RELATIONSHIP BETWEEN THE ISO SERIES OF STANDARDS AND OTHER PRODUCTS OF ISO/TC 46/SC 11: 1. Records processes and controls 2012

Size: px
Start display at page:

Download "RELATIONSHIP BETWEEN THE ISO SERIES OF STANDARDS AND OTHER PRODUCTS OF ISO/TC 46/SC 11: 1. Records processes and controls 2012"

Transcription

1 RELATIONSHIP BETWEEN THE ISO SERIES OF STANDARDS AND OTHER PRODUCTS OF ISO/TC 46/SC 11: Records processes and controls White paper written by ISO TC46/SC11- Archives/records management Date: March PURPOSE This paper explains the relationship between the first two management systems for records (MSR) standards and the related standards and technical reports produced by ISO TC46/SC11 Archives/Records Management. The first two products are: ISO 30300:2011. Information and documentation Management systems for records - Fundamentals and vocabulary ISO 30301:2011. Information and documentation Management systems for records Requirements This paper clarifies how the related technical products can be used to support/implement the MSR standard/s, and attempts to show the interrelationship between the two with regard to records processes and controls. 2 BACKGROUND On November 2011 the two first products of the ISO Standards series Management systems for records were published. The ISO series offers the methodology to implement an MSR based on a systematic approach to the creation and management of records, aligned with organizational objectives and strategies. ISO 30300:2011 MSR - Fundamentals and vocabulary explains the rationale behind the creation of an MSR, the guiding principles for its successful implementation, and provides the terminology which ensures that it is compatible with other management systems standards. ISO 30301:2011 MSR - Requirements specifies the requirements necessary to develop a records policy. It also sets objectives and targets for an organization to implement systemic improvements. This is achieved through designing records processes and systems, estimating the appropriate allocation of resources, and establishing benchmarks to monitor, measure and evaluate outcomes. These steps help to ensure that corrective action can be taken and

2 continuous improvements are built into the system in order to support an organization in achieving its mandate, mission, strategy and goals. Many questions were raised about the relationship, similarities and differences between ISO and other Standards and Technical Reports developed by ISO TC46/SC11 during the development process and since its publication. The previously published products are aimed at the records professional community, whereas the ISO series has been developed primarily for a management audience. 3 MAIN CONCEPTS 3.1 MANAGEMENT SYSTEMS FOR RECORDS In general, the word system is used to describe different concepts and ideas and requires interpretation to be placed in the context in which it is being used. In the records domain, system is also used for a set of three related, but different concepts. The first clarification needed is what is a Management system for records? The following table provides the meaning of system within the MSR framework, shows the three different levels in which the word system could be used, and indicates how the concept is identified at the three levels in ISO and ISO System levels in records domain System level in a MSR Named in ISO series as: Named in ISO as: Set of interrelated or interacting elements of an organization to establish policies and objectives, and processes to achieve those objectives related to records MSR Not named. Out of scope System/programme that regulates the creation, reception, maintenance, use and disposition of records Records processes controls and Records programme Information system which captures, manages and provides access to records over time Records system Records system Illustration 1

3 3.2 STRATEGIC AND OPERATIONAL LEVEL Management systems for records (MSR) are based on a continuous improvement approach which is common to other management systems such as ISO 9000, ISO MSR is intended to build a framework to manage records at the strategic level. Strategic level Management system for records ( (ISO & ISO 30301) Records management ( ISO & 2) Records processes (ISO Work process analysis ISO Digitization ISO Metadata) Records system (ISO ) Operational level Relationships of ISO MSR series products and ISO series products ( Source: Xiaomi An, November 12, 2011 The Second National Forum on Electronic Records Management, Beijing, China ) Illustration 2 The operational elements of a MSR are described as Records Processes and Controls in the normative Annex A of ISO This Annex is strongly linked to ISO (the foundation standard of ISO TC46/SC11) and the best practices described in ISO have been converted into requirements for the Operation section (section 8 + Annex A). In a MSR framework, the design of records processes and controls is based on the records policy and objectives, after the assessment of risks. The Operation section of ISO establishes requirements for the implementation of records processes and controls in records systems.

4 TC46/SC11. Archives/records management Implementation of records processes in records systems Best practices of converted to requirements: Annex A Records systems mainly IT systems for both paper/electronic records Design of record processes in an MSR environment Policy Objectives Risks Processes Controls Carlota Bustelo. Convenor of WG9- Management systems for records. Requirements carlota@carlotabustelo.com Source: Carlota Bustelo and Judith Ellis. What is ISO 30300? Who, when, where, why and how Judith Ellis. Convenor of WG08. Management systems for records. Fundamentals and vocabulary judithellis@enterpriseknowledge.com.au to implement. Innova.doc. Barcelona (Spain), October Terms and Definitions Illustration 3 ISO defines terms and definitions applicable to the MSR standards. It contains some terms that are identical to or adapted from ISO plus other terms. A separate white paper will be available on the terminology used specifically in the MSR series of standards.

5 4 RELATIONSHIPS ISO ANNEX A / OTHER STANDARDS AND TECHNICAL REPORTS Controls in Annex A of are directly related to the technical information provided in the related standards. For a complete understanding a full reading of these technical standards is recommended. The following table is a guidance tool that links the MSR Control requirements from ISO to the most relevant clauses where technical information can be found in each related standards and technical reports. Other information related to a particular requirement can be found within other clauses that are not specifically highlighted here, as records processes and controls are often interrelated. The technical information can be used to implement the operational elements necessary to meet the MSR requirements. ISO TC46/SC11 standards and technical reports referred in the following table ISO : Information and documentation Records management General ISO/TR : Information and documentation Records management Guidelines ISO/TR 26122: Information and documentation -- Work process analysis for records ISO : Information and documentation Records management processes Metadata for records ISO : Information and documentation Records management processes Metadata for records Conceptual and implementation issues ISO/TR 13028: Information and documentation Implementation guidelines for digitization of records ISO :2010. Information and documentation Principles and functional requirements for records in electronic office environments -- Part 1: Overview and statement of principles ISO : Information and documentation Principles and functional requirements for records in electronic office environments -- Part 2: Guidelines and functional requirements for digital records management systems ISO :2010. Information and documentation Principles and functional requirements for records in electronic office environments -- Part 3: Guidelines and functional requirements for records in business systems

6 A All operational, reporting, audit and other stakeholders' needs for information (captured as records with appropriate metadata) about the organization's processes shall be identified and documented systematically.. Cl. 9.1 Determining documents to be captured into a records system - ISO Cl Determining documents to be captured into a records system - ISO/TR Cl. 4.2 Records dimension of work process analysis - ISO Cl. 5.1 Records management metadata that should be applied in the organization - ISO Cl. 3.1 Records related principles Cl Create -ISO Cl. 2.3 Determining needs for evidence of events, transactions and decisions in business systems A A Requirements for creating, capturing and managing records, and decisions not to capture records for specific processes, shall be determined based on business, legal and other requirements, documented and authorized. Records shall be created at the time of (or soon after) the transaction or incident to which they relate by individuals who have direct knowledge of the facts or by instruments routinely used by the organization to conduct the transaction.. Cl. 9.1 Determining documents to be captured into a records system Cl. 5 Regulatory environment,. Cl Determining documents to be captured into a records system Cl. 3.2 Design and implementation of a records system - ISO Cl. 5.1 Records management metadata that should be applied in the organization - ISO/TR Cl. 6.3 Digitization process management. Cl. 9.1 Determining documents to be captured into a records system. Cl Determining documents to be captured into a records system -ISO

7 Cl Metadata at the point of record capture -ISO Cl Metadata capture A A A A A A procedure shall be established to determine retention periods for records according to the requirements of each work process. Decisions about retention and disposition of records based on business, legal and other identified requirements shall be documented in a disposition schedule. Methods of integrating the capture of records with business processes shall be decided upon and documented. The information needed to identify the records of each work process, including identifying the section of the organization responsible for those records and the work process, shall be determined and documented as part of the records requirements. The points at which the information is captured in or added to the records and from what sources shall be identified in the procedures for each work process.. Cl. 9.2 Determining how long to retain records Cl Determining how long to retain records. Cl. 9.2 Determining how long to retain records Cl Records disposition authority Cl Determining how long to retain records. Cl. 7.1 Principles of records management programmes Cl Create -ISO Cl. 3.1 Creating records in context CI. 8.4 Design and implementation methodology CI Documenting records management processes. Cl. 3.2 Design and implementation of a records system - ISO/TR Cl. All Cl. 9.3 Records capture Capture -ISO

8 Cl Metadata at the point of record capture Cl Metadata after record capture -ISO Cl Metadata capture A A A The information, and the form and structure of the information, required as records for each work process, shall be identified and documented. Technologies for creating and capturing records shall be selected for each work process (whether automated or manual). The selection and any change of technologies shall be documented. For work processes which require evidence of capture, a procedure for registering records by attaching a unique identifier at the time of capture shall be implemented. The procedure shall ensure that no transactions involving the record can take place before registration is completed. A The records shall be grouped (classified) according to the Cl. 7.2 Characteristics of a record Cl Identification of requirements for records - ISO Cl. 8 Metadata model for managing records -ISO Cl Storage in specified formats Cl. 8.3 Designing and implementing records systems 8.5 Discontinuing records systems Cl Design of a records system Cl Create - ISO Cl. 3.1 Creating records in context CI. 9.4 Registration Cl Register - ISO Cl Registration ISO Cl Identification - unique identifiers

9 work processes to which they are related. Cl. 9.5 Classification Cl Business activity classification Cl Classification - ISO Cl. 8.4 Metadata structures - ISO Cl. 7.1 Aggregations -ISO Cl Records aggregations Cl Classification -ISO Cl Records classification A The scheme for grouping (classifying) the records reflecting the nature, number and complexity of the work processes of the organization shall be documented (including changes over time) and implemented as part of the procedures of those work processes. Cl. 9.5 Classification Cl Business activity classification -ISO Cl Business classification scheme A The descriptive and control information (metadata elements) required to create and control the records for each work process shall be identified and documented. Cl. 9.3 Records capture Cl. 9.4 Registration Cl. 9.5 Classification Cl. 9.8Tracking -ISO /TR Cl Capture Cl Registration Cl Access and security classification Cl Use and tracking -ISO/TR 26122

10 Cl. 4.2 Records dimension of work process analysis Cl General Cl Outcomes of the analysis of the sequence of transactions in a process Cl. 7.9 Outcomes of the analysis of the links to other processes -ISO Cl. All -ISO Cl. All -ISO/TR Cl Metadata A A Records processes which need to be recorded in metadata linked to the record event history shall be defined. Procedures shall be established to link the event history to the records and to maintain it for as long as the records themselves. Decisions about what metadata are required to identify, manage and control records throughout the organization, and externally, shall be documented and implemented. Cl. 9.8 Tracking Cl Use and tracking -ISO Cl Metadata after record capture Cl. 8.3 Points throughout the existence of records when metadata should be created and applied - ISO Cl. 9.4 Event plan metadata Cl. 9.5 Event history metadata -ISO Cl Records management process metadata Cl. 9.3 Records capture Cl. 9.4 Registration Cl. 9.5 Classification Cl. 9.8 Tracking Cl Vocabulary Cl Development of security and access classification

11 Cl Capture Cl Registration Cl Access and security classification Cl Use and tracking -ISO Cl. All -ISO Cl. All -ISO/TR Cl All digitised images should be assigned metadata to document digitising processes and to support ongoing business processes A A Rules shall be established for regulating access to records based on work process requirements, relevant legislation and, if appropriate, commercial considerations. These shall be documented and maintained for as long as the records are required. The access rules shall be implemented in the records systems by assigning access status to both records and individuals. Cl Integrity Cl Access, retrieval and use Cl Principal instruments Cl Security and access classification scheme Cl Access and security classification -ISO/TR Cl. 4.2 Records dimension of work process analysis Cl Access, retrieval and use Cl Principal instruments Cl Security and access classification scheme Cl Access and security classification - ISO Cl Metadata supporting the security of records -ISO Cl Maintain

12 A Procedures shall be implemented to ensure the integrity/security of the records and to prevent unauthorized use, modification, removal, concealment and/or destruction. Cl Authenticity Cl Integrity Cl Access, retrieval and use Cl Continuing retention Cl Security and access classification scheme Cl Access and security classification Cl Records storage decisions Cl Use and tracking -ISO Cl. 5 Purpose of records management metadata Cl Authenticity and fixity of metadata - ISO Cl Purposes of metadata for managing records -ISO TR Cl All digitised images should be assigned metadata to document digitising processes and to support ongoing business processes -ISO Cl Maintain -ISO Cl Online security processes A The means of maintaining/storing the records shall meet the relevant standards for the medium and technology used in order to ensure they remain useable for as long as required. Cl Distributed management Cl. 9.6 Storage and handling -ISO Cl Records storage decisions Cl Digital storage Cl Continuing retention Cl Transfer of custody or ownership of records -ISO TR 13028

13 CI Storage media and procedures should be defined, documented and implemented A A A Procedures shall be established and implemented to ensure that digital records remain accessible and meaningful over time, also outside the context of their creation. Restrictions, including use of encryption, shall be removed after a stated period Procedures shall be established for reviewing, authorizing and implementing decisions on retention and disposition of the records of each work process.. Cl Usability Cl Conversion and migration Cl Continuing retention -ISO Cl. 11 Implementing metadata for managing records -ISO TR Cl Digitised records should be managed in a way that allows their continued existence for as long as they are required -ISO Cl Migration, export and destruction ISO Cl. 3.3 Supporting import, export and interoperability. Cl. 9.7 Access Cl Security and access classification scheme - ISO Cl Metadata supporting the security of records -ISO Cl Maintain Cl Retention and disposition Cl. 9.2 Determining how long to retain records Cl. 9.9 Implementing disposition - ISO Cl Records disposition authority - ISO/TR 26122

14 Cl. All - ISO Cl. 9.6 Metadata about records management processes - ISO Cl. 9.4 Event plan metadata Cl Creating metadata for managing records Cl Metadata as control tools for managing records Cl Appraisal - ISO/TR Cl. 6.5 Records disposition - ISO Cl. 3 Guiding principles Cl. 5.6 Retention and disposition - ISO Cl. 3.4 Retaining and disposing of records as required A A Decisions about the transfer, removal or destruction of records shall be authorized and documented. Procedures for authorized and controlled transfer of records to another organization or system shall be Cl. 9.9 Implementing disposition Cl Implementation of disposition - ISO/TR Cl. 6.5 Records disposition - ISO Cl. 3 Guiding principles Cl. 5.6 Retention and disposition - ISO Cl. 3.3 Supporting import, export and interoperability Cl. 3.4 Retaining and disposing of records as required

15 established and implemented. Cl. 9.9 Implementing disposition Cl Implementation of disposition -ISO Cl Metadata after record capture - ISO Cl Appraisal Cl Transferring records - ISO/TR Cl. 6.5 Records disposition - ISO Cl. 3 Guiding principles Cl. 5.6 Retention and disposition - ISO Cl. 3.4 Retaining and disposing of records as required - ISO (to be published) Cl. all A Procedures for authorized, regular removal of records which are no longer required, including removal to off-site or off-line storage, shall be established and implemented. Cl. 8.5 Discontinuing records Systems Cl. 9.6 Storage and handling Cl. 9.9 Implementing disposition Cl Implementation of disposition - ISO/TR Cl. 6.5 Records disposition - ISO Cl. 3 Guiding principles Cl. 5.6 Retention and disposition

16 - ISO Cl. 3.4 Retaining and disposing of records as required A A A Records authorized for destruction shall be destroyed under appropriate supervision. The destruction shall be documented. Where the nature and complexity of the business and formal accountabilities require it, control information (registration, identification and history metadata) about records which have been destroyed shall be retained. All records systems (including business systems which keep records) shall be clearly identified, assigned to a responsible owner and documented in an inventory which is regularly updated. Cl. 9.9 Implementing disposition Cl Implementation of disposition - ISO Cl. 3 Guiding principles Cl. 5.6 Retention and disposition - ISO Cl. 3.4 Retaining and disposing of records as required Cl. 9.9 Implementing disposition - ISO Cl Implementation of disposition - ISO Cl Metadata after record capture - ISO Cl Appraisal ISO Cl. 3 Guiding principles Cl. 5.6 Retention and disposition - ISO Cl. 3.4 Retaining and disposing of records as required Cl Record metadata -ISO Cl Step D: Assessment of existing systems -ISO

17 Cl. 2 Good practice: digital records and the role of software A A Implementation decisions on records systems shall be documented, maintained and made available to all users who need them. Rules shall be established, documented and maintained for regulating access to records systems in order to undertake system administration tasks. -ISO Cl Step G: Implementation of a records system -ISO/TR Cl. 6.4 Management systems -ISO Cl. 4 Implementation issues -ISO Cl Access controls Cl Establishing security control Cl Assigning security levels -ISO Cl Online security processes A Procedures for operational maintenance shall be established to ensure records systems' availability. -ISO Appendices B. Integrating records considerations into the systems development life cycle A A A Regular monitoring of the performance of records systems against business requirements and records objectives shall be implemented and documented. Procedures shall be provided to ensure and demonstrate that any system malfunction, upgrade or regular maintenance does not affect records integrity. Changes in records systems, particularly exceptional operations (such as migration, integration of new requirements, computer technology change or discontinuation), shall be analysed, planned and implemented. Decisions made shall be documented. -ISO Cl Step H: Post-implementation review Cl. 8.2 Records systems characteristics ISO Cl Back-up and recovery - ISO Implementation Cl. 8.5 Discontinuing records systems -ISO (to be published). Cl. all

ISO TC46/SC11 Archives/records management

ISO TC46/SC11 Archives/records management ISO TC46/SC11 Archives/records management GUIDANCE FOR IMPLEMENTING DOCUMENTED INFORMATION CLAUSE USING PROCESSES AND CONTROLS OF ISO 30301:2011 Management system for records EXPLANATORY PAPER NOVEMBER

More information

ISO INTERNATIONAL STANDARD. Information and documentation Records management Part 1: General

ISO INTERNATIONAL STANDARD. Information and documentation Records management Part 1: General Provläsningsexemplar / Preview INTERNATIONAL STANDARD ISO 15489-1 First edition 2001-09-15 Information and documentation Records management Part 1: General Information et documentation «Records management»

More information

Australian Standard. Records Management. Part 1: General AS ISO ISO

Australian Standard. Records Management. Part 1: General AS ISO ISO AS ISO 15489.1 2002 ISO 15489-1 AS ISO 15489.1 Australian Standard Records Management Part 1: General [ISO title: Information and documentation Records management Part 1: General] This Australian Standard

More information

A S ISO Records Management Part 1: General

A S ISO Records Management Part 1: General AS ISO 15489.1 2002 ISO 15489-1 AS ISO 15489.1 Australian Standard Records Management Part 1: General [ISO title: Information and documentation Records management Part 1: General] This Australian Standard

More information

Australian Standard. Records Management. Part 2: Guidelines AS ISO ISO TR

Australian Standard. Records Management. Part 2: Guidelines AS ISO ISO TR AS ISO 15489.2 2002 ISO TR 15489-2 AS ISO 15489.2 Australian Standard Records Management Part 2: Guidelines [ISO title: Information and documentation Records management Part 2: Guidelines] This Australian

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO 15489-1 Second edition 2016-04-15 Information and documentation Records management Part 1: Concepts and principles Information et documentation Gestion des documents d activité

More information

ISO Information and documentation Digital records conversion and migration process

ISO Information and documentation Digital records conversion and migration process INTERNATIONAL STANDARD ISO 13008 First edition 2012-06-15 Information and documentation Digital records conversion and migration process Information et documentation Processus de conversion et migration

More information

SOUTH AFRICAN NATIONAL STANDARD

SOUTH AFRICAN NATIONAL STANDARD ISBN 978-0-626-32708-8 ISO 15489-1:2001 SOUTH AFRICAN NATIONAL STANDARD Information and documentation Records management Part 1: General This national standard is the identical implementation of ISO 15489-1:2001,

More information

Chain of Preservation Model Diagrams and Definitions

Chain of Preservation Model Diagrams and Definitions International Research on Permanent Authentic Records in Electronic Systems (InterPARES) 2: Experiential, Interactive and Dynamic Records APPENDIX 14 Chain of Preservation Model Diagrams and Definitions

More information

ISO/TR TECHNICAL REPORT. Information and documentation Implementation guidelines for digitization of records

ISO/TR TECHNICAL REPORT. Information and documentation Implementation guidelines for digitization of records TECHNICAL REPORT ISO/TR 13028 First edition 2010-12-01 Information and documentation Implementation guidelines for digitization of records Information et documentation Mise en œuvre des lignes directrices

More information

PRINCIPLES AND FUNCTIONAL REQUIREMENTS

PRINCIPLES AND FUNCTIONAL REQUIREMENTS INTERNATIONAL COUNCIL ON ARCHIVES PRINCIPLES AND FUNCTIONAL REQUIREMENTS FOR RECORDS IN ELECTRONIC OFFICE ENVIRONMENTS RECORDKEEPING REQUIREMENTS FOR BUSINESS SYSTEMS THAT DO NOT MANAGE RECORDS OCTOBER

More information

Terms in the glossary are listed alphabetically. Words highlighted in bold are defined in the Glossary.

Terms in the glossary are listed alphabetically. Words highlighted in bold are defined in the Glossary. Glossary 2010 The Records Management glossary is a list of standard records terms used throughout CINA s guidance and training. These terms and definitions will help you to understand and get the most

More information

ISO INTERNATIONAL STANDARD. Information and documentation Managing metadata for records Part 2: Conceptual and implementation issues

ISO INTERNATIONAL STANDARD. Information and documentation Managing metadata for records Part 2: Conceptual and implementation issues INTERNATIONAL STANDARD ISO 23081-2 First edition 2009-07-01 Information and documentation Managing metadata for records Part 2: Conceptual and implementation issues Information et documentation Gestion

More information

ISO INTERNATIONAL STANDARD. Information and documentation Records management processes Metadata for records Part 1: Principles

ISO INTERNATIONAL STANDARD. Information and documentation Records management processes Metadata for records Part 1: Principles INTERNATIONAL STANDARD ISO 23081-1 First edition 2006-01-15 Information and documentation Records management processes Metadata for records Part 1: Principles Information et documentation Processus de

More information

ISO & ISO & ISO Cloud Documentation Toolkit

ISO & ISO & ISO Cloud Documentation Toolkit ISO & ISO 27017 & ISO 27018 Cloud ation Toolkit Note: The documentation should preferably be implemented order in which it is listed here. The order of implementation of documentation related to Annex

More information

SYSTEMKARAN ADVISER & INFORMATION CENTER. Information technology- security techniques information security management systems-requirement

SYSTEMKARAN ADVISER & INFORMATION CENTER. Information technology- security techniques information security management systems-requirement SYSTEM KARAN ADVISER & INFORMATION CENTER Information technology- security techniques information security management systems-requirement ISO/IEC27001:2013 WWW.SYSTEMKARAN.ORG 1 www.systemkaran.org Foreword...

More information

Advent IM Ltd ISO/IEC 27001:2013 vs

Advent IM Ltd ISO/IEC 27001:2013 vs Advent IM Ltd ISO/IEC 27001:2013 vs 2005 www.advent-im.co.uk 0121 559 6699 bestpractice@advent-im.co.uk Key Findings ISO/IEC 27001:2013 vs. 2005 Controls 1) PDCA as a main driver is now gone with greater

More information

EDRMS Document Migration Guideline

EDRMS Document Migration Guideline Title EDRMS Document Migration Guideline Creation Date 23 December 2016 Version 3.0 Last Revised 28 March 2018 Approved by Records Manager and IT&S Business Partner Approval date 28 March 2018 TABLE OF

More information

DIRECTIVE ON RECORDS AND INFORMATION MANAGEMENT (RIM) January 12, 2018

DIRECTIVE ON RECORDS AND INFORMATION MANAGEMENT (RIM) January 12, 2018 DIRECTIVE ON RECORDS AND INFORMATION MANAGEMENT (RIM) January 12, 2018 A. OVERRIDING OBJECTIVE 1.1 This Directive establishes the framework for information management of the Asian Infrastructure Investment

More information

Position Description IT Auditor

Position Description IT Auditor Position Title IT Auditor Position Number Portfolio Performance and IT Audit Location Victoria Supervisor s Title IT Audit Director Travel Required Yes FOR OAG HR USE ONLY: Approved Classification or Leadership

More information

SOUTH AFRICAN NATIONAL STANDARD

SOUTH AFRICAN NATIONAL STANDARD ISBN 978-0-626-32709-5 ISO/TR 15489-2:2001 SOUTH AFRICAN NATIONAL STANDARD Information and documentation Records management Part 2: Guidelines This national standard is the identical implementation of

More information

TARGET2-SECURITIES INFORMATION SECURITY REQUIREMENTS

TARGET2-SECURITIES INFORMATION SECURITY REQUIREMENTS Target2-Securities Project Team TARGET2-SECURITIES INFORMATION SECURITY REQUIREMENTS Reference: T2S-07-0270 Date: 09 October 2007 Version: 0.1 Status: Draft Target2-Securities - User s TABLE OF CONTENTS

More information

EU GDPR & ISO Integrated Documentation Toolkit https://advisera.com/eugdpracademy/eu-gdpr-iso integrated-documentation-toolkit

EU GDPR & ISO Integrated Documentation Toolkit https://advisera.com/eugdpracademy/eu-gdpr-iso integrated-documentation-toolkit EU GDPR & https://advisera.com/eugdpracademy/eu-gdpr-iso-27001-integrated-documentation-toolkit Note: The documentation should preferably be implemented in the order in which it is listed here. The order

More information

Records Management Standard for the New Zealand Public Sector: requirements mapping document

Records Management Standard for the New Zealand Public Sector: requirements mapping document Records Management Standard for the New Zealand Public Sector: requirements mapping document Introduction This document maps the requirements in the new Records Management Standard to the requirements

More information

ELECTRONIC RECORDS MANAGEMENT SYSTEMS - SYSTEM SPECIFICATIONS FOR PUBLIC OFFICES

ELECTRONIC RECORDS MANAGEMENT SYSTEMS - SYSTEM SPECIFICATIONS FOR PUBLIC OFFICES ELECTRONIC RECORDS MANAGEMENT SYSTEMS - SYSTEM SPECIFICATIONS FOR PUBLIC OFFICES VERSION 3 NATIONAL ARCHIVES OF MALAYSIA 2011 CONTENTS 1. INTRODUCTION 1.1 Background 1.2 Scope 1.3 Purpose 1.4 Audience

More information

This document is a preview generated by EVS

This document is a preview generated by EVS INTERNATIONAL STANDARD ISO/IEC/ IEEE 90003 First edition 2018-11 Software engineering Guidelines for the application of ISO 9001:2015 to computer software Ingénierie du logiciel Lignes directrices pour

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management

ISO/IEC INTERNATIONAL STANDARD. Information technology Security techniques Information security risk management INTERNATIONAL STANDARD ISO/IEC 27005 First edition 2008-06-15 Information technology Security techniques Information security risk management Technologies de l'information Techniques de sécurité Gestion

More information

Data Processing Clauses

Data Processing Clauses Data Processing Clauses The examples of processing clauses below are proposed pending the adoption of standard contractual clauses within the meaning of Article 28.8 of general data protection regulation.

More information

Approved 10/15/2015. IDEF Baseline Functional Requirements v1.0

Approved 10/15/2015. IDEF Baseline Functional Requirements v1.0 Approved 10/15/2015 IDEF Baseline Functional Requirements v1.0 IDESG.org IDENTITY ECOSYSTEM STEERING GROUP IDEF Baseline Functional Requirements v1.0 NOTES: (A) The Requirements language is presented in

More information

ISO COMPLIANCE GUIDE. How Rapid7 Can Help You Achieve Compliance with ISO 27002

ISO COMPLIANCE GUIDE. How Rapid7 Can Help You Achieve Compliance with ISO 27002 ISO 27002 COMPLIANCE GUIDE How Rapid7 Can Help You Achieve Compliance with ISO 27002 A CONTENTS Introduction 2 Detailed Controls Mapping 3 About Rapid7 8 rapid7.com ISO 27002 Compliance Guide 1 INTRODUCTION

More information

Management: A Guide For Harvard Administrators

Management: A Guide For Harvard Administrators E-mail Management: A Guide For Harvard Administrators E-mail is information transmitted or exchanged between a sender and a recipient by way of a system of connected computers. Although e-mail is considered

More information

Information and documentation Records management. Part 1: Concepts and principles AS ISO :2017 ISO :2016

Information and documentation Records management. Part 1: Concepts and principles AS ISO :2017 ISO :2016 ISO 15489-1:2016 AS ISO 15489.1:2017 Information and documentation Records management Part 1: Concepts and principles This Australian Standard was prepared by Committee IT-021, Records and Document Management

More information

Recordkeeping Standards Analysis of HealthConnect

Recordkeeping Standards Analysis of HealthConnect Recordkeeping Standards Analysis of HealthConnect Electronic Health Records: Achieving an Effective and Ethical Legal and Recordkeeping Framework Australian Research Council Discovery Grant, DP0208109

More information

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 ISO / IEC 27001:2005 A brief introduction Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 Information Information is an asset which, like other important business assets, has value

More information

Information technology Service management. Part 10: Concepts and vocabulary

Information technology Service management. Part 10: Concepts and vocabulary Provläsningsexemplar / Preview INTERNATIONAL STANDARD ISO/IEC 20000-10 First edition 2018-09 Information technology Service management Part 10: Concepts and vocabulary Technologies de l'information Gestion

More information

BCS Practitioner Certificate in Information Risk Management Syllabus

BCS Practitioner Certificate in Information Risk Management Syllabus BCS Practitioner Certificate in Information Risk Management Syllabus Version 6.5 April 2017 This qualification is not regulated by the following United Kingdom Regulators - Ofqual, Qualification in Wales,

More information

_isms_27001_fnd_en_sample_set01_v2, Group A

_isms_27001_fnd_en_sample_set01_v2, Group A 1) What is correct with respect to the PDCA cycle? a) PDCA describes the characteristics of information to be maintained in the context of information security. (0%) b) The structure of the ISO/IEC 27001

More information

ETSI TR V1.1.1 ( )

ETSI TR V1.1.1 ( ) TR 119 400 V1.1.1 (2016-03) TECHNICAL REPORT Electronic Signatures and Infrastructures (ESI); Guidance on the use of standards for trust service providers supporting digital signatures and related services

More information

Introduction to ISO/IEC 27001:2005

Introduction to ISO/IEC 27001:2005 Introduction to ISO/IEC 27001:2005 For ISACA Melbourne Chapter Technical Session 18 th of July 2006 AD Prepared by Endre P. Bihari JP of Performance Resources What is ISO/IEC 17799? 2/20 Aim: Creating

More information

Information Technology Branch Organization of Cyber Security Technical Standard

Information Technology Branch Organization of Cyber Security Technical Standard Information Technology Branch Organization of Cyber Security Technical Standard Information Management, Administrative Directive A1461 Cyber Security Technical Standard # 1 November 20, 2014 Approved:

More information

Software Requirements Specification (SRS) Software Requirements Specification for <Name of Project>

Software Requirements Specification (SRS) Software Requirements Specification for <Name of Project> Software Requirements Specification (SRS) Software Requirements Specification for Version Release Responsible Party Major Changes Date 0.1 Initial Document Release for

More information

Use of data processor (external business unit)

Use of data processor (external business unit) Published with the support of: Code of conduct for information security www.normen.no Use of data processor (external business unit) Supporting document Fact sheet no 10 Version: 4.0 Date: 12 Feb 2015

More information

LESSONS LEARNED FROM THE INDIANA UNIVERSITY ELECTRONIC RECORDS PROJECT. How to Implement an Electronic Records Strategy

LESSONS LEARNED FROM THE INDIANA UNIVERSITY ELECTRONIC RECORDS PROJECT. How to Implement an Electronic Records Strategy LESSONS LEARNED FROM THE INDIANA UNIVERSITY ELECTRONIC RECORDS PROJECT Philip Bantin Indiana University Archivist Director of the IU Project bantin@indiana.edu How to Implement an Electronic Records Strategy

More information

SPECIFIC PROVISIONS FOR THE ACCREDITATION OF CERTIFICATION BODIES IN THE FIELD OF INFOR- MATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001)

SPECIFIC PROVISIONS FOR THE ACCREDITATION OF CERTIFICATION BODIES IN THE FIELD OF INFOR- MATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001) BELAC 2-405-ISMS R0 2017 SPECIFIC PROVISIONS FOR THE ACCREDITATION OF CERTIFICATION BODIES IN THE FIELD OF INFOR- MATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001) The only valid versions of the documents

More information

"Charting the Course... Certified Information Systems Auditor (CISA) Course Summary

Charting the Course... Certified Information Systems Auditor (CISA) Course Summary Course Summary Description In this course, you will perform evaluations of organizational policies, procedures, and processes to ensure that an organization's information systems align with overall business

More information

Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED.

Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED. Assistant Deputy Minister (Review Services) Reviewed by in accordance with the Access to Information Act. Information UNCLASSIFIED. Security Audits: Management Action Plan Follow-up December 2015 1850-3-003

More information

Agenda. Bibliography

Agenda. Bibliography Humor 2 1 Agenda 3 Trusted Digital Repositories (TDR) definition Open Archival Information System (OAIS) its relevance to TDRs Requirements for a TDR Trustworthy Repositories Audit & Certification: Criteria

More information

Southington Public Schools

Southington Public Schools 3543 POLICY REGARDING RETENTION OF ELECTRONIC RECORDS AND INFORMATION I.POLICY The Board of Education (the Board ) complies with all state and federal regulations regarding the retention, storage and destruction

More information

Records Management and Retention

Records Management and Retention Records Management and Retention Category: Governance Number: Audience: University employees and Board members Last Revised: January 29, 2017 Owner: Secretary to the Board Approved by: Board of Governors

More information

BCS EXIN ITAMOrg Software Asset Management Specialist Syllabus Version 1.1 December 2016

BCS EXIN ITAMOrg Software Asset Management Specialist Syllabus Version 1.1 December 2016 BCS EXIN ITAMOrg Software Asset Management Specialist Syllabus Version 1.1 December 2016 This professional certification is not regulated by the following United Kingdom Regulators - Ofqual, Qualification

More information

Metadata Framework for Resource Discovery

Metadata Framework for Resource Discovery Submitted by: Metadata Strategy Catalytic Initiative 2006-05-01 Page 1 Section 1 Metadata Framework for Resource Discovery Overview We must find new ways to organize and describe our extraordinary information

More information

PART 5: INFORMATION TECHNOLOGY RECORDS

PART 5: INFORMATION TECHNOLOGY RECORDS PART 5: INFORMATION TECHNOLOGY RECORDS SECTION 5 1: RECORDS OF AUTOMATED APPLICATIONS GR5800 01 AUDIT TRAIL RECORDS Files needed for electronic data audits such as files or reports showing transactions

More information

Electronic Records Management the role of TNA. Richard Blake Head of the Records Management Advisory Service

Electronic Records Management the role of TNA. Richard Blake Head of the Records Management Advisory Service Electronic Records Management the role of TNA Richard Blake Head of the Records Management Advisory Service What records management has to address Accountability & records as evidence Standards & controls

More information

Standard CIP 007 4a Cyber Security Systems Security Management

Standard CIP 007 4a Cyber Security Systems Security Management A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-4a 3. Purpose: Standard CIP-007-4 requires Responsible Entities to define methods, processes, and procedures for

More information

When Recognition Matters WHITEPAPER ISO SUPPLY CHAIN SECURITY MANAGEMENT SYSTEMS.

When Recognition Matters WHITEPAPER ISO SUPPLY CHAIN SECURITY MANAGEMENT SYSTEMS. When Recognition Matters WHITEPAPER ISO 28000 SUPPLY CHAIN SECURITY MANAGEMENT SYSTEMS www.pecb.com CONTENT 3 4 4 4 4 5 6 6 7 7 7 8 9 10 11 12 Introduction An overview of ISO 28000:2007 Key clauses of

More information

Sparta Systems Stratas Solution

Sparta Systems Stratas Solution Systems Solution 21 CFR Part 11 and Annex 11 Assessment October 2017 Systems Solution Introduction The purpose of this document is to outline the roles and responsibilities for compliance with the FDA

More information

ISO 22301: An Overview of BCM Implementation Process. Presenter: Dejan Kosutic

ISO 22301: An Overview of BCM Implementation Process. Presenter: Dejan Kosutic ISO 22301: An Overview of BCM Implementation Process Presenter: Dejan Kosutic GoToWebinar Control Panel Open and close your Panel View, Select, and Test your audio Submit text questions they will be addressed

More information

New York Cybersecurity. New York Cybersecurity. Requirements for Financial Services Companies (23NYCRR 500) Solution Brief

New York Cybersecurity. New York Cybersecurity. Requirements for Financial Services Companies (23NYCRR 500) Solution Brief Publication Date: March 10, 2017 Requirements for Financial Services Companies (23NYCRR 500) Solution Brief EventTracker 8815 Centre Park Drive, Columbia MD 21045 About EventTracker EventTracker s advanced

More information

MALAYSIAN STANDARD INFORMATION AND DOCUMENTATION - RECORDS MANAGEMENT - PART 1: GENERAL (ISO :2001, IDT)

MALAYSIAN STANDARD INFORMATION AND DOCUMENTATION - RECORDS MANAGEMENT - PART 1: GENERAL (ISO :2001, IDT) MALAYSIAN STANDARD MS 2223-1:2009 INFORMATION AND DOCUMENTATION - RECORDS MANAGEMENT - PART 1: GENERAL (ISO 15489-1:2001, IDT) ICS: 01.140.20 Descriptors: information, documentation, record management,

More information

Version 1/2018. GDPR Processor Security Controls

Version 1/2018. GDPR Processor Security Controls Version 1/2018 GDPR Processor Security Controls Guidance Purpose of this document This document describes the information security controls that are in place by an organisation acting as a processor in

More information

Key definitions. May Part of the Department of Internal Affairs

Key definitions. May Part of the Department of Internal Affairs Key definitions May 2018 Part of the Department of Internal Affairs Document details Document Identifier: 16/F17 Version Date Description Revision due 0.1 Mar 2016 Development Draft 1.0 Jul 2016 Publication

More information

Summary of Changes in ISO 9001:2008

Summary of Changes in ISO 9001:2008 s in ISO 9001:2008 Clause 0.1 Introduction General Added the phrase its organizational environment, changes in that environment, or risks associated with that environment, to the first paragraph Created

More information

ISO RM standards. Hans Hofman DLM Forum Budapest, 6 October 2005

ISO RM standards. Hans Hofman DLM Forum Budapest, 6 October 2005 ISO RM standards Hans Hofman DLM Forum Budapest, 6 October 2005 Overview ISO context: TC46/SC11 ISO 23081 metadata standard Other related work on metadata Revision ISO 15489 records management ISO context

More information

Report. Conceptual Framework for the DIAMONDS Project. SINTEF ICT Networked Systems and Services SINTEF A Unrestricted

Report. Conceptual Framework for the DIAMONDS Project. SINTEF ICT Networked Systems and Services SINTEF A Unrestricted SINTEF A22798- Unrestricted Report Conceptual Framework for the DIAMONDS Project Author(s) Gencer Erdogan, Yan Li, Ragnhild Kobro Runde, Fredrik Seehusen, Ketil Stølen SINTEF ICT Networked Systems and

More information

Common approaches to management. Presented at the annual conference of the Archives Association of British Columbia, Victoria, B.C.

Common approaches to  management. Presented at the annual conference of the Archives Association of British Columbia, Victoria, B.C. Common approaches to email management Presented at the annual conference of the Archives Association of British Columbia, Victoria, B.C. Agenda 1 2 Introduction and Objectives Terms and Definitions 3 Typical

More information

Standard CIP 007 3a Cyber Security Systems Security Management

Standard CIP 007 3a Cyber Security Systems Security Management A. Introduction 1. Title: Cyber Security Systems Security Management 2. Number: CIP-007-3a 3. Purpose: Standard CIP-007-3 requires Responsible Entities to define methods, processes, and procedures for

More information

ISO/IEC Information technology Security techniques Code of practice for information security controls

ISO/IEC Information technology Security techniques Code of practice for information security controls INTERNATIONAL STANDARD ISO/IEC 27002 Second edition 2013-10-01 Information technology Security techniques Code of practice for information security controls Technologies de l information Techniques de

More information

Sparta Systems TrackWise Digital Solution

Sparta Systems TrackWise Digital Solution Systems TrackWise Digital Solution 21 CFR Part 11 and Annex 11 Assessment February 2018 Systems TrackWise Digital Solution Introduction The purpose of this document is to outline the roles and responsibilities

More information

IT MANAGEMENT AND THE GDPR: THE VMWARE PERSPECTIVE

IT MANAGEMENT AND THE GDPR: THE VMWARE PERSPECTIVE TRANSFORM SECURITY DATA PROTECTION SOLUTION OVERVIEW IT MANAGEMENT AND THE GDPR: THE VMWARE PERSPECTIVE Introduction This Solution Overview is intended for IT personnel interested in the VMware perspective

More information

Managing Official Electronic Records Guidelines

Managing Official Electronic Records Guidelines Application and Scope of Guidelines Managing Official Electronic Records Guidelines These guidelines are meant to assist Government Institutions in understanding responsibilities and concerns that must

More information

Conformity assessment Requirements for bodies providing audit and certification of management systems. Part 6:

Conformity assessment Requirements for bodies providing audit and certification of management systems. Part 6: TECHNICAL SPECIFICATION ISO/IEC TS 17021-6 First edition 2014-12-01 Conformity assessment Requirements for bodies providing audit and certification of management systems Part 6: Competence requirements

More information

Predstavenie štandardu ISO/IEC 27005

Predstavenie štandardu ISO/IEC 27005 PERFORMANCE & TECHNOLOGY - IT ADVISORY Predstavenie štandardu ISO/IEC 27005 ISMS Risk Management 16.02.2011 ADVISORY KPMG details KPMG is a global network of professional services firms providing audit,

More information

Security and Architecture SUZANNE GRAHAM

Security and Architecture SUZANNE GRAHAM Security and Architecture SUZANNE GRAHAM Why What How When Why Information Security Information Assurance has been more involved with assessing the overall risk of an organisation's technology and working

More information

Survey of Research Data Management Practices at the University of Pretoria

Survey of Research Data Management Practices at the University of Pretoria Survey of Research Data Management Practices at the University of Pretoria Undertaken by the Department of Library Services in order to improve research practices at the University Unisa Library Open Access

More information

Standard Development Timeline

Standard Development Timeline Standard Development Timeline This section is maintained by the drafting team during the development of the standard and will be removed when the standard is adopted by the NERC Board of Trustees (Board).

More information

RI AND RF CRITERIA AND FORMATS

RI AND RF CRITERIA AND FORMATS RI-42 RI AND RF CRITERIA AND FORMATS PURPOSE This procedure establishes design criteria and standard formats for detailed procedures and records required for effective operations, communications and management

More information

UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY October 25, 2017

UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY October 25, 2017 UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY October 25, 2017 I. Introduction Institutional information, research data, and information technology (IT) resources are critical assets

More information

,!1.,,,. Uni^rig. Document Migration Guideline. ECM Document Migration Guideline 23 December 2016 I.O. Approved by Approval date.

,!1.,,,. Uni^rig. Document Migration Guideline. ECM Document Migration Guideline 23 December 2016 I.O. Approved by Approval date. ,!1.,,,. Uni^rig ^. in Australia, Syiiod of NSW & ACT EC Document Migration Guideline Title Creation Date Version Last Revised Approved by Approval date ECM Document Migration Guideline 2 December 2016

More information

Description Cross-domain Task Force Research Design Statement

Description Cross-domain Task Force Research Design Statement Description Cross-domain Task Force Research Design Statement Revised 8 November 2004 This document outlines the research design to be followed by the Description Cross-domain Task Force (DTF) of InterPARES

More information

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 1: Processes and tiered assessment of conformance

ISO/IEC INTERNATIONAL STANDARD. Information technology Software asset management Part 1: Processes and tiered assessment of conformance INTERNATIONAL STANDARD This is a preview - click here to buy the full publication ISO/IEC 19770-1 Second edition 2012-06-15 Information technology Software asset management Part 1: Processes and tiered

More information

An Overview of ISO/IEC family of Information Security Management System Standards

An Overview of ISO/IEC family of Information Security Management System Standards What is ISO/IEC 27001? The ISO/IEC 27001 standard, published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), is known as Information

More information

Category: Data/Information Keywords: Records Management, Digitization, Imaging, Image capture, Scanning, Process

Category: Data/Information Keywords: Records Management, Digitization, Imaging, Image capture, Scanning, Process IMT Standards IMT Standards Oversight Committee Government of Alberta Effective Date: 2013-03-01 Scheduled Review: 2016-05-19 Last Reviewed: 2016-05-19 Type: Process Standard number A000015 Digitization

More information

IAF Mandatory Document KNOWLEDGE REQUIREMENTS FOR ACCREDITATION BODY PERSONNEL FOR INFORMATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001)

IAF Mandatory Document KNOWLEDGE REQUIREMENTS FOR ACCREDITATION BODY PERSONNEL FOR INFORMATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001) IAF Mandatory Document KNOWLEDGE REQUIREMENTS FOR ACCREDITATION BODY PERSONNEL FOR INFORMATION SECURITY MANAGEMENT SYSTEMS (ISO/IEC 27001) (IAF MD 13:2015) Issue 1 IAF MD - Knowledge Requirements for Accreditation

More information

General Framework for Secure IoT Systems

General Framework for Secure IoT Systems General Framework for Secure IoT Systems National center of Incident readiness and Strategy for Cybersecurity (NISC) Government of Japan August 26, 2016 1. General Framework Objective Internet of Things

More information

Google Cloud & the General Data Protection Regulation (GDPR)

Google Cloud & the General Data Protection Regulation (GDPR) Google Cloud & the General Data Protection Regulation (GDPR) INTRODUCTION General Data Protection Regulation (GDPR) On 25 May 2018, the most significant piece of European data protection legislation to

More information

Information Security Policy

Information Security Policy April 2016 Table of Contents PURPOSE AND SCOPE 5 I. CONFIDENTIAL INFORMATION 5 II. SCOPE 6 ORGANIZATION OF INFORMATION SECURITY 6 I. RESPONSIBILITY FOR INFORMATION SECURITY 6 II. COMMUNICATIONS REGARDING

More information

ISO/IEC TR TECHNICAL REPORT

ISO/IEC TR TECHNICAL REPORT TECHNICAL REPORT ISO/IEC TR 27019 First edition 2013-07-15 Information technology Security techniques Information security management guidelines based on ISO/IEC 27002 for process control systems specific

More information

Section Qualifications of Audit teams Qualifications of Auditors Maintenance and Improvement of Competence...

Section Qualifications of Audit teams Qualifications of Auditors Maintenance and Improvement of Competence... Section 9. SFI 2010-2014 Audit Procedures and Auditor Qualifications and Accreditation Updated January 2011 Section 9 Introduction... 3 1. Scope... 3 2. Normative Reference... 3 3. Terms and Definitions...

More information

4.2 Electronic Mail Policy

4.2 Electronic Mail Policy Policy Statement E-mail is an accepted, efficient communications tool for supporting departmental business. As provided in the Government Records Act, e-mail messages are included in the definition of

More information

Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC :2011

Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC :2011 TECHNICAL REPORT ISO/IEC TR 90006 First edition 2013-11-01 Information technology Guidelines for the application of ISO 9001:2008 to IT service management and its integration with ISO/IEC 20000-1:2011

More information

Swedish National Data Service, SND Checklist Data Management Plan Checklist for Data Management Plan

Swedish National Data Service, SND Checklist Data Management Plan Checklist for Data Management Plan Swedish National Data Service, SND Checklist Data Management Plan 2017-10-16 Checklist for Data Management Plan Content Checklist for Data Management Plan... 1 Introduction to SND:s Checklist for Data

More information

Executive Order 13556

Executive Order 13556 Briefing Outline Executive Order 13556 CUI Registry 32 CFR, Part 2002 Understanding the CUI Program Phased Implementation Approach to Contractor Environment 2 Executive Order 13556 Established CUI Program

More information

EMC Centera CentraStar/SDK Compatibility with Centera ISV Applications

EMC Centera CentraStar/SDK Compatibility with Centera ISV Applications EMC Centera CentraStar/SDK Compatibility with Centera ISV Applications A Detailed Review Abstract This white paper provides an overview on the compatibility between EMC Centera CentraStar and SDK releases,

More information

FRAMEWORK MAPPING HITRUST CSF V9 TO ISO 27001/27002:2013. Visit us online at Flank.org to learn more.

FRAMEWORK MAPPING HITRUST CSF V9 TO ISO 27001/27002:2013. Visit us online at Flank.org to learn more. FRAMEWORK MAPPING HITRUST CSF V9 TO ISO 27001/27002:2013 Visit us online at Flank.org to learn more. HITRUST CSF v9 Framework ISO 27001/27002:2013 Framework FLANK ISO 27001/27002:2013 Documentation from

More information

Checklist: Credit Union Information Security and Privacy Policies

Checklist: Credit Union Information Security and Privacy Policies Checklist: Credit Union Information Security and Privacy Policies Acceptable Use Access Control and Password Management Background Check Backup and Recovery Bank Secrecy Act/Anti-Money Laundering/OFAC

More information

Framework for building information modelling (BIM) guidance

Framework for building information modelling (BIM) guidance TECHNICAL SPECIFICATION ISO/TS 12911 First edition 2012-09-01 Framework for building information modelling (BIM) guidance Cadre pour les directives de modélisation des données du bâtiment Reference number

More information

Higher National Unit specification: general information. Graded Unit 2

Higher National Unit specification: general information. Graded Unit 2 Higher National Unit specification: general information This Graded Unit has been validated as part of the HND Computing: Software Development. Centres are required to develop the assessment instrument

More information

Understanding my data and getting value from it

Understanding my data and getting value from it Understanding my data and getting value from it Creating Value With GDPR: Practical Steps 20 th February 2017 Gregory Campbell Governance, Regulatory and Legal Consultant, IBM Analytics gcampbell@uk.ibm.com

More information

Higher National Unit specification: general information. Graded Unit title: Computer Science: Graded Unit 2

Higher National Unit specification: general information. Graded Unit title: Computer Science: Graded Unit 2 Higher National Unit specification: general information This Graded Unit has been validated as part of the HND Computer Science. Centres are required to develop the assessment instrument in accordance

More information

EDPB Certification Guidelines

EDPB Certification Guidelines EDPB Certification Guidelines Public Consultation: Comments submitted by SCOPE Europe bvba/sprl Published and Submitted: 10. July 2018 1 About SCOPE Europe sprl SCOPE Europe is a subsidiary of Selbstregulierung

More information