SlideShare a Scribd company logo
Delivering	the	best	in	z	services,	software,	hardware	and	training.Delivering	the	best	in	z	services,	software,	hardware	and	training.
Delivering	the	best	in	z	services,	skills,	security	and	software.
GDPR	– What	Does	It	Mean	For	The	
Mainframe?
Who	am	I?	A	quick	introduction…
RUI	MIGUEL	FEIO
• Senior	Technical	Lead	at	RSM	Partners
• Based	in	the	UK	but	travels	all	over	the	world
• 18	years	experience working	with	mainframes
• Started	with	IBM	as	an	MVS	Sys	Programmer
• Specialist	in	mainframe	security
• Experience	in	other	platforms
Data	Privacy	on	a	Digital	
World
(2017) GDPR – What Does It Mean For The Mainframe v0.2
http://www.ohchr.org/EN/Issues/DigitalAge/Pages/DigitalAgeIndex.aspx
The	Data	Protection	Act	controls	how	your	
personal	information	is	used	by	organisations,	
businesses	or	the	government.
Everyone	responsible	for	using	data	has	to	follow	
strict	rules	called	‘data	protection	principles’.	
The	UK	Data	Protection	Act
https://www.gov.uk/data-protection/the-data-protection-act
(2017) GDPR – What Does It Mean For The Mainframe v0.2
(2017) GDPR – What Does It Mean For The Mainframe v0.2
(2017) GDPR – What Does It Mean For The Mainframe v0.2
https://www.webpagefx.com/blog/general/what-are-data-brokers-and-what-is-your-data-worth-infographic/
https://www.webpagefx.com/blog/general/what-are-data-brokers-and-what-is-your-data-worth-infographic/
“It	knows	who	you	are.	It	knows	where	you	live.	It	knows	what	you	do.”	
New	York	Times
The	Paradigm	of	Private	Data
General	Data	Protection	
Regulation	(GDPR)
• GDPR	is	composed	of	11	chapters	and	99	articles:
– Chapter	1	– General	provisions
– Chapter	2	– Principles
– Chapter	3	– Rights	of	the	data	subject
– Chapter	4	– Controller	and	processor
– Chapter	5	– Transfers	of	personal	data	to	third	countries	or	international	
organisations
– Chapter	6	– Independent	supervisory	authorities
– Chapter	7	– Cooperation	and	consistency
– Chapter	8	– Remedies,	liability	and	penalties
– Chapter	9	– Provisions	relating	to	specific	processing	situations
– Chapter	10	– Delegated	acts	and	implementing	acts
– Chapter	11	– Final	provisions
GDPR	Regulation
• General	Data	Protection	Regulation	to	be	enforced	on	25	May	2018	
• This	regulation	will	impact	any	business,	whether	based	in	the	EU	
or	not,	that	holds	the	personal data of	EU	citizens.
• GDPR	is	driven	by	two	serious	threats:	
– Reputational	damage	
– Monetary	fines (up	to	€20m	max	or	4%	of	total	worldwide	
annual	turnover,	whichever	is	higher)
• Mandatory	for	businesses	of	over	250	employees	to	appoint	
a Data Protection Officer	(DPO).
• GDPR	has	several	rules	such	as	‘the	right	to	be	forgotten’
GDPR	Overview
http://www.eugdpr.org/
(2017) GDPR – What Does It Mean For The Mainframe v0.2
• 1	in	4	companies	in	the	UK	have	stopped	preparing	for	GDPR
• “If	you	process	data	about	individuals	in	the	context	of	selling	goods	
or	services	to	citizens	in	other	EU	countries	then	you	will	need	to	
comply	with	the	GDPR,	irrespective	as	to	whether	or	not	you	the	
UK	retains	the	GDPR	post-Brexit.”	*
• 84%	of	financial	services	firms	are	not	prepared	for	GDPR**
The	Brexit	and	GDPR
*	http://www.eugdpr.org/gdpr-faqs.html
**	2016	Egress	article
How	Does	GDPR	Affect	
The	Mainframe?
• Most	mainframe	sites	have	not	started	to	prepare	for	GDPR!
• Main	reasons	are:
– Belief	that	it	only	applies	to	countries	of	the	European	Union
– Mainframe	is	unhackable so	there’s	nothing	to	be	done
– Mainframe	meets	all	the	GDPR	requirements	by	default
• Funny	enough	in	some	cases	the	GDPR	compliance	box	has	been	
ticked	without	the	mainframe	technical	teams	being	even	
consulted!!
Current	Status
• How	much	customer	data	do	you	store	on	the	mainframe?
• What	type	of	data	you	are	collecting?
• How	much	of	that	data	relates	to	EU	citizens	or	companies?
• How	data	is	processed,	managed,	stored	and	protected?
• Which	applications	and	processes	use	the	data?
• Who	has	got	access	to	it?
• Is	the	data	properly	classified?
Do	You	Know?
Your	Mainframe	got	breached?
(2017) GDPR – What Does It Mean For The Mainframe v0.2
(2017) GDPR – What Does It Mean For The Mainframe v0.2
How	To	Avoid	”Losing”	
Your	Head?
You	need	to	know	your	data,	your	processes,	your	
applications;	in	summary	you	need	to	know	your	
mainframe	environment…
• 7	Steps	to	meet	the	GDPR	technical	requirements:
– #	1	- Data	Discovery	&	Detection:
• Identify,	document	and	classify	the	data
• Where	is	it	used,	processed	and	stored?
– #	2	- Access	Control	&	Restriction:
• Access	to	Data	must	be	restricted
• Access	control	of	applications,	processes	and	databases	
needs	to	be	reviewed
Mainframe	Technical	Perspective	(1)
– #	3	- End-point-protection:
• Tapes	and	other	end-point-devices	need	to	be	controlled	
and	protected.
• Consider	this:
– Can	the	data	be	accessed	by	mobile	devices?
– Can	the	data	be	downloaded	to	the	local	terminal	and	
transferred	into	a	USB	memory	stick?
– #	4	- Pseudonymisation and	Encryption:
• Data	should	be	encrypted	and	anonymised	both	at	“rest”	
and	”in	transit”
Mainframe	Technical	Perspective	(2)
– #	5	- Backup	and	Recovery:
• Think	of	CIA:	Confidentiality,	Integrity	and	Availability
– #	6	- Anti-virus	&	Malware	detection:
• Does	not	apply	to	the	mainframe	(until	it	does)
• Think	of	alerting	and	monitoring
– #	7	- Vulnerability	scanning	and	Penetration	testing:
• Consider	undertaking	these	tests	at	a	reasonable	frequency	
to	keep	measuring	your	security	effectiveness
Mainframe	Technical	Perspective	(3)
Review
SecureMonitor
Mainframe	Technical	- Summary
• Although	not	a	direct	GDPR	requirement	(at	least	not	at	the	
moment),	consider	Security	Certifications.
• It	is	extremely	likely	that	approved	certifications	or	codes-of-
conduct	specifically	for	GDPR	will	arrive,	and	it’s	also	highly	possible	
that	these	will	look	for	security	certifications	as	pre-requisites	(e.g.	
ISO	27001).
Consider	Security	Certifications
Mainframe	Technical	Hardware
• Some	examples	of	products	that	may	help	with	GDPR:
– IBM	zSecure (or	Vanguard’s	equivalent)
– IBM	Multi-Factor	Authentication	for	z/OS	
– IBM	Security	Identity	Governance	and	Intelligence
– RSM	Exception	Reporter
– RSM	Enterprise	Connector
– RSM	zDetect
– CA	Privileged	Access	Manager
– CA	Test	Data	Manager
– CA	Data	Content	Discovery
Mainframe	Technical	Software
The	Clock	is	Ticking
https://www.helpnetsecurity.com/2017/11/06/gdpr-impact-ma-activity/
(2017) GDPR – What Does It Mean For The Mainframe v0.2
Questions?
Rui	Miguel	Feio
RSM	Partners	
ruif@rsmpartners.com
mobile:	+44	(0)7570	911459
www.rsmpartners.com
Contact

More Related Content

PDF
(2017) Cybercrime, Inc. (v3.2)
PDF
2017 - Data Privacy and GDPR (v1.1)
PDF
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
PDF
2017 - A New Look at Mainframe Hacking and Penetration Testing v2.2
PDF
Security Audit on the Mainframe (v1.0 - 2016)
PDF
How to Protect Your Mainframe from Hackers (v1.0)
PDF
Cyber security and the mainframe (v1.3)
PDF
Share 2015 - 5 Myths that can put your Mainframe at risk (v1.3)
(2017) Cybercrime, Inc. (v3.2)
2017 - Data Privacy and GDPR (v1.1)
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
2017 - A New Look at Mainframe Hacking and Penetration Testing v2.2
Security Audit on the Mainframe (v1.0 - 2016)
How to Protect Your Mainframe from Hackers (v1.0)
Cyber security and the mainframe (v1.3)
Share 2015 - 5 Myths that can put your Mainframe at risk (v1.3)

What's hot (20)

PDF
Network and Endpoint Security v1.0 (2017)
PDF
Mainframe Security - It's not just about your ESM v2.2
PDF
How to Improve RACF Performance (v0.2 - 2016)
PPTX
Keynote Information Security days Luxembourg 2015
PPTX
Keynote at the Cyber Security Summit Prague 2015
PDF
2012 06-19 --ncc_group_-_iet_seminar_-_mobile_apps_and_secure_by_design
PPTX
7 Habits of Highly Secure Organizations
PDF
12 Simple Cybersecurity Rules For Your Small Business
PDF
Rothke Computer Forensics Show 2010 Deployment Strategies For Effective E...
KEY
Application Security Done Right
PPT
Competitive cyber security
DOC
Resume
PDF
IBM Security 2017 Lunch and Learn Series
PDF
Data Security For SMB - Fly first class on a budget
PPTX
Cyber Security: Past and Future
PPTX
Understanding Your Attack Surface and Detecting & Mitigating External Threats
PPTX
Cyber Security: Past and Future
PDF
How to Reduce the Attack Surface Created by Your Cyber-Tools
PPT
Understanding Technology Stakeholders: Their Progress and Challenges
PPTX
Webinar: Critical Steps For NIST Compliance
Network and Endpoint Security v1.0 (2017)
Mainframe Security - It's not just about your ESM v2.2
How to Improve RACF Performance (v0.2 - 2016)
Keynote Information Security days Luxembourg 2015
Keynote at the Cyber Security Summit Prague 2015
2012 06-19 --ncc_group_-_iet_seminar_-_mobile_apps_and_secure_by_design
7 Habits of Highly Secure Organizations
12 Simple Cybersecurity Rules For Your Small Business
Rothke Computer Forensics Show 2010 Deployment Strategies For Effective E...
Application Security Done Right
Competitive cyber security
Resume
IBM Security 2017 Lunch and Learn Series
Data Security For SMB - Fly first class on a budget
Cyber Security: Past and Future
Understanding Your Attack Surface and Detecting & Mitigating External Threats
Cyber Security: Past and Future
How to Reduce the Attack Surface Created by Your Cyber-Tools
Understanding Technology Stakeholders: Their Progress and Challenges
Webinar: Critical Steps For NIST Compliance
Ad

Similar to (2017) GDPR – What Does It Mean For The Mainframe v0.2 (20)

PDF
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
PDF
2016 11-17-gdpr-integro-webinar
PPTX
What is GDPR?
PDF
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
PDF
20170323 are you ready the new gdpr is here
PDF
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
PPTX
Cyber - it's all now a matter of time!
PDF
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
PPTX
info-sys-security.pptx
PPTX
GDPR How ready are you? The What, Why and How.
PDF
Brendan Byrne, Security Services Consulting and Systems Integration Leader at...
PPTX
GDPR Complaince: Don't Let SIEM BE Your Downfall
PDF
Preparing for GDPR Compliance...
PPTX
Adrian Ifrim - prezentare - Cyber Security Trends 2020
PDF
What will be the Impact of GDPR Compliance in EU & UK?
PDF
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
PPTX
Automatski - The Internet of Things - Privacy Standards
PPTX
GDPR Part 1: Quick Facts
PDF
14.3.2018, Παρουσίαση Κώστα Γκρίτση στην εκδήλωση «Προστασία Προσωπικών Δεδομ...
PPTX
GDPR Compliance & Data-Centric Security | Seclore
1 -2-6 kista watson summit-gdpr ibm pov hogg-sm
2016 11-17-gdpr-integro-webinar
What is GDPR?
Symantec Webinar Part 5 of 6 GDPR Compliance, the Operational Impact of Cross...
20170323 are you ready the new gdpr is here
Compliance in Motion: Aligning Data Governance Initiatives with Business Obje...
Cyber - it's all now a matter of time!
Symantec Webinar Part 4 of 6 GDPR Compliance, What NAM Organizations Need to...
info-sys-security.pptx
GDPR How ready are you? The What, Why and How.
Brendan Byrne, Security Services Consulting and Systems Integration Leader at...
GDPR Complaince: Don't Let SIEM BE Your Downfall
Preparing for GDPR Compliance...
Adrian Ifrim - prezentare - Cyber Security Trends 2020
What will be the Impact of GDPR Compliance in EU & UK?
Symantec Webinar Part 3 of 6 How to Tackle Data Protection Risk in Time for G...
Automatski - The Internet of Things - Privacy Standards
GDPR Part 1: Quick Facts
14.3.2018, Παρουσίαση Κώστα Γκρίτση στην εκδήλωση «Προστασία Προσωπικών Δεδομ...
GDPR Compliance & Data-Centric Security | Seclore
Ad

More from Rui Miguel Feio (10)

PDF
RACF - The Basics (v1.2)
PDF
2017 - Ciberseguranca v1.0 (versao em Portugues)
PDF
2017 - Cibersecurity v1.0 (English version)
PDF
Tackling the cyber security threat (2016 - v1.0)
PDF
Cyber Crime - The New World Order (v1.0 - 2016)
PDF
Cybercrime Inc. v2.2
PDF
Challenges of Outsourcing the Mainframe (v1.2)
PDF
IOT & BYOD – The New Security Risks (v1.1)
PDF
The Billion Dollar Product - Online Privacy (v2.2)
PDF
Implementation of RBAC and Data Classification onto a Mainframe system (v1.5)
RACF - The Basics (v1.2)
2017 - Ciberseguranca v1.0 (versao em Portugues)
2017 - Cibersecurity v1.0 (English version)
Tackling the cyber security threat (2016 - v1.0)
Cyber Crime - The New World Order (v1.0 - 2016)
Cybercrime Inc. v2.2
Challenges of Outsourcing the Mainframe (v1.2)
IOT & BYOD – The New Security Risks (v1.1)
The Billion Dollar Product - Online Privacy (v2.2)
Implementation of RBAC and Data Classification onto a Mainframe system (v1.5)

Recently uploaded (20)

PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PDF
Cloud-Scale Log Monitoring _ Datadog.pdf
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PPTX
artificialintelligenceai1-copy-210604123353.pptx
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PPTX
PptxGenJS_Demo_Chart_20250317130215833.pptx
PDF
Tenda Login Guide: Access Your Router in 5 Easy Steps
PPTX
Introuction about WHO-FIC in ICD-10.pptx
PPTX
innovation process that make everything different.pptx
PPTX
Digital Literacy And Online Safety on internet
PPT
Ethics in Information System - Management Information System
PPTX
Internet___Basics___Styled_ presentation
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PDF
Sims 4 Historia para lo sims 4 para jugar
PPTX
E -tech empowerment technologies PowerPoint
PPT
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
Cloud-Scale Log Monitoring _ Datadog.pdf
Introuction about ICD -10 and ICD-11 PPT.pptx
Design_with_Watersergyerge45hrbgre4top (1).ppt
artificialintelligenceai1-copy-210604123353.pptx
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PptxGenJS_Demo_Chart_20250317130215833.pptx
Tenda Login Guide: Access Your Router in 5 Easy Steps
Introuction about WHO-FIC in ICD-10.pptx
innovation process that make everything different.pptx
Digital Literacy And Online Safety on internet
Ethics in Information System - Management Information System
Internet___Basics___Styled_ presentation
WebRTC in SignalWire - troubleshooting media negotiation
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
Sims 4 Historia para lo sims 4 para jugar
E -tech empowerment technologies PowerPoint
isotopes_sddsadsaadasdasdasdasdsa1213.ppt

(2017) GDPR – What Does It Mean For The Mainframe v0.2