Expert Advice Community

Guest

GDPR and ISO Compliance

  Quote
Guest
Guest user Created:   May 08, 2020 Last commented:   May 08, 2020

GDPR and ISO Compliance

I have heard a lot about GDPR and how much it restricts the privacy of PII. in my case I have a proxy web server that has many back services behind it, one of those backend services uses something called BasicAuthentication to authenticate the user, in basic-authentication the user submit has username and password and these being base64 encoded on the request header, the point is my proxy logs the username from that header on the audit log, so if the user is admin then I'll log User: Admin on my log,

does this prohibit in GDPR or ISO 27k? noting that I'm logging this info for security reasons.

0 0

Assign topic to the user

EU GDPR & ISO 27001 INTEGRATED DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

EU GDPR & ISO 27001 INTEGRATED DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 08, 2020

ISO 27001 does not prescribe restrictions about the use of PII, only that privacy and PII must be ensured considering applicable legal requirements, in case-control A.18.1.4 - Privacy and protection of personally identifiable information is applicable to your organization.

Now, GDPR lets the data controller evaluate and balance the risk of security measures taken. There is a presumption of adequacy of encrypted data and encouraging Multi Factors Authentication. Of course, Article 32 GDPR on security measures requires the data controller to balance risks for the freedom and rights of data subjects with the state of art, cost of implementation and nature, scope, purposes of processing in order to determine the right level of security.

These articles will provide you a further explanation about ISO 27001 and GDPR: 

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 08, 2020

May 08, 2020