Ilmainen e-kirja: NIS2 haltuun hyödyntäen ISO 27001 -käytäntöjä
Lataa e-kirja

Vaatimuskehikkoon sisältyvät vaatimukset

A.8.4.2
ISO 27701

Return, transfer, or disposal of PII

A.8.4.3
ISO 27701

PII transmission controls

A.8.5
ISO 27701

PII sharing, transfer and disclosure

A.8.5.1
ISO 27701

Basis for PII transfer between jurisdictions

A.8.5.2
ISO 27701

Countries and international organizations to which PII can be transferred

A.8.5.3
ISO 27701

Records of PII disclosure to third parties

A.8.5.4
ISO 27701

Notification of PII disclosure requests

A.8.5.5
ISO 27701

Legally binding PII disclosures

A.8.5.6
ISO 27701

Disclosure of subcontractors used to process PII

A.8.5.7
ISO 27701

Engagement of subcontractor to process PII

A.8.5.8
ISO 27701

Change of subcontractor to process PII

ISO 27701

ISO 27701 is a privacy extension to ISO 27001. The framework aims to upgrade the existing Information Security Management System (ISMS) with additional requirements related to processing and protecting personal data in order to establish also a Privacy Information Management System (PIMS).

  • Documentation related to processing activities, transfers and disclosures of personal data.
  • Tasks related to data subject rights and ensuring lawfulness of processing.
  • Advanced privacy-related tasks about ensuring proper consent and filling other requirements for personal data controllers and processors.

Certifications are available for ISO 27701. As the framework extends ISO 27001, organizations seeking an ISO 27701 certification will need to have the ISO 27001 certification.

Vaatimuskehikon teema-alueet

No items found.