Skip main navigation
Committee

Committee:

CTN 320 - Cybersecurity, privacity and data protection

Secretary:
UNE - ASOCIACIÓN ESPAÑOLA DE NORMALIZACIÓN
Field of Activity:
Standardization of:Cybersecurity, information protection, and data protection covering: - Management systems and frameworks for cybersecurity and information security. - Technical security mechanisms including cryptography, security controls, and protection methods for ICT systems, networks, and devices. - Data protection and privacy including privacy by design and identity management. - Security evaluation and assessment standards for organizations of all sizes. - Competence requirements for cybersecurity and data protection professionals. - Guidelines and methodologies for emerging technologies and regulatory compliance. Scope covers all aspects of the evolving digital information society, from foundational security mechanisms to practical implementation for large enterprises and SMEs.
Structure:

SC 1 Cybersecurity management systems

SC 2 Cryptography and security mechanisms

SC 3 Security evaluation, testing and specification

SC 4 Security services

SC 5 Data protection, privacy and identity management

SC 6 Product security

SC 7 Cryptografy

GT CAV Cybersecurity in automotive (mobility)

GT CIOT IOT cybersecurity

GT CIOT2 Secure IoT-Blockchain Architecture Model

International Relations:

ISO/IEC/JTC 1/SC 27  Information security, cybersecurity and privacy protection

ISO/IEC/JTC 1/SC 44  Consumer protection in the field of privacy by design

CEN/CLC/JTC 13  Cybersecurity and Data Protection

Standards developed by the committee: CTN 320: 89

UNE-ISO/IEC 27000:2012

Status: ANULADA / 2019-02-20

Information technology. Security techniques. Information security management systems. Overview and vocabulary

UNE-ISO/IEC 27002:2009

Status: ANULADA / 2017-05-24

Information Technology. Code of practice for information security management

UNE-ISO/IEC 27002:2015

Status: ANULADA / 2017-05-24

Information technology -- Security techniques -- Code of practice for information security controls

UNE-ISO/IEC 27001:2007/1M:2009

Status: ANULADA / 2017-05-24

Information technology. Security techniques. Information security management systems. Requirements.

UNE-ISO/IEC 27001:2007

Status: ANULADA / 2017-05-24

Information technology. Security techniques. Information security management systems. Requirements. (ISO/IEC 27001:2005)

UNE-ISO/IEC 27001:2014/COR 1:2015

Status: ANULADA / 2017-05-24

Information technology. Security techniques. Information security management systems. Requirements

UNE-ISO/IEC 27001:2014

Status: ANULADA / 2017-05-24

Information technology -- Security techniques -- Information security management systems -- Requirements

UNE-ISO/IEC 17799:2002

Status: ANULADA / 2009-12-09

Information Technology. Code of practice for information security management.

UNE 71502:2004

Status: ANULADA / 2008-12-31

Specifications for Information Security Management Systems (ISMS)