Search results

Guest

Guest

Create New Topic As guest or Sign in

HTML tags are not allowed

Assign topic to the user

  • SOA Table ISO 27018 specific controls for processing Personally Identifiable Information (PII)

    From your question, I’m assuming by renumbered clauses you mean the clauses related to the reviewed controls in ISO 27002 standard, released in February 2022.

    Considering that, please note that the ISO 27001, 27017 & 27018 toolkit is based on ISO 27001 standard, and a new version of this standard is expected to be released only in May 2022.

    ISO 27002 is only a supporting standard to implement ISO 27001, and it is not mandatory to implement ISO 27001.

    The new toolkit, with the templates updated according to the new standard, will be released as soon as the new standard is published, and customers that bought the toolkit in the last 12 months before the standard’s release date will receive the updated documents free of charge.

    After publication, organizations will have a transition time (defined by the time of the release of the new standard) to change their controls and documentation to the new standard, so you will have plenty of time to make your changes. The transition period is probably going to be 24 months.

    To see how the new controls numbering of ISO 27002:2022 are related to the controls numbering from ISO 27002:2019, please see this free to download the whitepaper:
    - Overview of new security controls in ISO 27002:2022 https://info.advisera.com/27001academy/free-download/overview-of-new-security-controls-in-iso-27002/

  • Use of SCCs and TOMs

    It is important to know the entity that offers the service to your customers. If it is the US entity, a transfer takes place because you manage your Google Cloud Platform instance so you have access to that personal data as a service provider. In its “Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR”, the European Data Protection Board gives three conditions for an international personal data transfer to take place:

    • A controller or a processor is subject to the GDPR for the given processing
    • This controller or processor (“exporter”) discloses by transmission or otherwise makes personal data, subject to this processing, available to another controller, joint controller, or processor (“importer”).
    • The importer is in a third country or is an international organization, irrespective of whether or not this importer is subject to the GDPR in respect of the given processing in accordance with Article 3
       

    So if the US company is signing the contract with your EU customer, you should sign Standard Contractual Clauses (SCC) with additional Technical and Organizational Measures (TOM), to demonstrate protection of personal data from access by US authorities. If you have an EU company under control signing the contract with your EU customer, you don’t need to sign an SCC. However you must check whether your US company falls under FISA 702, in which case you should adopt additional TOMs to demonstrate protection of personal data from access by US authorities, and add them to the standard Data Protection Agreement. Also I recommend performing a DPIA regarding these transfers.

    Please consult these links as well:

  • What rules should be applied to 3D printed - patient specific products?

    The biggest question here is what is the intended purpose of the device. Depending on the purpose of the product, and thus the classification of the product, it depends on whether it is necessary to put the CE mark on the product and what documentation needs to be prepared.

    Only implantable and Class III custom-made products require the affixing of the CE mark and the inclusion of a Notify body in the whole process. For all other classes, it is sufficient to prepare technical documentation for the product as described in Annex 13.

    For more information, see:

    • EU MDR Annex 13 - Procedure for custom made devices - https://advisera.com/13485academy/mdr/procedure-for-custom-made-devices/

    • Question - ISO 27001

      1. How do you put in place HR systems when there are no employees ? Would this be more about Supplier management ? and supplier worker management ?

      Since your customer uses contractors, his relationship with them and their employees will be through supplier management, so regarding ISO 27001 implementation, this will mostly cover controls from ISO 27001 Annex A section 15 Supplier relationships.

      For further information, see:

      2.  With Software Development - Would they either:  (a) require suppliers to follow his requirements or ISO Compliant software development manuals. OR.  (b)  require the subsidiary to produce there software development manual (which meets the requirements of ISO 27001) – which he approves?

      In this situation first, you need to ensure, by means of security clauses in contracts or service agreements, that risks you consider relevant, and legal requirements applicable to his organization, related to software development are properly treated by the supplier.

      Considering that, alternative (a) is more adequate because in alternative (b) you only consider the standard's requirements, not those of your customer.

      These articles will provide you with further explanation about security clauses and software development:

    • SOP in ISO 9001

      Do you know when you O d on it best place to buy generic cialis online
    • Dental burs

      На этом ресурсе вы сможете найти ценную информацию. https://relax-spb.ru/read-info/1205-tyomnye-teni-podlinnosti-kak-vdova-ernsta-neizvestnogo-predvidela-falsifikatsiyu-na-vystavke.html
    • ISO 27001 implementation requirement

      First is important to note that ISO 27001 does not specify the PDCA cycle.

      Please note that the best practice is to consider Risk assessment as part of the Plan phase, since its main objective is to identify and prioritized relevant risks to be treated, so you can plan why controls to implement.

      In the Do phase, you implement and operates the controls.

      This article will provide you a further explanation about ISO 27001 and PDCA cycle:
      - Has the PDCA Cycle been removed from the new ISO standards? https://advisera.com/27001academy/blog/2014/04/13/has-the-pdca-cycle-been-removed-from-the-new-iso-standards/

    • Can private hardware used for business purposes be excluded from the scope?

      ISO 27001/ISO 27017/ISO 27018 allow the usage of private hardware, and you can exclude this hardware from the ISMS scope - this is pretty common in companies that have remote workers. 

      Once you specify in your ISMS scope document that private hardware is out of the scope, you need to ensure compliance with security rules by signing agreements with workers that use such hardware where you will specify specific security rules for using such hardware.

      In your toolkit, you will find the document "Security clauses for suppliers and partners" in folder 08 Annex A Security Controls - A.15 Supplier relationships - you can use clauses from this document in the agreement with your workers.

    • Device asset tracking

      ISO 27001 does not prescribe information to be used to track an asset, so organizations can define the information they see best fits their needs.

      In general, for tracking an asset you should consider information that is unique for each asset, and the serial number information fits these criteria, so it is a good choice for tracking information.

      This article will provide you with a further explanation of asset management:

Page 96 of 1130 pages

Didn’t find an answer?

Start a new topic and get direct answers from the Expert Advice Community.

CREATE NEW TOPIC +