电工委员会),ISO(国际标准化组织)和ITU(国际电信联盟)制订的《保护个人验证信息的规程》,为个人数据的监管方提供了一项国际标准。

自愿性标准 ISO/IEC 29151 | ITU-T X.1058 为致力于加强个人数据保护力度的政府和工业提供了一个有价值的参考。

它树立了数据保护控制的目标,明确了所要求的控制并为他们的实施提供了指导。同时它也表明了这些管控措施如何安排才能满足组织在评估个人数据保护的风险和影响中提出的要求。

除了ISO/IEC 27002标准的新增补规定之外,ITU X.1058的附录提供了一套扩展的个人数据控制措施。这份附录进一步细化了和“许可与选择”有关的控制目标以及相关的“个人数据负责人的参与”,即数据需要获得其认可人的参与。他们提供指导,通过审查“目的合法性”判断保留个人数据是否合适。他们鼓励追求“收集限制”、“数据最小化”和组织在个人数据相关政策上的“开放和透明”。

ISO/IEC 29151 | ITU-T X.1058  是在ISO/IEC“安全技术”标准专家小组的协助下编撰而成, ISO/IEC JTC 1/SC 27 和ITU-T Study Group 17 为信息与通讯技术的使用增添了自信与安全。

 

International Standard looks to curb theft of personal data

Uber is making headlines for its reaction to the theft of the personal data of 57 million drivers and users

Geneva, Switzerland, 27 November 2017  The July 2017 breach of Equifax, a large US credit bureau, exposed the social security numbers, birthdates and addresses of 143 million people. Yahoo last month – just prior to its acquisition by Verizon – shared new intelligence that a data breach in 2013 thought to have affected a billion users had in fact compromised all three billion Yahoo user accounts.

The increasing prevalence of high-profile data breaches has motivated countries worldwide to investigate potential reforms to policy and regulation. One of the best-known examples is the European Union’s General Data Protection Regulation to come into force in May 2018, with global implications.
Privacy has taken on new dimensions in our hyper connected world. The need to protect personal data is increasing in urgency with the digital transformation of sectors such as healthcare and financial services. More and more organizations are processing personal data, all of them dealing with an increasing amount of this data.
Personal data custodians have received new guidance from IEC, ISO and ITU – the three leading international standards bodies – in the form of an International Standard providing a ‘Code of Practice for the Protection of Personally Identifiable Information’.
The voluntary standard, ISO/IEC 29151 | ITU-T X.1058 provides a valuable point of reference to government and industry as they intensify their bid to guarantee the protection of personal data. 
It establishes the objectives of data-protection controls, specifies the controls required and provides guidelines for their implementation. It shows how arrangements of these controls can meet the requirements identified by organizations’ risk and impact assessments relevant to the protection of personal data.  
An Annex integral to ITU X.1058 provides an extended set of controls for personal data beyond the standard’s augmented provisions of ISO/IEC 27002.
The Annex details control objectives relevant to ‘consent and choice’ and the related ‘participation of personal data principals’, the people with whom data can be identified. They look at ‘purpose legitimacy’ to provide guidance as to whether or not the retention of personal data is appropriate. They encourage the pursuit of ‘collection limitation’ and ‘data minimization’ as well as the ‘openness and transparency’ of organizational policy with respect to personal data.
ISO/IEC 29151 | ITU-T X.1058   was developed in collaboration by the ISO/IEC standardization expert group for ‘security techniques’, ISO/IEC JTC 1/SC 27 and  ITU-T Study Group 17  ‘building confidence and security in the use of ICTs’.

 

最全最新的标准分享平台

客服微信:1093451816返回首页