Identifying and maintaining measures of success in privacy programs. The publication of ISO 27701 is an exciting development for all companies looking to enhance and potentially certify their privacy programs. As companies race to digest and implement the new standard, many questions arise about addressing some of its particular requirements. One such area involves the governance of an ISO 27701 program. It is important to understand that while ISO 27701 specifically deals with privacy, the framework is nested with the ISO 27001 security framework. Each of clauses 4 – 8 of ISO 27701 references ISO 27001/ISO 27002 and establish “additional criteria”. As a result, ISO 27701 is not intended to be a stand-alone framework but rather a sister framework to ISO 27001. To obtain ISO 27701 certification, you must also obtain ISO 27001 certification. If you are unfamiliar with the ISO 27001 framework, you can read our whitepaper
here.
PIMS 101
An organization’s Privacy Information Management System (PIMS) governs the scope of its ISO 27701 implementation and a set of processes to govern, implement, operate, monitor, review and continuously improve the PIMS. The PIMS must address both information security and privacy, marking a significant expansion of an organization’s Information Security Management System (ISMS) under ISO 27001. Under ISO 27001 clause 6.2 and ISO 27701 clause 5.4.2, an organization must develop measurable information security and privacy objectives. In our ISO 27001 and ISO 27701 implementations, we help companies define Key Performance Indicators (KPIs) relevant to information security and privacy to address this requirement. These KPIs are designed to give management a quick overview of how the PIMS is functioning, so that management can identify areas for continual improvement.Measuring Program Performance
Coming up with KPIs that accurately measure and represent the performance of the program can be a challenge in itself. When implementing a PIMS, what are some examples of good privacy KPIs? Here are a few that may be useful:- Number of privacy complaints (customer, regulator)
- Response time to data subject requests - standard response times will be defined in the Privacy Policy as required under ISO 27701, Clause 7.3.9
- Results of privacy internal audits (required under ISO 27701)
- Timely Privacy Impact Assessment (PIA) completion rate
- On-time regulator notification for privacy breaches
Philip Brudney
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)