Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... plicants CVs) by establishing a principle in line with the period the data controller may need those data (i.e. until the job position has been covered).Therefore, specifications for data retention schedules may vary from case to case depending on the data processing.
You can find more information here:- The role of the DPO in light of the General Data Protection Regulation: https://advisera.com/eugdpracademy/knowledgebase/the-role-of-the-dpo-in-light-of-the-general-data-protection-regulation/- How the GDPR could impact your HR department: https://advisera.com/eugdpracademy/blog/2018/02/22/how-the-gdpr-could-impact-your-hr-department/- Implementing 3 main accountability principles under the EU GDPR: https://advisera.com/eugdpracademy/blog/2017/09/27/implementing-3-main-accountability-principles-under-the-eu-gdpr/- Understanding 6 key GDPR principles: https://advisera.com/eugdpracademy/knowledgebase/understanding-6-key-gdpr-principles/
... ting risk vs current controls?
Please note that there is no sequence here.
Since current controls have a direct influence on impact and likelihood, the components of the risk, the risk, and current controls have to be assessed at the same time.
For example for the risk of data loss, if you already have a backup solution implemented, it does not make sense to evaluate the risk of data loss without considering the backup. This would result in an unrealistic risk and unnecessary work to evaluate the risk again, now considering the control. The proper approach is to consider the risk of data loss considering the effects of the backup solution.
... ollected CVs from job applicants are deleted as soon as the job position has been covered. From this principle comes the rule to HR department "delete every CV you received as soon as the selected candidates start working and no later than the trial period ends." Therefore, in this example, there is a GDPR principle (data minimization), a company principle (collected CVs must be deleted) and a rule for the HR department.
In other words, Data protection policy explains how employees and company will process data and, though it is not directed to customer, it helps Supervisory Authority to verify that anything is declared in the Privacy policy (i.e. how data are processed) is coherent with principles and instruction given to employees, and with the internal company interpretation of GDPR. This is why the correct answer is d. All of the above.
For more information, see the following article:
Is it Ok to consider FAI as a subsitute of Design Validation?
... sk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
2. With regards to the risk categories, do you know which one a power surge or a loss of power would fall under?
Considering common definitions used for STEEPCOIL: the most adequate category for power surge and loss of power would be organizational risks because it covers risks related to structure and ownership assets responsible for the establishment and operation of a process facility (e.g., a power plant, or electricity company).
I have a question regarding asset list/inventory. We are creating the list of assets for the Risk Assessment and Risk Treatment process. Once that list is complete and we come up with threats and vulnerabilities for each, is there any need for a separate list of assets as in A.8.1 Inventory of Assets?
I know that you have stated that "assets are not only the information in electronic and paper form, but also software, hardware, services, people, facilities, and everything else that provides value to an organization.", so I have a question on that as well:
Our company is using a consulting group that has an online tool for managing all records and policies, but it seems to define assets stictly as devices. Also, risks are listed separately and are linked only to "category type" not to a specific detail asset.
We are developing a mobile app where we scan documents, ask for data in forms and use blockchain.
We want to make sure we comply with GDPR. Especially around:
-data retention, is hashing data enough?
-anonymized vs pseudonymized. Are we understanding it correctly?
-data access by personell. Is it ok that developers and database admin can see some of the data
-how to know when data is misused, mis-accessed, or breached
-are we a data processor or controller?
Can I do iso 14001:2015 myself or I need any consultant?
... ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
My second question is : Can a company say that it is certified for the information security management for the cloud computing services just with the ISO 27001/27002?
ISO 27001 has enough security controls to allow an organization to be certified considering cloud computing services in its ISMS scope. You only would need to include controls from ISO 27017 if your organization has specific requirements demanding the implementation of ISO 27017 controls (e.g., laws, regulations or contracts).
This article will provide you further explanation about ISMS scope: