Shield Security Consultancy Services offer a bouquet of information security/cyber security services covering data privacy protection, ISMS implementation, support with ISO27001 & ISO22301 certifications, penetration testing and business continuity program implementation.
GDPR Compliance Consultancy Services
By 25th May 2018, all organisations that handle data of EU residents will be required to comply with a single set of rules about data governance/protection, regardless of where the organisation is located. The introduction of the General Data Protection Regulation (GDPR) (www.eugdpr.org) will dramatically change the way in which data is stored, shared and moved. The legislation will give individuals greater rights and control over their data by way of consent as well as the power to access, rectify or erase information held and the right to be informed. With severe non-compliance penalties of up to EURO 20 million or 4% of worldwide turnover, the GDPR will make organisations more accountable for their approach to handling personal data and safeguarding it. Organisations need to make sure they are ready for the legislation before it comes into force on 25th May 2018. That might sound like more than enough time to prepare, but getting your house in order is not an overnight task. The far-reaching nature of the GDPR means every aspect of business will feel its impact and, in places, entire processes will need to be replaced or set up from scratch.
Shield Security Information Security Consultancy Services can help your organisation achieve its privacy goals and compliance obligations in time for the implementation of GDPR through cost-effective advice and support. Our experienced International Association of Privacy Protection (IAPP) Certified specialist data privacy consultancy team can provide you with the necessary expertise to implement a total privacy program that meets GDPR compliance requirements. We can also undertake an initial privacy impact assessment of your current compliance regime if you are just getting started with a data protection program. Our “free of cost no obligations” initial assessment is aimed at making organisations understand GDPR applicability as it affects them and the quantum of work required for achieving GDPR compliance. Our GDPR consultancy services come in three packages: Platinum package: an all-inclusive GDPR compliance service package where we do everything for you to ensure GDPR compliance. Gold package where we do things together and a Silver Package where you do it and we provide guidance. Please enquire for further details. Our GDPR spectrum of consultancy services includes:
Support with establishing Data Privacy Governance Structure:
- Understand impact of GDPR on organisation
- Undertake data privacy impact assessment including for 3rd parties
- Data Privacy Strategy and policies formulation
- Identifying organisational roles/responsibilities including formulation of job descriptions
- DPO Training (if nominated/need established)
- Audit and compliance monitoring procedures and establishing KPIs
- Establishing communication channels & policies
- Support with establishing Data Privacy Committee and charter of duties
- Support with Compiling Personal Data Inventory and establishing Data Transfer Mechanisms:
- Compile inventory of personal data holdings (what personal data is held and where)
- Classify personal data holdings by type (e.g. sensitive, confidential, public)
- Obtaining regulator approval for data processing (where prior approval is required)
- Register databases with regulator(s) (where registration is required)
- Maintain flow charts for data flows (e.g. between systems, between processes, between countries
- Maintain records of the transfer mechanism used for cross–border data flows (e.g., standard contractual clauses, binding corporate rules, approvals from regulators)
- Formulating Binding Corporate Rules as a data transfer mechanism
- Contract clauses formulation where contracts are being used as a data transfer mechanism (e.g., Standard Contractual Clauses)
- Obtaining regulator approval as a data transfer mechanism
- Help with understanding the EU–US Privacy Shield and support aimed at ensuring adherence
- Establishing/identifying legal basis for data processing
- Establishing policies/procedures for:
- Collection and use of sensitive personal data (including biometric data)
- For maintaining data quality
- For the de–identification of personal data
- For reviewing processing conducted wholly or partially by automated means
- For secondary uses of personal data
- For obtaining valid consent
- For secure destruction of personal data
- Integrate data privacy into records retention practices.
- Integrating data privacy into direct marketing practices
- Integrating data privacy into hiring practices etc.
- Support With Data Privacy Risk Identification and Mitigation:
- Identification of data privacy security risks
- Risk register and risk mitigation plans
- Establishing administrative and technical controls to address risks
- Third party due diligence and risk mitigation
- Establishing 3rd party data privacy requirements
- Support with formulating data privacy notices:
- Formulating privacy notice that details the organization’s personal data handling practices
- Identifying points for exhibiting privacy notices
- Formulating data privacy notices for contracts, marketing activities, etc.
- Support with formulating Data Subject Requests and Complaints procedures:
- For responding to requests establishing a mechanism for individuals to update or correct their personal data
- For responding to data portability requests and establishing mechanism for providing such data
- Establishing complaints handling and investigation procedure
- Support with establishing Data Privacy Impact Assessment procedures including formulation of organisation specific checklists and templates
- Support with data privacy breach monitoring and reporting program:
- Establishing data privacy incident/breach response plan
- Establishing breach notification (to affected individuals) and reporting (to regulators, credit agencies, law enforcement) protocol
- Breach incident log creation
- Establishing mechanism/methodology for testing of data privacy incident/ breach plans
- Support with preparing all necessary documentation as evidence of .organisation’s compliance with GDPR.
- Support with identifying/recommending GDPR automation solutions.
- Post compliance GDPR Health Checks and Continuous Improvement Support, refresher training and awareness campaigns and data privacy risk re-assessment and mitigation support.
ISO 27001 Certification Consultancy Services
The way in which you look after and use corporate information can mean the difference between success and failure for your business. Get it right and you’ll grow your customer-base. Get it wrong and the risks and penalties can stop you in your tracks. ISO 27001 certification demonstrates that your business has systems in place to protect corporate information and data, whether this is online or offline. By gaining ISO 27001, customer and stakeholder confidence is increased and your company’s reputation is improved, allowing you to stand out amongst competitors.
Our experienced and certified ISO27001 consultancy team can help your organisation prepare for securing ISO27001 certification and provide post-certification support to ensure your certificate remains current. Alternatively, if certification is not what you are after and you would like, instead, to put in place a robust information security protection regime we can help your organisation develop and implement an effective and efficient information security management system (ISMS) aimed at mitigate information security risks faced by your organisation. Key support in helping you attain ISO27001 certification includes:
- Establishing ISO27001 based Information Security Governance Framework
- Identification of information security risks and support with prioritising risks
- Implementing information security risk mitigation plan
- Information security operations management
- Audit of 3rd party information security compliance
- Establishing IT Business Continuity Plans
- Putting in place robust information security incident management plans in place
- Setting up KPIs/compliance monitoring regimes
Regular reviews and audits to confirm that your organisation continues to comply with the ISO 27001 standard and that your ISMS continues to operate as specified and intended.
In case you would like more details regarding the above services or any of our other Information/IT Security offerings like PCI DSS implementation, pen testing, IT DRP or business continuity program implementation etc.
please email us at Infosec@shieldsecurity.co.uk or speak to a member of our team.