Information Classification, PESTLE and Privacy Policies

Information Classification

Summary

In ISO 27001 a requirement exists about information classification.

It is what it says on the tin. You classify information based upon its sensitivity to the organisation.

Another way of thinking about this is…

If the Confidentiality, Availability or Integrity (CIA) of that information was to be compromised in any way, what would the damage to your business be?

➕ Additional Information: Privilege Management Template

PESTLE Analysis

Summary

PESTLE - Political, Economic, Sociological, Technological, Legal & Environmental.

With any business comes an operating environment that adds complexity.

This consist the regulatory environment, customer requirements, industry standards as well as things such as political elements that can externally influence the organisation.

In ISO standards PESTLE analysis is a good way of understanding the context of your organisation. This way you can monitor it to prevent external issues creeping up on you.

➕ Additional Information: PESTLE Template

Privacy Policies

Summary

Privacy policies need to get better. Most of them are so bad its untrue.

They need to be written in a clear, concise and unambiguous manner.

That means nothing like this:-

  • We may

  • At our discretion

  • Possibly

  • Could

Statements must be definitive.

Anyway, enough of me moaning about bad privacy policies. Please see the template attached for something hopefully useful, please share it and we can get rid of shit privacy policies once and for all.

🔗 Additional Information: Privacy Policy Template

Previous
Previous

Privilege Management, SMART Objectives and Design Controls

Next
Next

UK MDR Transition Periods, Audit Tips and Compliance Matrices