
Introduce ISO 27701 as an extension of ISO 27001 for privacy and information security, offering guidance on protecting personal data, demonstrating compliance, and defining roles and responsibilities across organizations.
Discover how ISO/IEC 27701 extends privacy information management systems to help data controllers establish, implement, and continually improve privacy protection, with industry-specific requirements, alongside ISO/IEC 27001.
Discover ISO/IEC 27001’s risk-based approach to information security management and how ISO 27701 extends it to privacy management aligned with GDPR and DPAs.
Define the roles of the information controller and processor, explain data processing (storage, collection, and handling), and describe three contract-based customer scenarios: controller, processor, and subcontractor.
Explore how ISO 27701 links privacy and information security through the organization’s context and controller and processor roles. External and internal factors shape data privacy obligations and controls for compliance.
Identify stakeholders for the information security management system, including customers, supervisory authorities, controllers, processors, and subcontractors, and map their legal, contractual, and regulatory requirements under ISO 27001 and ISO 29100.
Determine the boundaries and applicability of the information security management system to establish its scope, and include the processing of personally identifiable information.
Lead senior management demonstrates commitment to information security and privacy by aligning ISMS policy and objectives with strategy, integrating processes, guaranteeing resources, and promoting continuous improvement.
Plan and apply integrated risk assessments for information security and privacy to protect personally identifiable information, evaluate loss of confidentiality, integrity, and availability, and declare applicable controls with justifications.
Identify and provide resources, build skills, and foster awareness to establish, implement, maintain, and improve privacy information systems management; ensure policy knowledge, compliant communication, and rigorous documentation controls.
Plan and control operations assessments, manage information security and privacy risk assessments and three-party processes, and implement risk treatment plans to meet requirements and objectives, documenting results.
Evaluate the performance and effectiveness of the information security and privacy management system through monitoring, internal audits, and management reviews; establish an audit program, report results, and pursue improvement opportunities.
Identify nonconformities in the information security and privacy management system, implement corrective actions, and continuously improve processes to eliminate causes and prevent recurrence.
Understand PIMS-specific requirements related to ISO/IEC 27002, and compare it with ISO/IEC 27001 to guide information security and privacy controls.
Develop and implement information security and privacy policies aligned with ISO 27002 and ISO 27701, covering legal compliance, controller and processor roles, and documented approval and maintenance.
Establish a management structure for information security and privacy, approve the information security policy, appoint a data protection officer, and integrate risk assessments with project and product management.
Guard mobile device privacy and information security in remote work by implementing a strict policy, PCI considerations, device registration, access controls, encryption, and remote deletion of data.
Explore teleworking policies that safeguard privacy and information security for remote work, covering secure remote access, encryption, two-factor authentication, antivirus, firewall, and safeguards for privately owned equipment.
Ensure pre-employment due diligence by conducting proportionate background checks, verifying identities and references, and confirming qualifications for roles with access to information and security responsibilities.
The lecture emphasizes educating employees and third parties about information security and privacy responsibilities during employment, with ongoing training, awareness activities, reporting channels, and management support to prevent incidents.
Maintain information security and privacy obligations after termination or change of employment, and ensure clear communication and enforcement with HR, managers, and third-party providers.
Identify and inventory information assets, assign owners, and define lifecycle protections from creation to destruction—and keep the inventory updated for risk management and ISO/IEC 27001 compliance.
Define an organization-wide information classification scheme that assigns asset value by sensitivity and criticality, guiding confidentiality, integrity, and availability protections, labeling, owner responsibility, and consistent handling across the lifecycle.
Learn how to manage removable media securely, including classification, encryption, handling, disposal, and audit trails to protect personal data throughout storage, transport, and destruction.
Defines access control policy and rules to limit information access based on business requirements, roles, and risks, supported by formal procedures, monitoring, and periodic rights reviews.
Establish controlled user access through registration and cancellation, enforce two-step provisioning and revocation, assign new user IDs, deprovision and disable IDs when leaving, and maintain a centralized access rights record.
Identify and control privileged access rights for each system and user category through a formal authorization process, maintain records, and regularly review and revoke privileges upon termination or role change.
Users are responsible for protecting their authentication information, following organizational practices, keeping it confidential, using strong unique passwords, and applying password management tools to minimize risk.
Enforce system and application access control per policy, restricting data and functions, with secure entry, strong authentication, and strict password and source code controls.
Learn to implement cryptographic controls across an organization to protect confidentiality and integrity, guided by risk assessment and policy, covering key management life cycle, mobile data encryption, and digital signatures.
Define security perimeters and restrict access to protect information processing facilities, and implement alarms, two-factor authentication, and visitor controls to ensure only authorized personnel access secure areas.
Protect assets by locating and securing equipment, minimizing access to information processing facilities, and enforcing environmental, lighting, and cabling safeguards to deter theft and disruption.
Ensure equipment maintenance is performed by authorized personnel per supplier specifications and documented; manage asset removal, chain of custody, and offsite risks, with proper disposal and encryption measures.
Document operation start up and shutdown procedures, manage changes, and monitor capacity, backups, and security to ensure safe information processing resources and segregation of development, testing, and production environments.
Protect information and resources from malware by implementing detection, prevention, and recovery controls, supported by user awareness, formal policies, and software controls like whitelists and blacklist management.
Protect against data loss by establishing and testing backup policies, with remote storage, encryption, and regular restoration drills to recover critical information and PII after disasters.
Record and maintain logs of user activities, log on/off times, and key system events. Enable automatic monitoring, regular log reviews, and protections to guard privacy and integrity of logs.
Ensure the integrity of operating systems by controlling software installation and updates by authorized administrators, conducting extensive testing, and using a configuration control system to preserve documentation and older versions.
Define roles and responsibilities for vulnerability monitoring, maintain an up-to-date asset inventory, and implement risk-based remediation with patch testing and change management.
Minimize the impact of information systems audits by planning controlled verification, agreeing on scope with management, and enforcing read-only access through isolated copies with monitored logs.
Explore network security management to protect information across networks and processing resources, with responsibilities, controls, and monitoring to ensure confidentiality, integrity, and availability.
Develop and enforce information transfer policies and controls to protect confidentiality, integrity, authenticity, encryption, and retention and disposal of information across electronic communications and external exchanges.
Integrate information security throughout the system lifecycle, from acquisition to maintenance, by defining security requirements and risk controls. Enforce authentication, confidentiality, and integrity for applications and services over public networks.
Explore how to design and implement secure development and support processes under ISO 27701, including secure coding, change control, testing, and privacy and PCI considerations.
Design secure information systems by applying privacy by design, secure engineering principles across all layers, and rigorous testing, including supplier controls and secure development environments.
Use synthetic data for testing; avoid operational databases with PII or confidential information. Apply access controls, authorization for copies, and audit trails, and perform risk analysis when testing unavoidable data.
Explore how organizations define information security requirements for supplier access, establish agreements with suppliers, and enforce controls across the supply chain.
Ensure supplier service delivery management by monitoring, auditing, and critically analyzing performance to meet information security requirements and service levels. Manage incidents, changes, and supplier relationships.
Define responsibilities and procedures for identifying, recording, notifying, and managing information security incidents, including escalation, evidence handling, and recovery, aligned with ISO 27701 privacy and information security.
Determine information security requirements within business continuity and disaster recovery, establish and maintain controls to sustain information security in adverse situations, and verify continuity through testing.
Identify business requirements for system availability and implement redundancies using architecture and redundant components; test failover to ensure continued operation while addressing risks to integrity and confidentiality.
Ensure compliance with all legal, regulatory, and contractual obligations for information security and privacy, identifying applicable requirements, controls, and responsibilities across locations, including intellectual property rights and PCI encryption requirements.
Perform independent critical reviews to assess an organization's information security approach, policies, and controls, including audits, for ongoing effectiveness and ISO-aligned compliance.
Explore additional ISO/IEC 27002 guidance for PII controllers, detailing lawful processing with a legal basis, purpose identification, customer disclosure, and documenting bases for each processing activity.
Document where and how consent is obtained, align processing with consent requirements, record details such as date, time, and freely given consent, and conduct a privacy impact assessment.
organizations must establish written contracts with every pii processor, require pci-specific security controls based on risk assessments, and document joint processing, transfers, and breach responsibilities.
Explain obligations to principals regarding the processing of personal data, and how organizations provide meaningful information, a current contact, and documentation of processing purposes and rights.
Provide principals with clear, timely, accessible information about processing and consent; enable modification or withdrawal of consent, rights to object, and online mechanisms via website or email.
Enable customers to access, correct, or delete their information; define response times; notify third parties of changes; and provide data copies in a portable, accessible format.
Define and document policies for handling legitimate client requests, set response times in the privacy policy, disclose fees, and address automated decision making with customer notification and human intervention.
Implement privacy by design and privacy by default by limiting collection and processing to what is necessary, minimizing data, maintaining accuracy, and documenting lifecycle policies to safeguard personal identifiable information.
Identify and delete personal identification information when no longer needed to prevent re-identification. Implement disposal techniques, temporary file management, and controlled data transmission to protect PII throughout processing.
Assess and document PII sharing, transfers, and disclosures across jurisdictions, ensuring regulatory compliance, supervisory authority reviews, and policy-driven records management, including law enforcement disclosures and data minimization for third parties.
Explains additional ISO 27002 guidance for processors, outlines contracts for lawful processing, purpose limitation, breach notification, privacy by design, and marketing consent requirements.
Identify and inform the client when a processing instruction may violate applicable law, verify violations within contractual and technological context, and provide information to demonstrate compliance and support audits.
Define the obligations to PII principals to receive information about processing. Ensure privacy by design and manage retention, disposal, return, and secure transfer under contract.
Explain the basis for transferring personal data across jurisdictions, and when to share or disclose it. Inform clients of transfers and changes so they can object or terminate the contract.
Ensure legally binding VII disclosures by consulting the client and rejecting nonbinding requests under the NDA. Include subcontractor details, transfer countries, and client authorization in contracts, and notify changes.
Examine annexes for ISO 27701, detailing control objectives for controllers and processors, the statement of applicability, and illustrative mappings to ISO 27001 and the GDPR.
Conclude your ISO 27701 course by reviewing privacy and information security concepts and learning to apply them within your organization.
This course addresses the privacy information management system based on ISO/IEC 27701:2013 in detail and including references from ISO 27001 and 27002. It explains how ISO 27701 can assist in the process of protecting personal information to comply with privacy laws and regulations without being tied to a specific law or regulation, and why it is a reference for any privacy information management system regardless of the size of the organization, applicable laws and regulations or segment in which it operates.
ISO 27701 is an extension of ISO 27001 – information security management and also of ISO 27002 that focuses on security controls. It is an international standard guiding how to protect privacy, including how organizations should manage personal information and also guidance on how you can demonstrate compliance with privacy regulations around the world.
ISO 27701 applies to all types and sizes of organizations, including public and private, governmental and non-profit entities. It guides those who are responsible for processing personal information through the use of the information security management system
ISO 27701 is another successful project of ISO/IEC, and brings numerous benefits to your organization:
Build confidence in personal information management
Provides transparency to interested parties
Facilitates business agreements
Clarifies roles and responsibilities
Supports compliance with privacy laws and regulations
Reduces complexity
BECOME A DATA PROTECTION PROFESSIONAL AND BOOST YOUR CAREER!
DATA PRIVACY NOWADAYS IS GLOBAL!