温馨提示:
1. 部分包含数学公式或PPT动画的文件,查看预览时可能会显示错乱或异常,文件下载后无此问题,请放心下载。
2. 本文档由用户上传,版权归属用户,汇文网负责整理代发布。如果您对本文档版权有争议请及时联系客服。
3. 下载前请仔细阅读文档内容,确认文档内容符合您的需求后进行下载,若出现内容与标题不符可向本站投诉处理。
4. 下载文档时可能由于网络波动等原因无法下载或下载错误,付费完成后未能成功下载的用户请联系客服处理。
网站客服:3074922707
ISO_IEC_22624_2020
Character_PDF_documenten
Information technology Cloud computing Taxonomy based data handling for cloud servicesINTERNATIONAL STANDARDISO/IEC22624Reference numberISO/IEC 22624:2020(E)First edition2020-02 ISO/IEC 2020 ISO/IEC 22624:2020(E)ii ISO/IEC 2020 All rights reservedCOPYRIGHT PROTECTED DOCUMENT ISO/IEC 2020All rights reserved.Unless otherwise specified,or required in the context of its implementation,no part of this publication may be reproduced or utilized otherwise in any form or by any means,electronic or mechanical,including photocopying,or posting on the internet or an intranet,without prior written permission.Permission can be requested from either ISO at the address below or ISOs member body in the country of the requester.ISO copyright officeCP 401 Ch.de Blandonnet 8CH-1214 Vernier,GenevaPhone:+41 22 749 01 11Fax:+41 22 749 09 47Email:copyrightiso.orgWebsite:www.iso.orgPublished in Switzerland ISO/IEC 22624:2020(E)Foreword.ivIntroduction.v1 Scope.12 Normative references.13Termsanddefinitions.14 Symbols and abbreviated terms.25 Overview:The need for a structured expression of data policies and practices based on a common data taxonomy.36 Framework for the structured expression of data related policies and practices.46.1 General.46.2 Framework elements.46.2.1 General.46.2.2 Data categories.56.2.3 Data identification qualifiers.66.2.4 Data usage scopes.76.2.5 Actions.86.2.6 Data classification.96.2.7 Further elements specific to the application domain.107 Using the framework.107.1 Modes of framework usage.107.2 Framework element usage.117.2.1 Data categories.117.2.2 Data identification qualifiers.117.2.3 Scopes and actions.117.3 Policy expressions.117.4 Example.118Expressionofdatarelatedpoliciesinrelationtospecificareasofconcern.128.1 General.128.2 Data geolocation.128.3 Cross border flow of data.138.3.1 Data jurisdictions considerations.138.3.2 Cross border data transfer.158.4 Data portability and data access.178.4.1 General.178.4.2 Data required for data portability or data access.178.4.3 Formats and portability.188.5 Data use.198.6 Data management.198.6.1 Data security.198.6.2 Data quality.218.7 Data governance.229 Application of the framework to codes of conduct.26Annex A(informative)Example for use of this document.30Bibliography.37 ISO/IEC 2020 All rights reserved iiiContents Page ISO/IEC 22624:2020(E)ForewordISO(the International Organization for Standardization)and IEC(the International Electrotechnical Commission)form the specialized system for worldwide standardization.National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established by the respective organization to deal with particular fields of technical activity.ISO and IEC technical committees collaborate in fields of mutual interest.Other international organizations,governmental and non-governmental,in liaison with ISO and IEC,also take part in the work.The procedures used to develop this document and those intended for its further maintenance are described in the ISO/IEC Directives,Part 1.In particular,the different approval criteria needed for the different types of document should be noted.This document was drafted in accordance with the editorial rules of the ISO/IEC Directives,Part 2(see www.iso.org/directives).Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights.ISO and IEC shall not be held responsible for identifying any or all such patent rights.Details of any patent rights identified during the development of the document will be in the Introduction and/or on the ISO list of patent declarations received(see www.iso.org/patents)or the IEC list of patent declarations received(see http:/patents.iec.ch).Any trade name used in this document is information given for the convenience of users and does not constitute an endorsement.For an explanation of the voluntary nature of standards,the meaning of ISO specific terms and expressions related to conformity assessment,as well as information about ISOs adherence to the World Trade Organization(WTO)principles in the Technical Barriers to Trade(TBT)see www.iso.org/iso/foreword.html.This document was prepared by Joint Technical Committee ISO/IEC JTC 1,Information technology,Subcommittee SC 38,Cloud Computing and Distributed Platforms.Any feedback or questions on this document should be directed to the users national standards body.A complete listing of these bodies can be found at www.iso.org/members.html.iv ISO/IEC 2020 All rights reserved ISO/IEC 22624:2020(E)IntroductionMany of the policies and practices in place for handling data in the cloud computing ecosystem need to be described based on the category of the data they address.For instance,personally identifiable information(PII)impose specific data management requirements not only in terms of security but also with regard to mechanisms that allow cloud service users to whom such data relate to exercise control