ISO IEC 27001 and GDPR v1.0
ISO IEC 27001 and GDPR v1.0
ISO/IEC 27001 and the General Data Protection Regulation (GDPR) Gemserv
ISO 27001 specifically recommends implementing a data A.9 covers the topic of access control, which, if implemented
protection policy specifying requirements for data protection properly, will ensure only individuals with a legitimate right can
supported by specific procedures regarding aspects of data access information according to their privilege level.
protection e.g. retention and destruction.
In addition, the IT systems must be sufficiently resilient to
external attacks. The ISO framework’s control 18.2.3 requires
The GDPR stipulates that companies to perform vulnerability tests and penetration tests
personal data shall be with due care, so that the systems tested are not compromised.
‘processed in a manner The requirement to manage technical vulnerabilities under
that ensures appropriate
ISO 27001 requires organisations to patch systems, keep a
security’.
record of logs, etc.
Gemserv ISO/IEC 27001 and the General Data Protection Regulation (GDPR)
content means that the focus can be centred on encrypting the
most valuable assets.
A huge number of data leaks are accidental and could have been
avoided if only a data classification policy had been in place to
raise user awareness and prevent sensitive content from being
stored on a USB or uploaded to third party web portals such as
Dropbox. Using visual labels also encourages users to be more
responsible and aware when handling physical copies of data
that have been printed out.
ISO/IEC 27001 and the General Data Protection Regulation (GDPR) Gemserv
TRAINING AND AWARENESS COOPERATION WITH THE SUPERVISORY AUTHORITY
ISO 27001 promotes a culture and awareness of security Both ISO 27001 and GDPR requires organisations to maintain
incidents in organisations. Information security is not only about contact with supervisory authorities, which, in the case of the UK
technology it’s also about people. would be the Information Commissioner’s Office (ICO).
Gemserv ISO/IEC 27001 and the General Data Protection Regulation (GDPR)
INCIDENT MANAGEMENT Adherence to the ISO framework will ensure that organisations
are in a position to rapidly detect and effectively manage a
Article 33 of the GDPR, requires organisations to Notify the ICO
personal data breach.
of a personal data breach without undue delay and not later than
72 hours after having become aware of a personal data breach.
The implementation of ISO 27001 control A.16.1 (Management
RISK ASSESSMENTS / PRIVACY IMPACT ASSESSMENTS
of information security incidents and improvements) will ensure
“a consistent and effective approach to the management One of the new requirements of the EU GDPR is the
of information security incidents, including communication implementation of Data Protection Impact Assessments, where
on security events.” Incident management is one of the key companies will have to first analyse the risks to their privacy.
processes to ensure the effectiveness of any business operation. The adoption of Privacy by Design, another GDPR requirement,
Security incident management is a critical control by ISO 27001 becomes mandatory in the development of products and
standards (clause A.13), and has an equal, if not higher, level systems. ISO 27001 helps ensure that “information security is an
of importance in other standards and frameworks. Incident integral part of information systems across the entire lifecycle.”
management forms an integral part of an organisation’s security
Where a new technology is being deployed that may affect
policies and procedures relating to backup, continuity, disaster
individuals’ rights and freedoms a privacy impact assessment
recovery (DR), risk management, and configuration management.
becomes necessary, The assessment should also contain a
To achieve this state of maturity, the following security incident
description of the measures envisaged to address the risks.
management processes must be included in the overall response
system: Risk assessment (and treatment) is the most important step at
the beginning of an ISO 27001 implementation project – it sets
• Clearly defined roles and responsibilities for the incident
the foundations for information security in your company.
response team.
ISO/IEC 27001 and the General Data Protection Regulation (GDPR) Gemserv
CONCLUSION the absence of a ‘privacy seal’ help demonstrate to Customers
and the Regulators GDPR compliance using ISO 27001 and
There are some key GDPR requirements that are not directly
ISO 27002.
covered in ISO 27001, such as key concepts of consent, fair
processing, data minimisation, storage limitation, the requirement The GDPR can be a daunting process for organisations
to appoint a Data Protection Officer and supporting the rights of considering the legal complexities and the financial ramifications
individuals relating to access, rectification, erasure and transfer of a loss of data, but those that were considering ISO 27001, or
of data. already have it in place, stand to benefit from a proactive stance
to information security. Almost any company that is operating
However, it is clear ISO 27001 provides a framework that
internationally will have to comply with this regulation. As
provides a solid foundation for GDPR compliance.
ISO 27001 is internationally and implemented all over the world,
The formation of an information security management system it may be the best option to facilitate immediate compliance with
enables organisations processing personal data to demonstrate GDPR.
that risks to personal data are being continuously reviewed,
updated and improved. An established ISMS is the perfect
framework to manage risks to all assets, inclusive of personal
data, and can provide assurance that the organisation takes
ISO 27001 and GDPR compliance seriously. In some cases,
controls can be precisely mapped to GDPR articles, where both
share identical content. In other instances, the controls pave
the way and little further work is required to achieve GDPR
compliance. Even where the GDPR diverts from the controls
found in the ISO framework, the core objectives do not differ
radically.
Gemserv ISO/IEC 27001 and the General Data Protection Regulation (GDPR)
For more information on ISO/IEC 27001 and the GDPR,
or if you would like to contact us for any other queries
please do so on:
@gemservinfosec
London Office:
8 Fenchurch Place
London
EC3M 4AJ