The full title of the ISO/IEC 27561:2024 standard is Information security, cybersecurity and privacy protection — Privacy operationalisation model and method (POMME) for engineering.
Expectations regarding personal data are typically set out in policy documents, contracts, and legislation. Ensuring these expectations are embedded in the daily operations of products, services, and processes becomes a separate management issue. ISO/IEC 27561 is a guidance document published to assist organisations in this regard. The document is abbreviated as ‘POMME’, which stands for ‘Privacy Operationalisation Methodology for Engineering’.
ISO/IEC 27561:2024 was published in its first edition in March 2024 and describes a method for addressing privacy objectives in projects.
What is the ISO/IEC 27561 Standard?
ISO/IEC 27561 describes a model and method that enable privacy-related objectives to be addressed at project stages. In short, it focuses on establishing the link between ‘expectation’ and ‘implementation’.
The objectives of the standard are:
- To clearly document privacy expectations,
- To translate these expectations into requirements,
- To identify the functions that must be present in the system,
- To verify the implementation through testing and documentation,
This approach prevents privacy from being treated as a one-off exercise and helps embed it into the project workflow.
Why is ISO/IEC 27561 Important?
Privacy objectives are often included in policy and commitment documents within organisations. The real need is for these objectives to be reflected as applicable requirements in the work plan and product development flow, and for the resulting application to be supported by verifiable records. ISO/IEC 27561 provides a method for systematically transferring these objectives to project steps.
The guide helps different teams address the same objectives within a common working framework. It clarifies how privacy expectations should be expressed, how system functions that meet these expectations can be determined, and how the verification approach should be designed. This reduces uncertainty throughout the project, defines responsibilities more clearly, and ensures more orderly progress in evidence management.
What is the Impact of ISO/IEC 27561 on the Organisation?
- Provides traceability: It becomes clearer which requirement addresses a privacy expectation, which design decision it is linked to, and which test evidence validates it.
- Strengthens audit and evidence management: Evidence production ceases to be a task gathered at the end of the project. It becomes part of a regular structure throughout the process.
- Increases inter-team harmony: Product, software, information security, legal, and compliance teams can pursue the same goal within the same workflow.
- Facilitates supplier and external service management: Contract and control expectations become clearer as the ‘privacy expectation’ is more explicitly translated into technical and operational requirements.
- Reduces loss of control in change management: Privacy requirements are revisited and kept up to date when introducing new features, new integrations, or process changes.
- Contributes to trust and reputation: The organisation can demonstrate that it manages privacy objectives in a planned and traceable manner, not randomly.
ISO/IEC 27561 Who is it important for?
- Product owners and product managers: Clarification of privacy objectives in product requirements and the creation of a common language across teams.
- Software development, architecture and testing teams: Methodological support for linking privacy principles to control needs and capabilities.
- Information security and cybersecurity teams: A reference approach for an implementation framework where privacy controls are addressed alongside security requirements.
- Compliance, legal, and GDPR teams: Contributing to the establishment of a traceable structure for the technical implementation of principles.
- Teams working with supply chains and external service providers: More clearly defining control expectations and translating them into technical requirements language.
CFECERT offers audit, gap analyses, and training services to support the implementation of ISO/IEC 27561 within your organisation.
You can contact us at info@cfecert.co.uk to jointly determine the appropriate roadmap in line with your organisation’s targeted scope and programmes, and to integrate it into your organisation.