Search
×
FR

Placeholder headline

This is just a placeholder headline

TEMA 2026 Edition – Online Subscription Only

$

BUY NOW

Placeholder headline

This is just a placeholder headline

API RP 15SIH, 2nd Edition: Installation and Handling of Spoolable Reinforced Plastic Line Pipe

$

158

BUY NOW

Placeholder headline

This is just a placeholder headline

API RP 754, 4th Edition: Process Safety Performance Indicators for the Refining and Petrochemical Industries

$

393

BUY NOW

Placeholder headline

This is just a placeholder headline

ASME B31.1-2020: Power Piping

$

668

BUY NOW

Placeholder headline

This is just a placeholder headline

ASME B31.1-2022: Power Piping

$

668

BUY NOW

ISO 27557:2022

ISO 27557:2022 Information security, cybersecurity and privacy protection – Application of ISO 31000:2018 for organizational privacy risk management

CDN $262.00

Description

This document provides guidelines for organizational privacy risk management, extended from ISO 31000:2018.

This document provides guidance to organizations for integrating risks related to the processing of personally identifiable information (PII) as part of an organizational privacy risk management programme. It distinguishes between the impact that processing PII can have on an individual with consequences for organizations (e.g. reputational damage). It also provides guidance for incorporating the following into the overall organizational risk assessment:

-    organizational consequences of adverse privacy impacts on individuals; and

-    organizational consequences of privacy events that damage the organization (e.g. by harming its reputation) without causing any adverse privacy impacts to individuals.

This document assists in the implementation of a risk-based privacy program which can be integrated in the overall risk management of the organization.

This document is applicable to all types and sizes of organizations processing PII or developing products and services that can be used to process PII, including public and private companies, government entities, and non-profit organizations.

Edition

1

Published Date

2022-11-04

Status

PUBLISHED

Pages

19

Language Detail Icon

English

Format Secure Icon

Secure PDF

Abstract

This document provides guidelines for organizational privacy risk management, extended from ISO 31000:2018.

This document provides guidance to organizations for integrating risks related to the processing of personally identifiable information (PII) as part of an organizational privacy risk management programme. It distinguishes between the impact that processing PII can have on an individual with consequences for organizations (e.g. reputational damage). It also provides guidance for incorporating the following into the overall organizational risk assessment:

-    organizational consequences of adverse privacy impacts on individuals; and

-    organizational consequences of privacy events that damage the organization (e.g. by harming its reputation) without causing any adverse privacy impacts to individuals.

This document assists in the implementation of a risk-based privacy program which can be integrated in the overall risk management of the organization.

This document is applicable to all types and sizes of organizations processing PII or developing products and services that can be used to process PII, including public and private companies, government entities, and non-profit organizations.

Previous Editions

Can’t find what you are looking for?

Please contact us at: