Part and parcel of operating with a watertight set of privacy protection controls is acknowledging the need to continually monitor, asses and improve organisational adherence with
PII-related objectives and legal/regulatory requirements.
ISO 27701 Control 5.7 sets out a clear set of guidelines that inform organisations on how to assess their own performance, and equally as important, how to enact meaningful change so that privacy protection remains at the forefront of their broader information security policy.
ISO 27701 Clause 5.7 contains three sub-clauses that deal with the three main constituent parts of privacy protection evaluation – monitoring, auditioning and review.
Each sub-clause is linked to an accompanying set of information security guidelines from ISO 27001:
Clause 5.7 lacks any additional guidance on how to apply performance evaluation guidelines within the context of a PIMs, nor does it feature any guidance within the scope of GDPR.
Organisations need to constantly monitor and evaluate how they perform from a privacy protection standpoint, and how efficient their PIMS is within the scope of their stated objectives.
In doing so, organisations need to establish:
As with all other privacy protection and PII-related activities, a thorough record of all monitoring activities needs to be kept in the form of official documentation.
Organisations need to be mindful of their responsibility to their own data and processes, by carrying out planned audits at appropriate intervals.
Audits need to establish:
To achieve these objectives, organisations should:
Senior management plays a key role in ensuring the viability and effectiveness of any privacy protection policy or PIMS implementation.
When reviewing organisational adherence to PII-related controls, policies and procedures, management should include:
All reviews should be thoroughly documented for future analysis, and to ensure continuity from one review to the next.
ISO 27701 Clause Identifier | ISO 27701 Clause Name | ISO 27001 Requirement | Associated GDPR Articles |
---|---|---|---|
5.7.1 | Monitoring, Measurement, Analysis and Evaluation | 9.1 – Monitoring, Measurement, Analysis and Evaluation for ISO 27001 | None |
5.7.2 | Internal Audit | 9.2 – Internal Audit for ISO 27001 | None |
5.7.3 | Management Review | 9.3 – Management Review for ISO 27001 | None |
The ISMS.online platform has built-in guidance at each step combined with our ‘Adopt, Adapt, Add’ implementation approach so the effort required to achieve ISO 27701 is substantially reduced.
You will also benefit from a range of powerful time-saving features.
Explore the benefits with ISMS.online by booking a demo.
Book a tailored hands-on session
based on your needs and goals
Book your demo
We can’t think of any company whose service can hold a candle to ISMS.online.