BS ISO/IEC 27557:2022
$142.49
Information security, cybersecurity and privacy protection. Application of ISO 31000:2018 for organizational privacy risk management
Published By | Publication Date | Number of Pages |
BSI | 2022 | 28 |
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | National foreword |
6 | Foreword |
7 | Introduction |
9 | 1 āScope 2 āNormative references 3 āTerms and definitions |
10 | 4 āPrinciples of organizational privacy risk management 5 āFramework 5.1 āGeneral 5.2 āLeadership and commitment |
11 | 5.3 āIntegration 5.4 āDesign 5.4.1 āUnderstanding the organization and its context 5.4.2 āArticulating risk management commitment 5.4.3 āAssigning organizational roles, authorities, responsibilities and accountabilities 5.4.4 āAllocating resources |
12 | 5.4.5 āEstablishing communication and consultation 5.5 āImplementation 5.6 āEvaluation 5.7 āImprovement 5.7.1 āAdapting 5.7.2 āContinually improving 6 āRisk management process 6.1 āGeneral 6.2 āCommunication and consultation |
13 | 6.3 āScope, context and criteria 6.3.1 āGeneral 6.3.2 āDefining the scope 6.3.3 āExternal and internal context 6.3.4 āDefining risk criteria |
14 | 6.4 āRisk assessment 6.4.1 āGeneral 6.4.2 āRisk identification |
17 | 6.4.3 āRisk analysis |
18 | 6.4.4 āRisk evaluation 6.5 āRisk treatment 6.5.1 āGeneral 6.5.2 āSelection of risk treatment options |
19 | 6.5.3 āPreparing and implementing risk treatment plans 6.6 āMonitoring and review |
20 | 6.7 āRecording and reporting |
21 | Annex A (informative) PII processing identification |
23 | Annex B (informative) Example privacy events and causes |
25 | Annex C (informative) Privacy impact and consequence examples |
26 | Annex D (informative) Template showing the severity scale for privacy impacts on individuals |
27 | Bibliography |