- What software is installed on all hardware owned by your Organisation?
- How is the software updated? (not updating your software can leave you vulnerable to cyber attacks – as Carphone Warehouse found out the hard way).
- Who is responsible for patch management & builds updates on your software applications?
- Where is your data kept within the organisation?
- How is the data protected?
- How informed are staff about the risks of out-of-date software, phishing attacks and the problems of sharing information online or via email?
- Do you need to initiate, update or refresh cyber-security awareness training for your staff?
- Under the GDPR, you have a general obligation to implement technical and organisational measures to show that you have considered and integrated data protection into your processing activities.
- Privacy by design has always been an implicit requirement of data protection that the ICO has consistently championed.
- The ICO has published guidance on privacy by design. We are working to update this guidance to reflect the provisions of the GDPR. In the meantime, the existing guidance is a good starting point for organisations.
No responses yet. Be the first to reply!
{{ctrlComment.postTotalComments}} responses
Load more responses