Ilmainen e-kirja: NIS2 haltuun hyödyntäen ISO 27001 -käytäntöjä
Lataa e-kirja

Vaatimuskehikkoon sisältyvät vaatimukset

A.7.4.3
ISO 27701

Accuracy and quality

A.7.4.4
ISO 27701

PII minimization objectives

A.7.4.5
ISO 27701

PII de-identification and deletion at the end of processing

A.7.4.6
ISO 27701

Temporary files

A.7.4.7
ISO 27701

Retention

A.7.4.8
ISO 27701

Disposal

A.7.4.9
ISO 27701

PII transmission controls

A.7.5
ISO 27701

PII sharing, transfer, and disclosure

A.7.5.1
ISO 27701

Identity basis for PII transfer between jursdictions

A.7.5.2
ISO 27701

Countries and international organizations to which PII can be transferred

A.7.5.3
ISO 27701

Records of transfer of PII

A.7.5.4
ISO 27701

Records of PII disclosure to third parties

A.8
ISO 27701

Additional ISO/IEC 27002 guidance for PII processors

A.8.2
ISO 27701

Conditions for collection and processing

A.8.2.1
ISO 27701

Customer agreement

A.8.2.2
ISO 27701

Organization's purposes

A.8.2.3
ISO 27701

Marketing and advertising use

A.8.2.4
ISO 27701

Infringing instruction

A.8.2.5
ISO 27701

Customer obligations

A.8.2.6
ISO 27701

Records related to processing PII

A.8.3
ISO 27701

Obligations to PII principals

A.8.3.1
ISO 27701

Obligations to PII principals

A.8.4
ISO 27701

Privacy by design and privacy by default

A.8.4.1
ISO 27701

Temprorary files

ISO 27701

ISO 27701 is a privacy extension to ISO 27001. The framework aims to upgrade the existing Information Security Management System (ISMS) with additional requirements related to processing and protecting personal data in order to establish also a Privacy Information Management System (PIMS).

  • Documentation related to processing activities, transfers and disclosures of personal data.
  • Tasks related to data subject rights and ensuring lawfulness of processing.
  • Advanced privacy-related tasks about ensuring proper consent and filling other requirements for personal data controllers and processors.

Certifications are available for ISO 27701. As the framework extends ISO 27001, organizations seeking an ISO 27701 certification will need to have the ISO 27001 certification.

Vaatimuskehikon teema-alueet

No items found.