Alongside the implementation of specific policies and the PIMS itself, organisations need to be mindful of how to both support and disseminate their broader privacy protection and PIMS-related activities, both internally and externally, to ensure continued adherence.
ISO 27701 5.5 addresses the concept of support in four main areas:
To articulate the various privacy protection, PII and PIMS-related guidelines, ISO 27701 5.5 relies heavily on the guidance contained within ISO 27001 section 7 (Support).
ISO 27701 5.5 contains four sub-clauses that take each element of organisational support activity in turn:
Unlike most other clauses in ISO 27701, clause 5.5 doesn’t contain any additional guidance that is applicable to the implementation of a PIMS, nor are any of its sub-clauses relevant to articles contained within GDPR legislation.
Organisations need to ensure that they have adequate resources to plan, implement and improve a PIMS that meets their stated privacy protection objectives.
Anyone who works on controls, policies and/or procedures that deal with organisational privacy protection should have the necessary competence to do so.
To safeguard PII and prevent against accidental exposure or loss of data, organisations should:
Promoting awareness of a PIMS and organisational privacy protection policy is paramount in ensuring adherence to broader information security and PII objectives.
Individuals doing work that has the potential to impact privacy protection should be explicitly aware of:
Book a tailored hands-on session
based on your needs and goals
Book your demo
As with most other business functions, efficient communication (both internal and external) should be front and centre of any organisational privacy protection efforts.
When implementing or changing a privacy protection policy or procedure, or making announcements about a PIMS or PII-related matter, organisation’s should decide:
how to communicate (i.e. what channels or media, and any processes that need to be followed, including initial drafting and approval).
ISO 27701 Clause Identifier | ISO 27701 Clause Name | ISO 27001 Requirement | Associated GDPR Articles |
---|---|---|---|
5.5.1 | Resources | 7.1 – Resources for ISO 27001 | None |
5.5.2 | Competence | 7.2 – Competence for ISO 27001 | None |
5.5.3 | Awareness | 7.3 – Awareness for ISO 27001 | None |
5.5.4 | Communication | 7.4 – Communication for ISO 27001 | None |
The ISMS.online platform has built-in guidance at each step combined with our ‘Adopt, Adapt, Add’ implementation approach so the effort required to achieve ISO 27701 is substantially reduced.
You will also benefit from a range of powerful time-saving features.
See all our features in action by booking a demo.
Book a tailored hands-on session
based on your needs and goals
Book your demo
We can’t think of any company whose service can hold a candle to ISMS.online.