SlideShare a Scribd company logo
4
Most read
8
Most read
11
Most read
Managing Information Asset Register

                          By
                 Ben Oguntala. LLB, LLM
         Ben.oguntala@dataprotectionofficer.com
How many Information data do you have, what are they and with whom are they shared?


                                                                                 1
Our 5 simple steps
1      Define the key stakeholders

2   Create your IAR & supplier register


3   Map current IAR to Suppliers & ISA

4     Create the relevant processes


5            Solution roll out

                                      2
Overview of the framework
        Privacy             Compliance               Information                                              THE KEY STAKEHOLDERS
                                                                              Business units
         team                 team                     security                                               Access given these teams
                                                                                                              to ensure a consolidated
                                                                                                              coverage.

     www.dataprotectionofficer.com                                                         CREATE YOUR IAR/PR/3PR & ISA
                                                                                           The databases provided:
                                                                                           - IAR – information Asset register
                                                   3rd party
                                  register




                                                   register
                                  Project




                                                                                           - Project register
                   IAR




                                                                       ISA
                                                                                           - 3rd party register
                                                                                           - ISA – information sharing agreements




            Business unit 1                                     Business unit 2                              Business unit 2

 Projects     IAR        3rd parties         ISA     Projects     IAR        3rd parties   ISA    Projects     IAR   3rd parties   ISA

   13          9             12              6           13        9             12         6       13          9        12        6



                                                                                                                                       3
        Business units can be structured according to the hierarchy of your organisation
1               Define the key stakeholders

    Team                      Role                         Benefits


Procurement                                     Procurement are best placed
                       Supply of the list of
    team                                        to know which suppliers you
                           suppliers
                                                         deal with

                                                As part of compliance the ISA
Privacy team         Supply the ISA template,
                                                is used with all 3rd party data
                         PIA & approval
                                                         exchanges.

 Compliance                                       Compliance ensures all
                       Supply compliance
   team                                         policies and procedures are
                           baseline
                                                         adhered to.

 Information                                     Play an operational role in
                     Supply risk assessment
   security                                     assessing projects & changes
                            function
                                                    to your organisation


Business units         Supply Information         All business units listed
                        Assets projects &       including sub business units
                            changes                     and Partners
                                                                                  4
2      Create your IAR & supplier register

    Team             Role




                                        3rd party
                                        register
Procurement      Supply of the
    team             list of
                   suppliers

                 Supply the ISA
Privacy team     template, PIA




                                          ISA
                  & approval

 Compliance         Supply
   team           compliance




                                          IAR
                   baseline

 Information      Supply risk
   security       assessment
                   function



                                        register
                                        Project
                     Supply
Business units    Information
                     Assets
                   projects &
                    changes                              5
2   Create your IAR & supplier register

Business unit: Organisation hierarchy




                                          6
2   Create your IAR & supplier register

       The Asset Register

                    Buena Ventura




                                          7
2          Create your IAR & supplier register

          Editing the Information Asset Register
                                                          Risk impact assessment




Asset details include format, location, input & output.                       8
3   Map current IAR to Suppliers & ISA




                         List of 3rd parties that the
                         information asset is shared with




      Detailed view

                             3rd
                           parties




                                                    9
3          Map current IAR to Suppliers & ISA

                      Details of the Asset Register
                                                                       3rd
                                                                     parties




                                                                                              10
Each asset is risk assessed, classified, owner assigned and no. of 3rd parties shared with listed
4              Create the relevant processes
                                List of Information
                                       Assets
                     IAR
                                New information




                                                                             IAR
                                Asset registration
                                  Project/Asset           IAR       87
                                    mapping
                                                      Projects      32


    Business       Projects




                                                                             Projects
                                  New/change
     units                          project


                                Project/asset/sup
                  3rd parties     plier mapping




                                                                           parties
                                                                             3rd
                                  New supplier
                                   registration
                                                                 Project




                                                                                        ISA
                                   Compliance
                     ISA
                                                       Information asset
                                                                                        11
4                  Create the relevant processes
                       Risk rating                                                                  Incident
                    Types of assets                                                               management




                                               Information
Business




                                                                             3rd party
                                                                             supplier
                                                 register
                                                                                               Information security




                                                  Asset
  unit




                                                                                                                              3rd parties
                   Total no. of Assets                                                              compliance
                     Project/Asset                                                               Data Protection
                                                                                                     officer
                    Types of assets
                                                                                                  Project/Asset
                                           • Privacy impact assessment
                                           • contract
                                           • Information sharing agreement

                                                        Privacy team

    Business units        Asset ID    Owner     Classification      Record type          ISA        Suppliers     Review date


            HR              901      A smut      Restricted      Full customer info      5            MOJ          23/09/10

           Sales            789       S Red     Unrestricted     Customer financials     7           OMG           13/12/10

       Marketing            456       N Ball      financial          Customer            3           Detica        02/06/11

     Procurement            123       W Ed       Restricted         Record type          1           Logica        04/01/11
                                                                                                                          12
5                        Solution roll out


           Business unit 1             Stakeholders

Projects     IAR   3rd parties   ISA
                                       Procurement
  13          9        12        6
                                           team
           Business unit 2

                                       Privacy team




                                                                Phased roll out
Projects     IAR   3rd parties   ISA




                                                                                  Operation
  13          9        12        6




                                                        Pilot
           Business unit 3              Compliance
                                          team
Projects     IAR   3rd parties   ISA

  13          9        12        6
                                        Information
           Business unit 4                security

Projects     IAR   3rd parties   ISA

  13          9        12        6     Business units
                                                                                              13
Contact details
To know what Information Assets you have and
  with whom you are sharing them, contact

•   Ben Oguntala, LLB, LLM
•   Ben.oguntala@dataprotectionofficer.com
•   07812 039 867
•   www.dataprotectionofficer.com

                                               14

More Related Content

DOCX
Information Asset Management...Comply for less!!
PDF
Data Governance Best Practices
PDF
Building an effective Information Security Roadmap
PDF
The Data Trifecta – Privacy, Security & Governance Race from Reactivity to Re...
PDF
Data Analytics Strategy
PPTX
Enterprise Security Architecture Design
PDF
Five Things to Consider About Data Mesh and Data Governance
PPT
Data Classification Presentation
Information Asset Management...Comply for less!!
Data Governance Best Practices
Building an effective Information Security Roadmap
The Data Trifecta – Privacy, Security & Governance Race from Reactivity to Re...
Data Analytics Strategy
Enterprise Security Architecture Design
Five Things to Consider About Data Mesh and Data Governance
Data Classification Presentation

What's hot (20)

PDF
Security operations center-SOC Presentation-مرکز عملیات امنیت
PDF
DMBOK and Data Governance
PPTX
ITSM and Service Catalog Overview
PPTX
Business Drivers Behind Data Governance
PPTX
TOP_407070357-Data-Governance-Playbook.pptx
PDF
Future Proofing Your IT Operating Model for Digital
PDF
Databricks: A Tool That Empowers You To Do More With Data
PPTX
Azure Sentinel with Office 365
PDF
Digital Transformation Strategy PowerPoint Presentation Slides
PDF
Getting Started: Data Factory in Microsoft Fabric (Microsoft Fabric Community...
PDF
ITIL,COBIT and IT4IT Mapping
PDF
Boldon James - How Data Classification can harness the power of Big Data
PPTX
Business intelligence competency centre strategy and road map
PDF
Data Products and teams
PDF
Data Catalogs Are the Answer – What is the Question?
PDF
Information Asset Registers: A Short Guide
PDF
Azure Information Protection
PDF
Digital Operating Model & IT4IT
PDF
Request to Fulfill Presentation (IT4IT)
PPT
ITS Managed Services Introduction
Security operations center-SOC Presentation-مرکز عملیات امنیت
DMBOK and Data Governance
ITSM and Service Catalog Overview
Business Drivers Behind Data Governance
TOP_407070357-Data-Governance-Playbook.pptx
Future Proofing Your IT Operating Model for Digital
Databricks: A Tool That Empowers You To Do More With Data
Azure Sentinel with Office 365
Digital Transformation Strategy PowerPoint Presentation Slides
Getting Started: Data Factory in Microsoft Fabric (Microsoft Fabric Community...
ITIL,COBIT and IT4IT Mapping
Boldon James - How Data Classification can harness the power of Big Data
Business intelligence competency centre strategy and road map
Data Products and teams
Data Catalogs Are the Answer – What is the Question?
Information Asset Registers: A Short Guide
Azure Information Protection
Digital Operating Model & IT4IT
Request to Fulfill Presentation (IT4IT)
ITS Managed Services Introduction
Ad

Viewers also liked (8)

PPTX
Data/File Security & Control
PDF
Using an Information Asset Register for the GDPR
PPTX
Fixed Asset Management by YENNES Infotec (P) Limited
PPT
Real-World Data Governance: Managing Data & Information as an Asset - Governa...
PPTX
Fixed asset management
PPTX
Accounting for fixed assets (as 10)
PPTX
Asset Management Presentation
PPT
SAP - FIXED ASSETS ACCOUNTING
Data/File Security & Control
Using an Information Asset Register for the GDPR
Fixed Asset Management by YENNES Infotec (P) Limited
Real-World Data Governance: Managing Data & Information as an Asset - Governa...
Fixed asset management
Accounting for fixed assets (as 10)
Asset Management Presentation
SAP - FIXED ASSETS ACCOUNTING
Ad

Similar to Managing Information Asset Register (20)

PDF
Business: Security & Privacy
PDF
Privacy Impact Assessment Final
PPTX
3.12 external and internal resources
PPTX
BiSL Introduction Eng 2010
PPTX
BiSL introduction ENG
PPTX
Electronic data & record management
PPT
Sap introduction
PDF
Sage er px3-puerto rico
PDF
Asset information management an it perspective b mick arc 2008
PDF
Itam Presentation by Cydney Davis
PPT
Where is your key business information?
PPT
Sharepoint & TRIM integration
PDF
The Effective eDocument Retention Program - Policies, Processes and Solutions
PPTX
The Project Network - Service Offering
PPTX
Code objects overview sep 2012
PPTX
Code objects overview sep 2012
PDF
SharePoint Saturday - Putting Paper to Work
PDF
Dilip sadh mm wm overview
PDF
Hacking Trust
PDF
Plugin ch12edited-ok
Business: Security & Privacy
Privacy Impact Assessment Final
3.12 external and internal resources
BiSL Introduction Eng 2010
BiSL introduction ENG
Electronic data & record management
Sap introduction
Sage er px3-puerto rico
Asset information management an it perspective b mick arc 2008
Itam Presentation by Cydney Davis
Where is your key business information?
Sharepoint & TRIM integration
The Effective eDocument Retention Program - Policies, Processes and Solutions
The Project Network - Service Offering
Code objects overview sep 2012
Code objects overview sep 2012
SharePoint Saturday - Putting Paper to Work
Dilip sadh mm wm overview
Hacking Trust
Plugin ch12edited-ok

More from Ben Omoakin Oguntala, developingafrica(dot)net (15)

PDF
Developing Africa Ode Remo brochure
PDF
PDF
PDF
Africa secretariat - The Home of African raw materials
PDF
Risk Assessment And Risk Treatment
PDF
Data Protection Compliance In Economically Depressing Times
PDF
Conformidad De Seguridad De InformacióNv2
PDF
Iso 27001 Audit Evidence Acquisitionv3
PDF
Iso 27001 Audit Evidence Acquisition
Developing Africa Ode Remo brochure
Africa secretariat - The Home of African raw materials
Risk Assessment And Risk Treatment
Data Protection Compliance In Economically Depressing Times
Conformidad De Seguridad De InformacióNv2
Iso 27001 Audit Evidence Acquisitionv3
Iso 27001 Audit Evidence Acquisition

Managing Information Asset Register

  • 1. Managing Information Asset Register By Ben Oguntala. LLB, LLM Ben.oguntala@dataprotectionofficer.com How many Information data do you have, what are they and with whom are they shared? 1
  • 2. Our 5 simple steps 1 Define the key stakeholders 2 Create your IAR & supplier register 3 Map current IAR to Suppliers & ISA 4 Create the relevant processes 5 Solution roll out 2
  • 3. Overview of the framework Privacy Compliance Information THE KEY STAKEHOLDERS Business units team team security Access given these teams to ensure a consolidated coverage. www.dataprotectionofficer.com CREATE YOUR IAR/PR/3PR & ISA The databases provided: - IAR – information Asset register 3rd party register register Project - Project register IAR ISA - 3rd party register - ISA – information sharing agreements Business unit 1 Business unit 2 Business unit 2 Projects IAR 3rd parties ISA Projects IAR 3rd parties ISA Projects IAR 3rd parties ISA 13 9 12 6 13 9 12 6 13 9 12 6 3 Business units can be structured according to the hierarchy of your organisation
  • 4. 1 Define the key stakeholders Team Role Benefits Procurement Procurement are best placed Supply of the list of team to know which suppliers you suppliers deal with As part of compliance the ISA Privacy team Supply the ISA template, is used with all 3rd party data PIA & approval exchanges. Compliance Compliance ensures all Supply compliance team policies and procedures are baseline adhered to. Information Play an operational role in Supply risk assessment security assessing projects & changes function to your organisation Business units Supply Information All business units listed Assets projects & including sub business units changes and Partners 4
  • 5. 2 Create your IAR & supplier register Team Role 3rd party register Procurement Supply of the team list of suppliers Supply the ISA Privacy team template, PIA ISA & approval Compliance Supply team compliance IAR baseline Information Supply risk security assessment function register Project Supply Business units Information Assets projects & changes 5
  • 6. 2 Create your IAR & supplier register Business unit: Organisation hierarchy 6
  • 7. 2 Create your IAR & supplier register The Asset Register Buena Ventura 7
  • 8. 2 Create your IAR & supplier register Editing the Information Asset Register Risk impact assessment Asset details include format, location, input & output. 8
  • 9. 3 Map current IAR to Suppliers & ISA List of 3rd parties that the information asset is shared with Detailed view 3rd parties 9
  • 10. 3 Map current IAR to Suppliers & ISA Details of the Asset Register 3rd parties 10 Each asset is risk assessed, classified, owner assigned and no. of 3rd parties shared with listed
  • 11. 4 Create the relevant processes List of Information Assets IAR New information IAR Asset registration Project/Asset IAR 87 mapping Projects 32 Business Projects Projects New/change units project Project/asset/sup 3rd parties plier mapping parties 3rd New supplier registration Project ISA Compliance ISA Information asset 11
  • 12. 4 Create the relevant processes Risk rating Incident Types of assets management Information Business 3rd party supplier register Information security Asset unit 3rd parties Total no. of Assets compliance Project/Asset Data Protection officer Types of assets Project/Asset • Privacy impact assessment • contract • Information sharing agreement Privacy team Business units Asset ID Owner Classification Record type ISA Suppliers Review date HR 901 A smut Restricted Full customer info 5 MOJ 23/09/10 Sales 789 S Red Unrestricted Customer financials 7 OMG 13/12/10 Marketing 456 N Ball financial Customer 3 Detica 02/06/11 Procurement 123 W Ed Restricted Record type 1 Logica 04/01/11 12
  • 13. 5 Solution roll out Business unit 1 Stakeholders Projects IAR 3rd parties ISA Procurement 13 9 12 6 team Business unit 2 Privacy team Phased roll out Projects IAR 3rd parties ISA Operation 13 9 12 6 Pilot Business unit 3 Compliance team Projects IAR 3rd parties ISA 13 9 12 6 Information Business unit 4 security Projects IAR 3rd parties ISA 13 9 12 6 Business units 13
  • 14. Contact details To know what Information Assets you have and with whom you are sharing them, contact • Ben Oguntala, LLB, LLM • Ben.oguntala@dataprotectionofficer.com • 07812 039 867 • www.dataprotectionofficer.com 14