SlideShare a Scribd company logo
GDPR and ISMS
Quick Map Framework
DRAFT:EUGENELEEWORK@GMAIL.COM
Topic
•Principle
•Lesson of GDPR
•Data Protection Officer (DPO)
•Quick Start Mapping
• How-To: Quick leverage ISO27001 ISMS in
order
Principle
1. Documented Policy
2. Minimize data collected
3. Do not retain data beyond purpose
4. Data Subject ownership to their Data
5. Breach notification
Must* notify data authorities within 72 hours once a personal data breach
discovered
Notify individual (data subjects) if high risk to their rights
6. Proven Records while legal requesting
2/8/2018eugeneleework@gmail.com 3
Lesson of GDPR
• Key Elements of GDPR
• Risk Assessment (DPIA)
• Documenting IT Procedures
• Data classification and Minima Data Lifetime
• Monitoring and Automation
• Extraterritoriality
• New law extend outside the EU, even there is no a physical
presence in the EU
• Especially e-commerce and cloud-based companies
2/8/2018eugeneleework@gmail.com 4
Data Protection Officer (DPO)
• Responsible for
• As Contactor (depends on condition)
• Creating access controls
• Reducing risk
• Ensuring compliance
• Responding to requests
• Reporting breaches within 72 hours
• Creating a strong data security policy
2/8/2018eugeneleework@gmail.com 5
Quick Start Mapping – Core
Element
• Data classification
• Define Information levels
• Metadata
• When was collected,Why was collected and its Purpose
• Governance
• GDPR security policies (personal data)
• Role and Privilege to which system (Authorization and Permission)
• ACL Policy,Who can access on limiting file
• Monitoring
• Unusual access patterns against files containing personal data
2/8/2018eugeneleework@gmail.com 6
Quick Start Mapping – Doc.
Plan.
• Documentation Strategy for GDPR
• Identify which control item fit and relates to GDPR
• Editing, Adding, Modify relates document or regulation
• Draft GDPR policy by referring back existing or edited document
• Example,
1. Privacy and Personal Data Protection
2. Draft the content table
3. Referring table back to existing controls (regulation, rules)
2/8/2018eugeneleework@gmail.com 7
Key Scope GDPR ISO27001
Guidance and Strategy Protection Policy
4、5、6
A.5 and its referral policy
Classification Data classification A.8.1、A.8.2
Metadata
HR、minimize data collected
CRM
Project
A.7、A.8、A.14、A.15
Governance
ACL on systems
HRMS、System which stored
personal information
A.6.1、A.8.1、A.8.3、A.9、
A.10、A11、A12、A.18.1.3、
A.18.1.4
Monitoring
Proven Logs on systems、
Monitor system、SysLog
6、10
A.8.3、A.9、A.11.1、A.12.4、
A.16
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 8
Key Scope GDPR ISO27001
New Role DPO A.6.1
ExtraTerritoriality (EU to US,
Privacy Shield)
Articles 3
HRMS, Saelsforce,CRM
A.7、A13.2、A.18
Privacy Shield Framework
Violations of basic principles
related to data security
Articles 5
5、6、7
A.5、A.6、A.7、A.13、
A.16、A.18
Violations of the core Privacy
by Design concepts
Articles 7
5、6、7
A.5、A.6、A.7、A.13、
A.16、A.18
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 9
Domain or Scope GDPR ISO27001
• Right to Erasure and to-
be-forgotten
• Able to discover and
target specific data when
ever intend to remove it
• Data subject can request
to erase the data held by
companies at any time
• Data processors have to
erase all whenever asked
Articles 17
HRMS, Saelsforce, CRM
6.1.2
A.7、A.8、A.12.3、
A.14.1.1、A.16
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 10
Domain or Scope GDPR ISO27001
Data Protection by Design
and By Default
Accountability and
Automation
Articles 25
6.1.2、6.1.3、7.5.3、9.1
A.6.1.5、A.7、A.8、
A.12.3、A.14.1.1、A.16
Not having records in order
2% of global revenue for
Records of Processing
Activities
Organizational measures to
process personal data
Articles 30
6、7、8
A.8、A.12.3、A.16、
A.18
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 11
Domain or Scope GDPR ISO27001
Security of Processing
Least privilege access,
Accountability by data
subject (the owner =
individuals)
Able to provide
measurement reports on
policies, processes
Articles 32
8.2、8.3
A.9、A.10、A.11、A.13、
A.16、A.15
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 12
Domain or Scope GDPR ISO27001
Notification of personal
data breach to the
supervisory authority
Prevent and alert on
data breach activity
Incidence response plan
Articles 33 A.16、A.18.1.4
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 13
Domain or Scope GDPR ISO27001
Not notifying the
supervising authority
and data subject about a
breach
Articles 34 A.16、A.18.1.4
Not conducting impact
assessments
Data Protection Impact
Assessment
Quantify data protection
risk profiles
Articles 35
6.1.2
A.6.1.3、A.8.2.1
Quick Start Mapping – cont.
2/8/2018eugeneleework@gmail.com 14
ThankYou

More Related Content

PDF
GDPR for Non-European Region - Financial Services EL
PDF
GDPR and ISO27001 mapping EL
PPTX
Payslip gdpr deck nov 2017
PPTX
Simple GDPR Overview
PPTX
Niall Rooney FD Event 05.09.19
PPTX
Sophie's Privacy - a story about GDPR
PDF
GDPR in a nutshell
PDF
GDPR Overview
GDPR for Non-European Region - Financial Services EL
GDPR and ISO27001 mapping EL
Payslip gdpr deck nov 2017
Simple GDPR Overview
Niall Rooney FD Event 05.09.19
Sophie's Privacy - a story about GDPR
GDPR in a nutshell
GDPR Overview

What's hot (19)

PDF
20170323 are you ready the new gdpr is here
PPTX
GDPR From Implementation to Opportunity
PDF
Gdpr overview ciso platform presentation
PPTX
GDPR – The Practicalities of a New Reality
PPTX
Payroll Data & GDPR: What you need to know?
PPTX
Preparing for general data protection regulations (gdpr) within the hous...
PPTX
GDPR practical info session for development
PDF
GDPR what you should know and how to minimize impact on your business
PDF
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
PDF
3GRC approach to GDPR V 0.1 www.3grc.co.uk
PDF
SureSkills GDPR - Discover the Smart Solution
PDF
GDPR for dummies
PPT
Data protection
PPTX
Ready for the GDPR, Ready for the Digital Economy
PDF
GDPR 101
PPTX
GDPR security services - Areyou ready ?
PDF
Data Protection and Privacy
PDF
The Essential Guide to GDPR
20170323 are you ready the new gdpr is here
GDPR From Implementation to Opportunity
Gdpr overview ciso platform presentation
GDPR – The Practicalities of a New Reality
Payroll Data & GDPR: What you need to know?
Preparing for general data protection regulations (gdpr) within the hous...
GDPR practical info session for development
GDPR what you should know and how to minimize impact on your business
Teleran Data Protection - Addressing 5 Critical GDPR Requirements
3GRC approach to GDPR V 0.1 www.3grc.co.uk
SureSkills GDPR - Discover the Smart Solution
GDPR for dummies
Data protection
Ready for the GDPR, Ready for the Digital Economy
GDPR 101
GDPR security services - Areyou ready ?
Data Protection and Privacy
The Essential Guide to GDPR
Ad

Similar to Gdpr and ISMS Quick Map Framework EL (20)

PPTX
New york oracle users group 2013 spring general meeting ulf mattsson
PDF
Partner enablement GDPR
PPTX
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
PPTX
Gdpr brief and controls ver2.0
PDF
Partner enablement GDPR
PDF
Mailstore advisory GDPR
PDF
Big Data LDN 2017: Applied AI for GDPR
PPTX
Gdpr action plan - ISSA
PDF
How to Maximize Data Governance in Snowflake Test Environment
PDF
Building the Governance Ready Enterprise for GDPR Compliance December 2017
PDF
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
PPTX
2018 advanced data governance - slide share
PDF
Using an Information Asset Register for the GDPR
PPTX
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
PPTX
CIO WaterCooler Focus: GDPR Jasmit Sagoo
PDF
Data+Management+Masterclasssdfsdfsdfsd.pdf
PDF
DEFeND Project Presentation - July 2018
PPTX
GDPR How to get started?
PDF
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
PPTX
The EU General Protection Regulation and how Oracle can help
New york oracle users group 2013 spring general meeting ulf mattsson
Partner enablement GDPR
Preparing for GDPR: General Data Protection Regulation - Stakeholder Presenta...
Gdpr brief and controls ver2.0
Partner enablement GDPR
Mailstore advisory GDPR
Big Data LDN 2017: Applied AI for GDPR
Gdpr action plan - ISSA
How to Maximize Data Governance in Snowflake Test Environment
Building the Governance Ready Enterprise for GDPR Compliance December 2017
[Webinar Slides] Data Explosion in Your Organization? Harness It with a Compr...
2018 advanced data governance - slide share
Using an Information Asset Register for the GDPR
CWIN17 san francisco-geert vanderlinden-don't be stranded without a (gdpr) plan
CIO WaterCooler Focus: GDPR Jasmit Sagoo
Data+Management+Masterclasssdfsdfsdfsd.pdf
DEFeND Project Presentation - July 2018
GDPR How to get started?
04 - VMUGIT - Lecce 2018 - Giampiero Petrosi, Rubrik
The EU General Protection Regulation and how Oracle can help
Ad

Recently uploaded (20)

PPT
Ethics in Information System - Management Information System
PDF
Decoding a Decade: 10 Years of Applied CTI Discipline
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
PPTX
newyork.pptxirantrafgshenepalchinachinane
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PDF
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
PDF
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
PPTX
presentation_pfe-universite-molay-seltan.pptx
PDF
Unit-1 introduction to cyber security discuss about how to secure a system
PPTX
artificial intelligence overview of it and more
PPTX
international classification of diseases ICD-10 review PPT.pptx
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PPT
tcp ip networks nd ip layering assotred slides
PPTX
Module 1 - Cyber Law and Ethics 101.pptx
PDF
Sims 4 Historia para lo sims 4 para jugar
PDF
Exploring VPS Hosting Trends for SMBs in 2025
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PDF
Introduction to the IoT system, how the IoT system works
PDF
Tenda Login Guide: Access Your Router in 5 Easy Steps
PDF
An introduction to the IFRS (ISSB) Stndards.pdf
Ethics in Information System - Management Information System
Decoding a Decade: 10 Years of Applied CTI Discipline
Power Point - Lesson 3_2.pptx grad school presentation
newyork.pptxirantrafgshenepalchinachinane
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
Automated vs Manual WooCommerce to Shopify Migration_ Pros & Cons.pdf
FINAL CALL-6th International Conference on Networks & IOT (NeTIOT 2025)
presentation_pfe-universite-molay-seltan.pptx
Unit-1 introduction to cyber security discuss about how to secure a system
artificial intelligence overview of it and more
international classification of diseases ICD-10 review PPT.pptx
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
tcp ip networks nd ip layering assotred slides
Module 1 - Cyber Law and Ethics 101.pptx
Sims 4 Historia para lo sims 4 para jugar
Exploring VPS Hosting Trends for SMBs in 2025
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
Introduction to the IoT system, how the IoT system works
Tenda Login Guide: Access Your Router in 5 Easy Steps
An introduction to the IFRS (ISSB) Stndards.pdf

Gdpr and ISMS Quick Map Framework EL

  • 1. GDPR and ISMS Quick Map Framework DRAFT:EUGENELEEWORK@GMAIL.COM
  • 2. Topic •Principle •Lesson of GDPR •Data Protection Officer (DPO) •Quick Start Mapping • How-To: Quick leverage ISO27001 ISMS in order
  • 3. Principle 1. Documented Policy 2. Minimize data collected 3. Do not retain data beyond purpose 4. Data Subject ownership to their Data 5. Breach notification Must* notify data authorities within 72 hours once a personal data breach discovered Notify individual (data subjects) if high risk to their rights 6. Proven Records while legal requesting 2/8/2018eugeneleework@gmail.com 3
  • 4. Lesson of GDPR • Key Elements of GDPR • Risk Assessment (DPIA) • Documenting IT Procedures • Data classification and Minima Data Lifetime • Monitoring and Automation • Extraterritoriality • New law extend outside the EU, even there is no a physical presence in the EU • Especially e-commerce and cloud-based companies 2/8/2018eugeneleework@gmail.com 4
  • 5. Data Protection Officer (DPO) • Responsible for • As Contactor (depends on condition) • Creating access controls • Reducing risk • Ensuring compliance • Responding to requests • Reporting breaches within 72 hours • Creating a strong data security policy 2/8/2018eugeneleework@gmail.com 5
  • 6. Quick Start Mapping – Core Element • Data classification • Define Information levels • Metadata • When was collected,Why was collected and its Purpose • Governance • GDPR security policies (personal data) • Role and Privilege to which system (Authorization and Permission) • ACL Policy,Who can access on limiting file • Monitoring • Unusual access patterns against files containing personal data 2/8/2018eugeneleework@gmail.com 6
  • 7. Quick Start Mapping – Doc. Plan. • Documentation Strategy for GDPR • Identify which control item fit and relates to GDPR • Editing, Adding, Modify relates document or regulation • Draft GDPR policy by referring back existing or edited document • Example, 1. Privacy and Personal Data Protection 2. Draft the content table 3. Referring table back to existing controls (regulation, rules) 2/8/2018eugeneleework@gmail.com 7
  • 8. Key Scope GDPR ISO27001 Guidance and Strategy Protection Policy 4、5、6 A.5 and its referral policy Classification Data classification A.8.1、A.8.2 Metadata HR、minimize data collected CRM Project A.7、A.8、A.14、A.15 Governance ACL on systems HRMS、System which stored personal information A.6.1、A.8.1、A.8.3、A.9、 A.10、A11、A12、A.18.1.3、 A.18.1.4 Monitoring Proven Logs on systems、 Monitor system、SysLog 6、10 A.8.3、A.9、A.11.1、A.12.4、 A.16 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 8
  • 9. Key Scope GDPR ISO27001 New Role DPO A.6.1 ExtraTerritoriality (EU to US, Privacy Shield) Articles 3 HRMS, Saelsforce,CRM A.7、A13.2、A.18 Privacy Shield Framework Violations of basic principles related to data security Articles 5 5、6、7 A.5、A.6、A.7、A.13、 A.16、A.18 Violations of the core Privacy by Design concepts Articles 7 5、6、7 A.5、A.6、A.7、A.13、 A.16、A.18 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 9
  • 10. Domain or Scope GDPR ISO27001 • Right to Erasure and to- be-forgotten • Able to discover and target specific data when ever intend to remove it • Data subject can request to erase the data held by companies at any time • Data processors have to erase all whenever asked Articles 17 HRMS, Saelsforce, CRM 6.1.2 A.7、A.8、A.12.3、 A.14.1.1、A.16 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 10
  • 11. Domain or Scope GDPR ISO27001 Data Protection by Design and By Default Accountability and Automation Articles 25 6.1.2、6.1.3、7.5.3、9.1 A.6.1.5、A.7、A.8、 A.12.3、A.14.1.1、A.16 Not having records in order 2% of global revenue for Records of Processing Activities Organizational measures to process personal data Articles 30 6、7、8 A.8、A.12.3、A.16、 A.18 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 11
  • 12. Domain or Scope GDPR ISO27001 Security of Processing Least privilege access, Accountability by data subject (the owner = individuals) Able to provide measurement reports on policies, processes Articles 32 8.2、8.3 A.9、A.10、A.11、A.13、 A.16、A.15 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 12
  • 13. Domain or Scope GDPR ISO27001 Notification of personal data breach to the supervisory authority Prevent and alert on data breach activity Incidence response plan Articles 33 A.16、A.18.1.4 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 13
  • 14. Domain or Scope GDPR ISO27001 Not notifying the supervising authority and data subject about a breach Articles 34 A.16、A.18.1.4 Not conducting impact assessments Data Protection Impact Assessment Quantify data protection risk profiles Articles 35 6.1.2 A.6.1.3、A.8.2.1 Quick Start Mapping – cont. 2/8/2018eugeneleework@gmail.com 14