Infoteenus
03 TEENUSED. ETTEVÕTTE ORGANISEERIMINE, JUHTIMINE JA KVALITEET. HALDUS. TRANSPORT. SOTSIOLOOGIA
Uued standardid
EVS-EN ISO/IEC 27017:2026
Information security, cybersecurity and privacy protection - Information security controls based on ISO/IEC 27002 for cloud services (ISO/IEC 27017:2026)
Käsitlusala: This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
- additional guidance for relevant controls specified in ISO/IEC 27002:2022;
- additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
- additional guidance for relevant controls specified in ISO/IEC 27002:2022;
- additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Alusdokumendid: ISO/IEC 27017:2026; EN ISO/IEC 27017:2026
Asendab: EVS-EN ISO/IEC 27017:2021
EVS-EN 18274:2026
Competence requirements for professional AI ethicists
Käsitlusala: This document establishes a systematized framework for the competences of AI ethicists, categorizing them into knowledge, skills and attitudes related to the specific activities and tasks of the role. It specifies requirements and recommendations necessary for individuals to effectively perform as AI ethicists. These competences encompass a strong understanding of European values and fundamental rights, further enhancing the knowledge, skills and attitudes required for this profession.
This document defines the essential concepts and principles inherent to the AI ethicist role. It illustrates a clear, uniform approach to the integral components of this profession.
Moreover, the document outlines how the role of AI ethicists can be seamlessly integrated into a wide variety of organizations. These include, but are not limited to, commercial enterprises, governmental agencies and non-profit organizations.
This document defines the essential concepts and principles inherent to the AI ethicist role. It illustrates a clear, uniform approach to the integral components of this profession.
Moreover, the document outlines how the role of AI ethicists can be seamlessly integrated into a wide variety of organizations. These include, but are not limited to, commercial enterprises, governmental agencies and non-profit organizations.
Alusdokumendid: EN 18274:2026
CWA 18366:2026
Commercial ports - Guidelines and requirements for the green transition of passenger terminals
Käsitlusala: This reference document applies to passenger or mixed terminals in commercial ports. It applies regardless of the port authority or the management method. The area concerned is defined as the port public domain. This Workshop has developed a document that specifies requirements for the ecological transition of passenger commerce terminals. The requirements are means-based requirements that enable the achievement of better environmental performance but not results-based requirements.
Alusdokumendid: CWA 18366:2026
ISO 13528:2022/Amd 1:2026
Statistical methods for use in proficiency testing by interlaboratory comparison — Amendment 1
Käsitlusala: Amendment to ISO 13528:2022
Alusdokumendid:
ISO 25186:2026
Financial services — Methods for the generation and verification of card security codes
Käsitlusala: This document defines a method for generating and verifying card security codes (CSCs) using cipher-based message authentication code (CMAC) or keyed-hash message authentication code (HMAC).
Key management mechanisms associated with these processes are beyond the scope of this document.
Key management mechanisms associated with these processes are beyond the scope of this document.
Alusdokumendid:
ISO 21926:2026
Semantic data model for audit data services
Käsitlusala: This document aims to define a methodology and framework to build a sematic data model for audit data services (ADS), adapt it (by extensions), and convert it to exchange formats.
The methodology describes a standardized semantic structure for audit data, focusing on specifying object classes and their attributes and associations, how to decouple audit data from specific systems (ERP applications) and how to extract and exchange data uniformly for audits, and describes the methods used for this such as graph walk (from relational to hierarchical model), syntax binding (to technical formats), semantic binding (link to other standards).
The semantic data model applies to areas such as general ledger journal entries, accounts receivable, sales, accounts payable, purchasing, inventory (movement and data), and property, plant, and equipment, customs and indirect tax and payroll.
These areas are limited to the functional requirements set forth in ISO 21378, ISO 5401, and ISO 5405 and can be extended with future extensions to ISO 21378.
This document describes the methodology and framework, not the full implementation or concrete technical exchange standards.
The methodology describes a standardized semantic structure for audit data, focusing on specifying object classes and their attributes and associations, how to decouple audit data from specific systems (ERP applications) and how to extract and exchange data uniformly for audits, and describes the methods used for this such as graph walk (from relational to hierarchical model), syntax binding (to technical formats), semantic binding (link to other standards).
The semantic data model applies to areas such as general ledger journal entries, accounts receivable, sales, accounts payable, purchasing, inventory (movement and data), and property, plant, and equipment, customs and indirect tax and payroll.
These areas are limited to the functional requirements set forth in ISO 21378, ISO 5401, and ISO 5405 and can be extended with future extensions to ISO 21378.
This document describes the methodology and framework, not the full implementation or concrete technical exchange standards.
Alusdokumendid:
IEC 63223-1:2026
Management of network assets in power systems - Part 1: Overview, principles and terminology
Käsitlusala: IEC 63223-1:2026 provides an overview of asset management, its principles and value creation options for the management of network assets in power systems.
This document can be applied to all types of network assets and by all types and sizes of power network companies. The term power network company does not necessarily refer to legally structured companies.
In this document, network assets refer mainly to the physical assets of the electrical energy network, meaning items, equipment, or systems that have potential or actual value for the electric company and are part of the power lines and substations responsible for the transmission and distribution of electrical energy. Examples of network assets that can be included in the asset portfolio of a power network company are presented in IEC 63223-2:2026, 4.2.2.
This document can be applied to all types of network assets and by all types and sizes of power network companies. The term power network company does not necessarily refer to legally structured companies.
In this document, network assets refer mainly to the physical assets of the electrical energy network, meaning items, equipment, or systems that have potential or actual value for the electric company and are part of the power lines and substations responsible for the transmission and distribution of electrical energy. Examples of network assets that can be included in the asset portfolio of a power network company are presented in IEC 63223-2:2026, 4.2.2.
Alusdokumendid:
ISO 28037:2026
Determination and use of straight-line calibration functions
Käsitlusala: This document is concerned with linear, that is, straight-line, calibration functions that describe the relationship between two variables and , namely, functions of the form . Although many of the principles apply to more general types of calibration function, the approaches described exploit the simple form of the straight-line calibration function wherever possible.
Values of the parameters and are estimated based on measured data points , Various cases are considered relating to the nature of the uncertainties associated with these data. No assumption is made that the errors relating to the are homoscedastic (having equal variance), and similarly for the when the errors are not negligible.
Estimates of the parameters and are determined using least‑squares’ methods. The emphasis of this document is on using the method most appropriate for the type of measured data, that is, respecting the associated uncertainties. The most general type of covariance matrix associated with the measured data is treated, but important special cases that lead to simpler calculations are described in detail.
For all cases considered, methods for validating the use of the straight-line calibration functions and for evaluating the uncertainties and covariance associated with the parameter estimates are given.
The document also describes the use of the estimates of the calibration-function parameters and their associated uncertainties and covariance to predict a value of and its associated standard uncertainty given a measured value of and its associated standard uncertainty.
NOTE 1 The document does not give a general treatment of outliers in measured data, although the validation tests given can be used to indicate discrepant data. ISO 16269-4 can be consulted for guidance.
NOTE 2 The document describes a method to evaluate the uncertainties associated with the measured data when those uncertainties are known only up to a scale factor (see Annex D).
Values of the parameters and are estimated based on measured data points , Various cases are considered relating to the nature of the uncertainties associated with these data. No assumption is made that the errors relating to the are homoscedastic (having equal variance), and similarly for the when the errors are not negligible.
Estimates of the parameters and are determined using least‑squares’ methods. The emphasis of this document is on using the method most appropriate for the type of measured data, that is, respecting the associated uncertainties. The most general type of covariance matrix associated with the measured data is treated, but important special cases that lead to simpler calculations are described in detail.
For all cases considered, methods for validating the use of the straight-line calibration functions and for evaluating the uncertainties and covariance associated with the parameter estimates are given.
The document also describes the use of the estimates of the calibration-function parameters and their associated uncertainties and covariance to predict a value of and its associated standard uncertainty given a measured value of and its associated standard uncertainty.
NOTE 1 The document does not give a general treatment of outliers in measured data, although the validation tests given can be used to indicate discrepant data. ISO 16269-4 can be consulted for guidance.
NOTE 2 The document describes a method to evaluate the uncertainties associated with the measured data when those uncertainties are known only up to a scale factor (see Annex D).
Alusdokumendid:
Asendab: ISO/TS 28037:2010
ISO/IEC 27017:2026
Information security, cybersecurity and privacy protection — Information security controls based on ISO/IEC 27002 for cloud services
Käsitlusala: This document provides guidance for information security controls, based on ISO/IEC 27002, applicable to the provision and use of cloud services. This document provides:
additional guidance for relevant controls specified in ISO/IEC 27002:2022;
additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
additional guidance for relevant controls specified in ISO/IEC 27002:2022;
additional controls with guidance that specifically relate to cloud services.
This document provides controls and guidance for cloud service customers (CSCs) and cloud service providers (CSPs).
This document is considered to be a horizontal document as it provides a foundation and a common understanding of security regarding the provision and use of cloud services.
NOTE This document applies to all types of cloud deployment models including the private cloud. When applying this document to the private cloud, the controls and guidance of this document are applicable, although adjustments can be necessary to adapt to the relationships and abilities of an organization’s internal departments.
Alusdokumendid:
Asendab: ISO/IEC 27017:2015
Asendatud standardid
ISO/IEC 27017:2015
Information technology -- Security techniques -- Code of practice for information security controls based on ISO/IEC 27002 for cloud services
Käsitlusala: ISO/IEC 27017:2015 gives guidelines for information security controls applicable to the provision and use of cloud services by providing:
- additional implementation guidance for relevant controls specified in ISO/IEC 27002;
- additional controls with implementation guidance that specifically relate to cloud services.
This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers.
- additional implementation guidance for relevant controls specified in ISO/IEC 27002;
- additional controls with implementation guidance that specifically relate to cloud services.
This Recommendation | International Standard provides controls and implementation guidance for both cloud service providers and cloud service customers.
Alusdokumendid:
Asendatud: ISO/IEC 27017:2026
ISO/TS 28037:2010
Determination and use of straight-line calibration functions
Käsitlusala: ISO/TS 28037:2010 is concerned with linear, that is, straight-line, calibration functions that describe the relationship between two variables X and Y, namely, functions of the form Y = A + BX. Although many of the principles apply to more general types of calibration function, the approaches described exploit the simple form of the straight-line calibration function wherever possible.
Values of the parameters A and B are determined on the basis of measured data points (xi, yi), i = 1, ... , m. Various cases are considered relating to the nature of the uncertainties associated with these data. No assumption is made that the errors relating to the yi are homoscedastic (having equal variance), and similarly for the xi when the errors are not negligible.
Estimates of the parameters A and B are determined using least squares methods. The emphasis is on choosing the least squares method most appropriate for the type of measurement data, in particular methods that reflect the associated uncertainties. The most general type of covariance matrix associated with the measurement data is treated, but important special cases that lead to simpler calculations are described in detail.
For all cases considered, methods for validating the use of the straight-line calibration functions and for evaluating the uncertainties and covariance associated with the parameter estimates are given.
ISO/TS 28037:2010 also describes the use of the calibration function parameter estimates and their associated uncertainties and covariance to predict a value of X and its associated standard uncertainty given a measured value of Y and its associated standard uncertainty.
Values of the parameters A and B are determined on the basis of measured data points (xi, yi), i = 1, ... , m. Various cases are considered relating to the nature of the uncertainties associated with these data. No assumption is made that the errors relating to the yi are homoscedastic (having equal variance), and similarly for the xi when the errors are not negligible.
Estimates of the parameters A and B are determined using least squares methods. The emphasis is on choosing the least squares method most appropriate for the type of measurement data, in particular methods that reflect the associated uncertainties. The most general type of covariance matrix associated with the measurement data is treated, but important special cases that lead to simpler calculations are described in detail.
For all cases considered, methods for validating the use of the straight-line calibration functions and for evaluating the uncertainties and covariance associated with the parameter estimates are given.
ISO/TS 28037:2010 also describes the use of the calibration function parameter estimates and their associated uncertainties and covariance to predict a value of X and its associated standard uncertainty given a measured value of Y and its associated standard uncertainty.
Alusdokumendid:
Asendatud: ISO 28037:2026
CEN/TS 16937:2016
Nanotechnologies - Guidance for the responsible development of nanotechnologies
Käsitlusala: This Technical Specification provides a guidance for the responsible development of nanotechnologies taking into account:
- Board Accountability;
- Stakeholder Involvement;
- Worker Health and Safety;
- Benefits to and Risks for Public Health, Safety and the Environment;
- Wider Social and Ethical Implications and Impacts;
- Engagement with Business Partners;
- Transparency and Disclosure.
NOTE 1 This Technical Specification contributes to social responsibility as defined in ISO 26000:2010.
NOTE 2 Nanotechnology activities include industrial production, R&D, services, and marketing of products.
This Technical Specification neither covers labelling and advertising aspects nor is it intended for certification purposes, nor does it imply any legally binding agreements.
This Technical Specification intends to cover nanotechnology activities involving manufactured nanomaterials, and where relevant incidental nanomaterials.
- Board Accountability;
- Stakeholder Involvement;
- Worker Health and Safety;
- Benefits to and Risks for Public Health, Safety and the Environment;
- Wider Social and Ethical Implications and Impacts;
- Engagement with Business Partners;
- Transparency and Disclosure.
NOTE 1 This Technical Specification contributes to social responsibility as defined in ISO 26000:2010.
NOTE 2 Nanotechnology activities include industrial production, R&D, services, and marketing of products.
This Technical Specification neither covers labelling and advertising aspects nor is it intended for certification purposes, nor does it imply any legally binding agreements.
This Technical Specification intends to cover nanotechnology activities involving manufactured nanomaterials, and where relevant incidental nanomaterials.
Alusdokumendid: CEN/TS 16937:2016
Kavandid
prEN ISO/IEC 42006
Information technology - Artificial intelligence - Requirements for bodies providing audit and certification of artificial intelligence management systems (ISO/IEC 42006:2025)
Käsitlusala: This document specifies additional requirements to ISO/IEC 17021-1. The requirements contained in this document, when implemented, support the demonstration of competence, consistency and reliability by the bodies performing auditing and certification of an artificial intelligence management system (AIMS) according to ISO/IEC 42001 for organizations that provide, develop or use AI systems.
Certification of AIMS is a third-party conformity assessment activity (as described in ISO/IEC 17000:2020, 4.5), and bodies performing this activity are third-party conformity assessment bodies.
This document also provides the necessary information and confidence to customers about the way certification has been granted.
NOTE This document can be used as a criteria document for accreditation or peer assessment.
Certification of AIMS is a third-party conformity assessment activity (as described in ISO/IEC 17000:2020, 4.5), and bodies performing this activity are third-party conformity assessment bodies.
This document also provides the necessary information and confidence to customers about the way certification has been granted.
NOTE This document can be used as a criteria document for accreditation or peer assessment.
Alusdokumendid: ISO/IEC 42006:2025; prEN ISO/IEC 42006
prEN ISO/IEC 17065
Conformity assessment - Requirements for bodies certifying products, processes and services (ISO/IEC FDIS 17065:2026)
Käsitlusala: 1.1 This International Standard contains principles and requirements for the competence, consistency and impartiality of the certification of products (including services; see clause 3.3 of ISO/IEC 17000) and processes and for the bodies providing those activities. Certification bodies operating to this International Standard need not offer all types of product, service or process certification.
1.2 Certification of products, services and processes is a third party conformity assessment activity (see clause 5.5 of ISO/IEC 17000:2004). Bodies performing this activity are therefore third party conformity assessment bodies, (named in this standard "certification body/bodies").
Note 1 A certification body can be non-governmental or governmental (with or without regulatory authority).
Note 2 This International Standard can be used as a criteria document for accreditation or peer assessment or other assessment processes.
1.2 Certification of products, services and processes is a third party conformity assessment activity (see clause 5.5 of ISO/IEC 17000:2004). Bodies performing this activity are therefore third party conformity assessment bodies, (named in this standard "certification body/bodies").
Note 1 A certification body can be non-governmental or governmental (with or without regulatory authority).
Note 2 This International Standard can be used as a criteria document for accreditation or peer assessment or other assessment processes.
Alusdokumendid: ISO/IEC FDIS 17065; prEN ISO/IEC 17065
prEN 15221-6
Facility Management - Part 6: Area and space measurement
Käsitlusala: This document establishes a common basis for planning and design, area and space management, financial assessment, as well as a tool for benchmarking in the life cycle of the built asset. This document covers area and space measurement for existing owned or leased buildings as well as buildings in state of planning or development.
This document establishes a framework to deal with area and space measurement to promote both the entire life cycle information requirements and the digital technologies used by the industry. In addition, it defines clear terms and definitions as well as methods for measuring horizontal areas and volumes in buildings and/or parts of buildings, independent of their function.
This document establishes a framework to deal with area and space measurement to promote both the entire life cycle information requirements and the digital technologies used by the industry. In addition, it defines clear terms and definitions as well as methods for measuring horizontal areas and volumes in buildings and/or parts of buildings, independent of their function.
Alusdokumendid: prEN 15221-6
EVS-ISO 13528:2023/prA1:2026
Statistilised meetodid laboritevahelise võrdluse teel teostatavatel tasemekatsetel kasutamiseks
Käsitlusala: Standardi EVS-ISO 13528:2023 muudatus.
Alusdokumendid: ISO 13528:2022/Amd 1:2026