Guidepost Solutions
Our team, in collaboration with a cybersecurity partner, executed a comprehensive assessment of current practices related to privacy, security, and integrity of personally identifiable information (PII) related to various country regulations. We began with an assessment of the data, rather than with the regulations, which streamlined our compliance analysis to keep it strictly relevant to the activities of organization. We determined how applicable data privacy regulations of each nation, such as the General Data Privacy Regulation (“GDPR”) of the European Union and similar statutes and regulatory schemes, apply to the organization’s data and data handling procedures.
Our team mapped data flows and handling of PII and created Data Flow Diagrams (DFDs) which supported the assessment of legal requirements, including GDPR. Then we leveraged the DFDs and Center for Internet Security (CIS) Critical Security Controls (CSCs) framework to uncover any problematic gaps in privacy or information security to recommend remediation actions. The CIS CSCs are a concise, prioritized set of cyber practices created to stop today’s most pervasive and dangerous cyber-attacks.
This effort led to the design of a worldwide compliance program to cover all of the organization’s data collection and handling activities, even if it means doing more than is required in some nations. Additionally, we created a robust information security program to maintain compliance and readiness to respond to current and potential future legislation and regulations.