Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

Privacy/Data Protection

Welcome to the Privacy/Data Protection topic!

Collaborate, contribute, consume and create knowledge around topics such as privacy frameworks and governance (OECD), protection of data, data leaks and data communicated across borders

ISACA members can participate by clicking on the “Join this Community” button. You must be signed into the site. Set your alerts to be notified of new discussion activity within this community. Not an ISACA member? Join now!

This Topic Has:
922 Members
1 Online
9740 Visits

 Recent Discussions

The Challenges of Applying HIPAA to the Cloud. Posted by yves_le_roux.
Where are we with Regulatory Enforcement in US... Posted by yves_le_roux.
May we have an effective Data protection legislation?. Posted by yves_le_roux.

Community Leader

Marc Vael

Marc Vael

Badge: Influential


NEW! Activity Badges

Badges help others understand your level of community activity and your reputation as a contributor within the Knowledge Center. Learn More.

Discussions: 63 total

Must be a Topic member to contribute
View All »
In 2013, HHS clarified that an entity that maintains electronic protected health information (ePHI) on behalf of a covered entity is a business associate. The HIPAA rules, however, were not designed with cloud computing in mind. A multitude of questions r...
yves_le_roux | 10/27/2014 5:25:42 AM | COMMENTS(0)
At the CSA Congress last September, the authors presented the latest regulatory enforcement trends on privacy and data security in the U.S., Canada and EU. You will find that presentation at
yves_le_roux | 10/27/2014 5:20:56 AM | COMMENTS(0)
In his paper , Professor Bert-Jaap Koops finds that the new EU data protection Regulation is based upon three fallacies: The first fallacy is the delusion that data protection law can give individuals control over their data, which it cannot. The second ...
yves_le_roux | 10/24/2014 2:28:27 PM | COMMENTS(1)
Does anyone have any ideas as to when the new EU data protection law will come into effect ? My personal view is 2016, but if anyone has a better insight please share. Secondly what do you think will be the key features of the new law and how to meet the ...
JayMIET927 | 10/22/2014 9:33:41 AM | COMMENTS(7)
Dear colleagues, According to The Guardian [1] "The White House has ordered that US data privacy protections will soon be extended to non-Americans [...] Officials will seek to make sure US government departments and companies treat data on foreigners wi...
Fidel Santiago | 10/6/2014 9:41:29 AM | COMMENTS(3)
Hi,I'm very new to Cobit, and I'd like to know if any of you  could share with me ideas about defining a data anonymization program or initiative using the Cobit 5 framework ? 
mb | 10/3/2014 12:58:23 PM | COMMENTS(3)

Documents & Publications: 54 total

Must be a Topic member to contribute
View All »
Information Systems Assurance and Control Guideline for Verifing Compliance with Personal Data Protection Act [POLAND]
Posted by JoannaK 273 days ago
Posted by ISACA 2 days ago
In Google Spain v AEPD and Mario Costeja Gonzalez (C-131/12), the Court of Justice for the European Union (CJEU) ruled that Google must delete "inadequate, irrelevant or no longer relevant" data from its results when an individual requests it. This has generated a lot of discussion as the "right to be forgotte"n is a new right that is introduced in the Draft Proposal for a General Data Protection Regulation of 2012,
Posted by yves_le_roux 9 days ago
In this publication the four European data protection authorities from Poland, the Czech Republic, Croatia and Bulgaria tried to compare the different practices implemented in their countries and find the general rules which might be common for all or most of the EU countries in the field of data protection from the point of view of a natural person searching for a job or being employed in one of the EU countries.
Posted by yves_le_roux 9 days ago
The Nymity Privacy Management Accountability Framework (“Framework”) is a comprehensive listing of over 150 privacy management activities identified through Nymity’s global data privacy accountability research. The privacy management activities are structured in 13 privacy management processes, and are jurisdiction and industry neutral.
Posted by yves_le_roux 9 days ago

Events & Online Learning: 8 total

19 Aug 2013
ISACA International Event
San Francisco, CA, USA
6 Nov 2013
ISACA International Event
Las Vegas, NV, USA
North America ISRM features relevant security and risk management topics presented by leading industry experts and practitioners.
29 Sep 2014
ISACA International Event
Barcelona, Spain
Stay on top of the trends and opportunities of the dynamic technology industry at EuroCACS/ISRM 2014—the leading European conference for IT audit, assurance, security and risk professionals.

Journal Articles: 113 total

Volume 6, 2014
by Ulf T. Mattsson
Data analysts require access to the data to efficiently perform meaningful analysis and gain a return on investment (ROI), and traditional data security has served to limit that access.
Volume 6, 2014
by Muhammad Mushfiqur Rahman, CISA, CCNA, CEH, ITIL V3, MCITP, MCP, MCSE, MCTS, OCP, SCSA
Database auditing is the activity of monitoring and recording configured database actions from database users and nondatabase users, to ensure the security of the databases.
Volume 6, 2014
by Ed Gelbstein, Ph.D., and Viktor Polic, CISA, CRISC, CISSP
Understanding who owns data is not as simple as it appears at first. It is easy to say that all data belong to the organization.
Volume 5, 2014
by Ashwin Chaudhary, CISA, CISM, CGEIT, CRISC, CISSP, CPA, PMP
Mobile computing and the bring your own device (BYOD) trend are revolutionizing end-user computing in many organizations.
Volume 3, 2014
Over the past few years, there has been a shift in the business world pertaining to assets that need to be protected.
Volume 3, 2014
by William Emmanuel Yu, Ph.D., CISM, CRISC, CISSP, CSSLP
With the advent of cost-effective technologies and solutions for longer-term storage of vast amounts of transaction data, more and more companies are investing in keeping more and more data for longer and longer periods.

Wikis: 2 total

Blog Posts: 19 total

27 Oct 2014
Now a days, you don’t need to be a IT guru or best software programmer to access /control other personal/organization data. If you follow below techniques, you can easily get confidential information. 1. Masquerading 2. Tailgeting (Piggy back) 3. Dum...
Posted By : Shaklain | 1 comments
23 Oct 2014
Posted By : masarker | 4 comments
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : Umesh391 | 2 comments
26 Jun 2013
Aspectos de seguridad de informacion en BIG DATA
Posted By : Roque | 0 comments
During an audit you may find that shell scripts are used to connect to your Oracle database (these are often scheduled jobs).  In many instances this represents a security risk as the Oracle database password is hardcoded into the script.  This means th...
Posted By : Ian Cooke | 0 comments
As with configurations the company you are auditing should have a policy on password controls.  We have previously discussed that SQL Server allows two methods of authenticating to the database – Mixed Mode and Windows Authentication (see http://www.isa...
Posted By : Ian Cooke | 0 comments