A cloud customer wants to select the standard that provides a code of practice for protecting personally identifiable information processed by public cloud providers acting as processors. Which standard is the correct choice?
- AISO/IEC 27018, which provides a code of practice for protecting PII in public clouds acting as processors. Correct
- BISO/IEC 27017, which provides cloud-specific information security controls guidance.
- CISO/IEC 27001, which specifies requirements for an information security management system.
- DNIST SP 800-145, which provides the reference definition of cloud computing.
Why A is correct: ISO/IEC 27018 is the code of practice specifically for protection of personally identifiable information in public clouds that act as PII processors, matching the requirement exactly.
Why B is wrong: ISO/IEC 27017 addresses cloud security controls generally and is easy to confuse here, but it is not the standard focused on protecting PII in public clouds.
Why C is wrong: ISO/IEC 27001 sets out ISMS requirements broadly and is not the PII-in-public-cloud code of practice being sought.
Why D is wrong: NIST SP 800-145 defines cloud computing and its service and deployment models; it says nothing about protecting PII as a processor.