4 hours 7 minutes
Welcome to Lesson 2.4 Identiod Data Processing Ecosystem Risk Management.
In this video we will cover the identify category number four. Data processing ecosystem risk management. We'll look at the five subcategories of data processing ecosystem risk management. And then we're also going to look at how data processing ecosystem risk management differs from the risk assessment in the previous uh lesson.
So here we are in data processing ecosystem risk management, I D D E. P.
The organization's priorities, constraints, risk tolerance and assumptions are established and used to support risk decisions associated with managing privacy risk and third parties within the data processing ecosystem.
So as you can see here, we have five subcategories and this is really focusing on third party risk management when it comes to privacy risk. So this is where you want to ensure that you have policies, processes and procedures in place that help you manage this third party risk
as well as identifying and prioritizing uh the other parties in your data processing ecosystem
um Using a privacy risk assessment process. So these can include service providers, customers, partners, manufacturers, developers, um and those are just to name a few.
But then when we move into P3, this is also when you want to look at contracts that you may have in place with your third parties that deal with data processing to make sure measures that are mentioned in those contracts are actually being implemented and followed
um as well as in uh before you want to look at the interoperability of frameworks or similar multiparty approaches that are used to manage data processing ecosystem privacy risks. Sometimes some security frameworks do have privacy sections within those frameworks.
And so you want to look at how those may work um in correlation to whatever in this uh whether you adopt in this privacy framework or some other framework, but you want to be mindful of those as well. And then finally in P5, this is focusing on making sure that with those third parties, your routinely doing audits or looking at test results or using other forms of evaluation
to confirm that your third parties are really meeting those contractual or interoperability frameworks or other obligations that may be in place for you.
So really what I wanted to make sure in the previous lesson, we went through the identified function of risk assessment and this one work. It seems like we're also looking at risk assessment but I really want to focus on that. I. D. R. A. Was focused on looking at the risk to the individual as well as the impact of the organization.
Should there be a problematic data action that occurs whereas in this particular
category, under the identified function, what we're focused on is really looking at managing the privacy risks with the other third parties um in your data processing ecosystem. So really keeping those separate as two separate types of risk assessments that need to happen.
Um It doesn't mean you wouldn't necessarily keep them on the same risk register. You very well could but you want to make sure that you're looking at risks from these two different standpoints. Um Looking at the risk to the individual
should something happen to the personal data and how that will impact your organization? And then, like Ceta also doing a risk assessment of your partners that are within that data processing ecosystem to make sure that they're following the contractual obligations that maybe maybe in place
as well as framework interoperability or even other obligations
um that they may have to adhere to, which could be G. D. P. R. Or C. C. P. A. Since their processing data on your behalf they would have to adhere to those regulations. So just want to make sure that we're understanding the difference of these two categories within the identify function.
So pop quiz time,
data processing ecosystem risk management is focused on risk assessing the following one risk to individuals,
Two risks to the enterprise or three managing privacy risks than 3rd parties.
So the answer here is number three managing privacy risks and third parties. Because remember we went through this when I was discussing that I. D. R. A. Dash P which is the identify function risk assessment category is really focusing on the privacy risk
to the individual and how that impacts the organization
and that data processing ecosystem risk management is really focused on managing the privacy risks and third parties.
So in this video we covered the components of the data processing ecosystem risk managements of categories. And then we also looked at the risk assessment focus difference between i. D. R. A, which is the risk assessment category under identify and the data processing ecosystem risk management category under the identify function.
So I hope you'll join me as we move into Module three.
NIST 800-53: Introduction to Security and Privacy Controls
This course will provide Executives, Assessors, Analysts, System Administrators and students with the foundational knowledge ...
2 CEU/CPE Hours Available
Certificate of Completion Offered
CIS Top 20 Critical Security Controls
CIS Controls are a prioritized set of actions that protect your organization and data from ...
4 CEU/CPE Hours Available
Certificate of Completion Offered