SlideShare a Scribd company logo
1 of 31
- Internal -
IS/DPP Baseline Training
E-learning - Intro
2
- Internal - Page
IS/DPP
INFORMATION SECURITY
DATA PROTECTION
PRIVACY
3
- Internal - Page
IS/DPP
INFORMATION SECURITY
DATA PROTECTION
PRIVACY
4
- Internal - Page
IS/DPP
INFORMATION SECURITY
DATA PROTECTION
PRIVACY
5
- Internal - Page
Why Do We Need Training?
6
- Internal - Page
Training Objectives
 Create awareness about IS/DPP
7
- Internal - Page
Training Objectives
 Create awareness about IS/DPP
 Give a high-level overview of the ACG policy framework on IS/DPP
 Refresh the basics and principles on IS/DPP
8
- Internal - Page
Training Objectives
 Create awareness about IS/DPP
 Give a high-level overview of the ACG policy framework on IS/DPP
 Refresh the basics and principles on IS/DPP
 Answer the question: “What is my role, as a staff member, in IS/DPP?”
 Give some guidance on good and bad practice.
9
- Internal - Page
Training Objectives
 Create awareness about IS/DPP
 Give a high-level overview of the ACG policy framework on IS/DPP
 Refresh the basics and principles on IS/DPP
 Answer the question: “What is my role, as a staff member, in IS/DPP?”
 Give some guidance on good and bad practice.
 Provide signposting to where you can find more information and guidance
11
- Internal - Page
What will You Learn?
 What is information classification? Why is it needed? What are the
different classification levels of data handled at ABC?
12
- Internal - Page
What will You Learn?
 What is information classification? Why is it needed? What are the
different classification levels of data handled at ABC?
 What are the general principles of IS/DPP?
13
- Internal - Page
What will You Learn?
 What is information classification? Why is it needed? What are the
different classification levels of data handled at ABC?
 What are the general principles of IS/DPP?
 What are “layers of defense”?
14
- Internal - Page
What will You Learn?
 What is information classification? Why is it needed? What are the
different classification levels of data handled at ABC?
 What are the general principles of IS/DPP?
 What are “layers of defense”?
 How do I, as a staff member, contribute to those layers of defense?
16
- Internal - Page
For ACG
17
- Internal - Page
Centrally
18
- Internal - Page
You
19
- Internal - Page
For You
20
- Internal - Page
For You
21
- Internal - Page
IS/DPP is not… (just) hacking
22
- Internal - Page
IS/DPP is also… social engineering.
23
- Internal - Page
IS/DPP is also… incidents.
24
- Internal - Page
IS/DPP is also… thinking like an attacker
25
- Internal - Page
IS/DPP is not… new
Code of Conduct:
I. I act fairly, honestly and transparently
II. I respect others
III. I comply with the law and professional standards
IV. I comply with instructions
V. I manage conflicts of interest
VI. I comply with data protection and information security
VII. I work in the customer’s best interest
VIII. I protect ABC’s interests
IX. I act professionally
X. I report any irregularity observed
Insert ABC’s code of conduct principles, e.g.
26
- Internal - Page
ABC IS/DPP Policy Framework
27
- Internal - Page
ABC IS/DPP Policy Framework
About continuously
Changes
• In the regulatory environment
• In processes
• In people (JLT)
• In technology
28
- Internal - Page
ABC IS/DPP Policy Framework
About continuously
Environment
Physical
Human
Device
Application
Repository
Carrier
Changes
• In the regulatory environment
• In processes
• In people (JLT)
• In technology
Network
Data
3rd Parties
29
- Internal - Page
Blocks in the Course
Environment
Physical
Human
Device
Application
Repository
Carrier
Changes
• In the regulatory environment
• In processes
• In people (JLT)
• In technology
Network
Data
3rd Parties
1. Introduction
2. Why?
3. Data (Classification)
4. Layers
5. Access
6. Acceptable Use
7. Incidents
8. Monitoring
30
- Internal - Page
More Information on IS/DPP at ABC
Intranet: (insert hyperlink)
31
- Internal - Page
Relevant Points of Contact
IT Helpdesk Incidents
Information Security Officer
ISO
Support relating to information security (=
overall + more technical side)
Data Protection Officer
DPO
Support relating to personal data protection
Information Asset Owner
IAO
Centralization of information /
documentation on an Information Asset
Human Resources
HR
Support on Join, Leave, Transfer
Procurement Unit Support on Relationships with Third Parties
Legal Unit Support on agreements
Marketing Unit Support on use of (personal) data for
marketing
Who is Who in IS/DPP?
32
- Internal - Page
What do we Expect of You?
General Mandatory “Please” “Pretty Please”
Baseline Test X
Baseline Videos X
Higher Belt Test X
Extra Videos X
Policies X
Guidelines X
Monitoring X
Useful links X
Target Group Mandatory “Please” “Pretty Please”
Classroom Training X
Test X
33
- Internal - Page
But Most of All…
IS/DPP

More Related Content

Similar to IS/DPP for staff #1 - intro

IS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - IncidentsIS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - IncidentsTommy Vandepitte
 
Part 1Strategic Management Case Study #6—IKEA (Case Study In.docx
Part 1Strategic Management Case Study #6—IKEA (Case Study In.docxPart 1Strategic Management Case Study #6—IKEA (Case Study In.docx
Part 1Strategic Management Case Study #6—IKEA (Case Study In.docxdanhaley45372
 
Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...
Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...
Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...Michael Scully
 
ARP_InformationSecurityLandscape_Report (1)
ARP_InformationSecurityLandscape_Report (1)ARP_InformationSecurityLandscape_Report (1)
ARP_InformationSecurityLandscape_Report (1)V_neha
 
Fundamentals of Information Systems Security Chapter 14
Fundamentals of Information Systems Security Chapter 14Fundamentals of Information Systems Security Chapter 14
Fundamentals of Information Systems Security Chapter 14Dr. Ahmed Al Zaidy
 
Big Data Framework - How to get started!
Big Data Framework - How to get started!Big Data Framework - How to get started!
Big Data Framework - How to get started!Mark Constable
 
IIBA Perth - Not so Risky Business with Ashley Aitken
IIBA Perth - Not so Risky Business with Ashley AitkenIIBA Perth - Not so Risky Business with Ashley Aitken
IIBA Perth - Not so Risky Business with Ashley AitkenAustraliaChapterIIBA
 
PSY 636 Short Paper Guidelines and Rubric Assignment instructi.docx
PSY 636 Short Paper Guidelines and Rubric Assignment instructi.docxPSY 636 Short Paper Guidelines and Rubric Assignment instructi.docx
PSY 636 Short Paper Guidelines and Rubric Assignment instructi.docxpotmanandrea
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...AIIM International
 
Bb0020 managing information
Bb0020  managing informationBb0020  managing information
Bb0020 managing informationsmumbahelp
 
5 Steps to Securing Your Company's Crown Jewels
5 Steps to Securing Your Company's Crown Jewels5 Steps to Securing Your Company's Crown Jewels
5 Steps to Securing Your Company's Crown JewelsIBM Security
 
Welingkar Presentation On Cobit And Iso 1799 And Bs 7799
Welingkar Presentation On Cobit And Iso 1799 And Bs 7799Welingkar Presentation On Cobit And Iso 1799 And Bs 7799
Welingkar Presentation On Cobit And Iso 1799 And Bs 7799Abhinav Goyal
 
Feb 26 NETP Slide Deck
Feb 26 NETP Slide DeckFeb 26 NETP Slide Deck
Feb 26 NETP Slide Deckddcomeau
 

Similar to IS/DPP for staff #1 - intro (19)

IS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - IncidentsIS/DPP for staff #7 - Incidents
IS/DPP for staff #7 - Incidents
 
Part 1Strategic Management Case Study #6—IKEA (Case Study In.docx
Part 1Strategic Management Case Study #6—IKEA (Case Study In.docxPart 1Strategic Management Case Study #6—IKEA (Case Study In.docx
Part 1Strategic Management Case Study #6—IKEA (Case Study In.docx
 
Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...
Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...
Itsi in-the-wild-why-micron-chose-splunk-it-service-intelligence-and-lessons-...
 
Funsec3e ppt ch14
Funsec3e ppt ch14Funsec3e ppt ch14
Funsec3e ppt ch14
 
ARP_InformationSecurityLandscape_Report (1)
ARP_InformationSecurityLandscape_Report (1)ARP_InformationSecurityLandscape_Report (1)
ARP_InformationSecurityLandscape_Report (1)
 
Information & Cyber Security Risk
Information & Cyber Security RiskInformation & Cyber Security Risk
Information & Cyber Security Risk
 
Fundamentals of Information Systems Security Chapter 14
Fundamentals of Information Systems Security Chapter 14Fundamentals of Information Systems Security Chapter 14
Fundamentals of Information Systems Security Chapter 14
 
Big Data Framework - How to get started!
Big Data Framework - How to get started!Big Data Framework - How to get started!
Big Data Framework - How to get started!
 
[2019] week03 systems & IS
[2019] week03 systems & IS[2019] week03 systems & IS
[2019] week03 systems & IS
 
IIBA Perth - Not so Risky Business with Ashley Aitken
IIBA Perth - Not so Risky Business with Ashley AitkenIIBA Perth - Not so Risky Business with Ashley Aitken
IIBA Perth - Not so Risky Business with Ashley Aitken
 
CISSP-WEB
CISSP-WEBCISSP-WEB
CISSP-WEB
 
PSY 636 Short Paper Guidelines and Rubric Assignment instructi.docx
PSY 636 Short Paper Guidelines and Rubric Assignment instructi.docxPSY 636 Short Paper Guidelines and Rubric Assignment instructi.docx
PSY 636 Short Paper Guidelines and Rubric Assignment instructi.docx
 
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
[Webinar Slides] Data Privacy for the IM Practitioner - Practical Advice for ...
 
Bb0020 managing information
Bb0020  managing informationBb0020  managing information
Bb0020 managing information
 
PACE-IT, Security+2.6: Security Related Awareness and Training
PACE-IT, Security+2.6: Security Related Awareness and TrainingPACE-IT, Security+2.6: Security Related Awareness and Training
PACE-IT, Security+2.6: Security Related Awareness and Training
 
5 Steps to Securing Your Company's Crown Jewels
5 Steps to Securing Your Company's Crown Jewels5 Steps to Securing Your Company's Crown Jewels
5 Steps to Securing Your Company's Crown Jewels
 
Session 01 02
Session 01 02Session 01 02
Session 01 02
 
Welingkar Presentation On Cobit And Iso 1799 And Bs 7799
Welingkar Presentation On Cobit And Iso 1799 And Bs 7799Welingkar Presentation On Cobit And Iso 1799 And Bs 7799
Welingkar Presentation On Cobit And Iso 1799 And Bs 7799
 
Feb 26 NETP Slide Deck
Feb 26 NETP Slide DeckFeb 26 NETP Slide Deck
Feb 26 NETP Slide Deck
 

More from Tommy Vandepitte

Gegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdrachtGegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdrachtTommy Vandepitte
 
20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)Tommy Vandepitte
 
GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)Tommy Vandepitte
 
Controller-to-processor agreements
Controller-to-processor agreementsController-to-processor agreements
Controller-to-processor agreementsTommy Vandepitte
 
Gegevensbescherming makelaars
Gegevensbescherming makelaarsGegevensbescherming makelaars
Gegevensbescherming makelaarsTommy Vandepitte
 
EEAS - Cultivate your data protection
EEAS - Cultivate your data protectionEEAS - Cultivate your data protection
EEAS - Cultivate your data protectionTommy Vandepitte
 
Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130Tommy Vandepitte
 
Training privacy by design
Training privacy by designTraining privacy by design
Training privacy by designTommy Vandepitte
 
GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)Tommy Vandepitte
 
GDPR project board deck (example)
GDPR project board deck (example)GDPR project board deck (example)
GDPR project board deck (example)Tommy Vandepitte
 
IS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - MonitoringIS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - MonitoringTommy Vandepitte
 
IS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable useIS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable useTommy Vandepitte
 
IS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - PasswordsIS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - PasswordsTommy Vandepitte
 
IS/DPP for staff #5a - Access
IS/DPP for staff #5a - AccessIS/DPP for staff #5a - Access
IS/DPP for staff #5a - AccessTommy Vandepitte
 
IS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data ClassificationIS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data ClassificationTommy Vandepitte
 
IS/DPP for staff #3a - Data
IS/DPP for staff #3a - DataIS/DPP for staff #3a - Data
IS/DPP for staff #3a - DataTommy Vandepitte
 
IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?Tommy Vandepitte
 
Training Information Asset Owners
Training Information Asset OwnersTraining Information Asset Owners
Training Information Asset OwnersTommy Vandepitte
 

More from Tommy Vandepitte (20)

DPIA template
DPIA templateDPIA template
DPIA template
 
Gegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdrachtGegevensbescherming-clausule in (overheids)opdracht
Gegevensbescherming-clausule in (overheids)opdracht
 
20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)20190131 - Presentation Q&A on legislation's influence (on travel management)
20190131 - Presentation Q&A on legislation's influence (on travel management)
 
GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)GDPR toegepast op huur-verhuur (Dutch)
GDPR toegepast op huur-verhuur (Dutch)
 
Controller-to-processor agreements
Controller-to-processor agreementsController-to-processor agreements
Controller-to-processor agreements
 
Gegevensbescherming makelaars
Gegevensbescherming makelaarsGegevensbescherming makelaars
Gegevensbescherming makelaars
 
EEAS - Cultivate your data protection
EEAS - Cultivate your data protectionEEAS - Cultivate your data protection
EEAS - Cultivate your data protection
 
Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130Presentation for the LSEC GDPR event - 20171130
Presentation for the LSEC GDPR event - 20171130
 
Training privacy by design
Training privacy by designTraining privacy by design
Training privacy by design
 
GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)GDPR voor steden en gemeenten (Dutch)
GDPR voor steden en gemeenten (Dutch)
 
GDPR project board deck (example)
GDPR project board deck (example)GDPR project board deck (example)
GDPR project board deck (example)
 
IS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - MonitoringIS/DPP for staff #8 - Monitoring
IS/DPP for staff #8 - Monitoring
 
IS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable useIS/DPP for staff #6 - Acceptable use
IS/DPP for staff #6 - Acceptable use
 
IS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - PasswordsIS/DPP for staff #5b - Passwords
IS/DPP for staff #5b - Passwords
 
IS/DPP for staff #5a - Access
IS/DPP for staff #5a - AccessIS/DPP for staff #5a - Access
IS/DPP for staff #5a - Access
 
IS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data ClassificationIS/DPP for staff #3b - Data Classification
IS/DPP for staff #3b - Data Classification
 
IS/DPP for staff #3a - Data
IS/DPP for staff #3a - DataIS/DPP for staff #3a - Data
IS/DPP for staff #3a - Data
 
IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?IS/DPP for staff #2 - Why?
IS/DPP for staff #2 - Why?
 
Training Procurement
Training ProcurementTraining Procurement
Training Procurement
 
Training Information Asset Owners
Training Information Asset OwnersTraining Information Asset Owners
Training Information Asset Owners
 

Recently uploaded

THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A Beña
 
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxMULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxAnupkumar Sharma
 
ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4MiaBumagat1
 
Food processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture honsFood processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture honsManeerUddin
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)lakshayb543
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designMIPLM
 
Full Stack Web Development Course for Beginners
Full Stack Web Development Course  for BeginnersFull Stack Web Development Course  for Beginners
Full Stack Web Development Course for BeginnersSabitha Banu
 
Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Celine George
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPCeline George
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Mark Reed
 
4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptx4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptxmary850239
 
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...JojoEDelaCruz
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...Nguyen Thanh Tu Collection
 
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptxAUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptxiammrhaywood
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptxmary850239
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...JhezDiaz1
 
Active Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdfActive Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdfPatidar M
 

Recently uploaded (20)

THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxMULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
 
ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4
 
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptxYOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
YOUVE_GOT_EMAIL_PRELIMS_EL_DORADO_2024.pptx
 
Food processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture honsFood processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture hons
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-design
 
Full Stack Web Development Course for Beginners
Full Stack Web Development Course  for BeginnersFull Stack Web Development Course  for Beginners
Full Stack Web Development Course for Beginners
 
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptxLEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
LEFT_ON_C'N_ PRELIMS_EL_DORADO_2024.pptx
 
Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERP
 
Raw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptxRaw materials used in Herbal Cosmetics.pptx
Raw materials used in Herbal Cosmetics.pptx
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)
 
4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptx4.16.24 21st Century Movements for Black Lives.pptx
4.16.24 21st Century Movements for Black Lives.pptx
 
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
 
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptxAUDIENCE THEORY -CULTIVATION THEORY -  GERBNER.pptx
AUDIENCE THEORY -CULTIVATION THEORY - GERBNER.pptx
 
4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx4.16.24 Poverty and Precarity--Desmond.pptx
4.16.24 Poverty and Precarity--Desmond.pptx
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
 
Active Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdfActive Learning Strategies (in short ALS).pdf
Active Learning Strategies (in short ALS).pdf
 

IS/DPP for staff #1 - intro

  • 1. - Internal - IS/DPP Baseline Training E-learning - Intro
  • 2. 2 - Internal - Page IS/DPP INFORMATION SECURITY DATA PROTECTION PRIVACY
  • 3. 3 - Internal - Page IS/DPP INFORMATION SECURITY DATA PROTECTION PRIVACY
  • 4. 4 - Internal - Page IS/DPP INFORMATION SECURITY DATA PROTECTION PRIVACY
  • 5. 5 - Internal - Page Why Do We Need Training?
  • 6. 6 - Internal - Page Training Objectives  Create awareness about IS/DPP
  • 7. 7 - Internal - Page Training Objectives  Create awareness about IS/DPP  Give a high-level overview of the ACG policy framework on IS/DPP  Refresh the basics and principles on IS/DPP
  • 8. 8 - Internal - Page Training Objectives  Create awareness about IS/DPP  Give a high-level overview of the ACG policy framework on IS/DPP  Refresh the basics and principles on IS/DPP  Answer the question: “What is my role, as a staff member, in IS/DPP?”  Give some guidance on good and bad practice.
  • 9. 9 - Internal - Page Training Objectives  Create awareness about IS/DPP  Give a high-level overview of the ACG policy framework on IS/DPP  Refresh the basics and principles on IS/DPP  Answer the question: “What is my role, as a staff member, in IS/DPP?”  Give some guidance on good and bad practice.  Provide signposting to where you can find more information and guidance
  • 10. 11 - Internal - Page What will You Learn?  What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?
  • 11. 12 - Internal - Page What will You Learn?  What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?  What are the general principles of IS/DPP?
  • 12. 13 - Internal - Page What will You Learn?  What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?  What are the general principles of IS/DPP?  What are “layers of defense”?
  • 13. 14 - Internal - Page What will You Learn?  What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?  What are the general principles of IS/DPP?  What are “layers of defense”?  How do I, as a staff member, contribute to those layers of defense?
  • 14. 16 - Internal - Page For ACG
  • 15. 17 - Internal - Page Centrally
  • 16. 18 - Internal - Page You
  • 17. 19 - Internal - Page For You
  • 18. 20 - Internal - Page For You
  • 19. 21 - Internal - Page IS/DPP is not… (just) hacking
  • 20. 22 - Internal - Page IS/DPP is also… social engineering.
  • 21. 23 - Internal - Page IS/DPP is also… incidents.
  • 22. 24 - Internal - Page IS/DPP is also… thinking like an attacker
  • 23. 25 - Internal - Page IS/DPP is not… new Code of Conduct: I. I act fairly, honestly and transparently II. I respect others III. I comply with the law and professional standards IV. I comply with instructions V. I manage conflicts of interest VI. I comply with data protection and information security VII. I work in the customer’s best interest VIII. I protect ABC’s interests IX. I act professionally X. I report any irregularity observed Insert ABC’s code of conduct principles, e.g.
  • 24. 26 - Internal - Page ABC IS/DPP Policy Framework
  • 25. 27 - Internal - Page ABC IS/DPP Policy Framework About continuously Changes • In the regulatory environment • In processes • In people (JLT) • In technology
  • 26. 28 - Internal - Page ABC IS/DPP Policy Framework About continuously Environment Physical Human Device Application Repository Carrier Changes • In the regulatory environment • In processes • In people (JLT) • In technology Network Data 3rd Parties
  • 27. 29 - Internal - Page Blocks in the Course Environment Physical Human Device Application Repository Carrier Changes • In the regulatory environment • In processes • In people (JLT) • In technology Network Data 3rd Parties 1. Introduction 2. Why? 3. Data (Classification) 4. Layers 5. Access 6. Acceptable Use 7. Incidents 8. Monitoring
  • 28. 30 - Internal - Page More Information on IS/DPP at ABC Intranet: (insert hyperlink)
  • 29. 31 - Internal - Page Relevant Points of Contact IT Helpdesk Incidents Information Security Officer ISO Support relating to information security (= overall + more technical side) Data Protection Officer DPO Support relating to personal data protection Information Asset Owner IAO Centralization of information / documentation on an Information Asset Human Resources HR Support on Join, Leave, Transfer Procurement Unit Support on Relationships with Third Parties Legal Unit Support on agreements Marketing Unit Support on use of (personal) data for marketing Who is Who in IS/DPP?
  • 30. 32 - Internal - Page What do we Expect of You? General Mandatory “Please” “Pretty Please” Baseline Test X Baseline Videos X Higher Belt Test X Extra Videos X Policies X Guidelines X Monitoring X Useful links X Target Group Mandatory “Please” “Pretty Please” Classroom Training X Test X
  • 31. 33 - Internal - Page But Most of All… IS/DPP

Editor's Notes

  1. Welcome to the IS/DPP baseline training. It is called a baseline training because it is a training for all staff, both internal and external, on the basics of IS/DPP. Some staff members may be requested to follow a level up training because they need some in depth knowledge on the topic in the context of their function or role.
  2. Information security is the broad domain of setting up technical and organisational measures to keep information confined to a number of authorized persons (confidentiality), to keep information unchanged so we can rely on the fact that the document we store or send to somebody is not tampered with (integrity), and to have the information available if and when needed (availability).
  3. Data Protection - in our context - relates to the protection of personal data as required by the law. In Belgium that is the 1992 Personal Data Protection Act. That act was later slightly amended to meet the requirements of a 1995 European Directive on the topic. As from 25 May 2018 that legislation will largely be replaced by the European General Data Protection Regulation (generally shortened to GDPR). We also keep in mind that next to that general data protection legislation, there are a number of specific statutes and regulations. For example the Payment Card Industry Data Security Standard (also known as PCI DSS), which applies to banks and payment institutions.
  4. Privacy is the human right legally protected in a number of international treaties and in constitutions. It is a concept that is not well-defined and to most people relates to their personsal perception of the things that are only shared with family and friend and to intimacy. And that is the main difference with data protection, which to a great extent abstracts from that personal perception.
  5. Why do we need training?
  6. This training has a few objectives. First off we consider it a way to create awareness on the topic.
  7. Second, we want to draw attention to the ABC Group policy framework by giving a high-level overview and by refreshing the basic principles.
  8. Third, we want to make the topic “alive” in your day to day job at ABC. We give some guidance on what is a good practice and what is not.
  9. And last, we want to promote the channels where we have posted more information and guidance on the topic.
  10. After this training we hope you will be able to explain what information classifcation is and why any organisation needs it. what th principles of IS/DPP are. what the layers of defense are. what your role is in all this.
  11. After this training we hope you will be able to explain what information classifcation is and why any organisation needs it.
  12. what the principles of IS/DPP are.
  13. what the layers of defense are.
  14. what your role is in all this.
  15. At ABC the TRUST of our customers is at the core of our business. Protecting the (personal) data of our customers is not only a legal obligation, but more importantly is a big part of gaining their trust. Some aspects of what we call “information security, data protection and privacy” (IS/DPP) are managed centrally, “behind the curtains”. Nevertheless a key role in making IS/DPP work is YOU, the individual staff member.
  16. At ABC the TRUST of our customers is at the core of our business. Protecting the (personal) data of our customers is not only a legal obligation, but more importantly is a big part of gaining their trust.
  17. Some aspects of what we call “information security, data protection and privacy” (IS/DPP) are managed centrally, “behind the curtains”.
  18. Nevertheless a key role in making IS/DPP work is YOU, the individual staff member.
  19. Using (personal) data just for the execution of your job and applying common sense in protecting that data, goes a long way. But it helps to be reminded of some principles of IS/DPP and lift the veil of what is happening centrally to make all of us and ABC Group as a whole even better at it.
  20. The topic is not only interesting to you as a staff member. You are also a data subject yourself who’s data is being processed by a number of companies on a daily basis.
  21. IS/DPP is more than just hacking. It is not only related to protection from highly skilled IT guys. There is a lot more to it than that.
  22. Information can be stolen, changed or deleted by a person who succeeds in talking his way through the security measures on the phone or even in our offices.
  23. We can also have a problem when you make a mistake or when we set up the access rights incorrectly.
  24. In any case, thinking of IS/DPP from an attackers point of view makes us more aware of (potential) vulnerabilities.
  25. IS/DPP is also not new. It is already in the code of conduct. As you will understand by the end of this training, rule number 6 is the explicit reference to information security and data protection, but most of the other rules have some relation to IS/DPP as well.
  26. IS/DPP for the ABC Group has been further worked out in a comprehensive framework. Due to the continuous changes in our operations, the legislation, potential attacks, etc. …
  27. this framework is continuously under construction. All policies of the framework will be communicated in full. However for the purpose of this training
  28. we have chosen to represent it visually as a layered structure.
  29. How does the course look? Well, we have chopped up this e-learning in different blocks. That way, we hope, you can more easily at look at them without taking you away from your job for too long. Also, should you want to revisit one of the topics, you should be able to do so quite easily. Additionally, it allows us to update one block, without having to re-work the entire video.
  30. In this training we will only touch upon the principles of IS/DPP. For more information we refer to the folder "company policies" on the intranet.
  31. You are an important part of ABC Group's defence. But you are not alone. There are a number of centers of competence you can go to. Here is a list with their functions. If you want to put a face to it, ask your line management or check the sharepoint webportal section “who is who in IS/DPP?”
  32. What do we expect of you? There is basically only one thing we actually require from you: pass the baseline test (yellow belt). However, we hope we can convince you to go beyond that and that you watch the other materials we have made available for you. If you are a member of a target group (IT, HR, procurement, project management, …) you will additionally be requested to follow a classroom training and/or a specific test.
  33. The test is one thing. Our call to action for you is simple: help us protect ABC Group’s data. And for that… thank you.