Information Classification, PESTLE and Privacy Policies
Information Classification
Summary
In ISO 27001 a requirement exists about information classification.
It is what it says on the tin. You classify information based upon its sensitivity to the organisation.
Another way of thinking about this is…
If the Confidentiality, Availability or Integrity (CIA) of that information was to be compromised in any way, what would the damage to your business be?
➕ Additional Information: Privilege Management Template
PESTLE Analysis
Summary
PESTLE - Political, Economic, Sociological, Technological, Legal & Environmental.
With any business comes an operating environment that adds complexity.
This consist the regulatory environment, customer requirements, industry standards as well as things such as political elements that can externally influence the organisation.
In ISO standards PESTLE analysis is a good way of understanding the context of your organisation. This way you can monitor it to prevent external issues creeping up on you.
➕ Additional Information: PESTLE Template
Privacy Policies
Summary
Privacy policies need to get better. Most of them are so bad its untrue.
They need to be written in a clear, concise and unambiguous manner.
That means nothing like this:-
We may
At our discretion
Possibly
Could
Statements must be definitive.
Anyway, enough of me moaning about bad privacy policies. Please see the template attached for something hopefully useful, please share it and we can get rid of shit privacy policies once and for all.
🔗 Additional Information: Privacy Policy Template