Governance Policies, Processes & Procedures

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
or

Already have an account? Sign In »

Time
4 hours 7 minutes
Difficulty
Intermediate
CEU/CPE
4
Video Transcription
00:00
Welcome to module three of 10 missed privacy framework core govern.
00:06
So looking at the course outline, we've now gone through the introduction, we've completed module one, which is an overview of this privacy framework and we've gone through module to which was in this private privacy framework core, identify. And we now move into module three where we're going through this privacy framework core govern.
00:26
So welcome to less than 3.1. Govern governance policies, processes and procedures.
00:34
So the learning objectives for this video are to look at the government function description, go through the government function, category number one governance policies, procedures and processes and then to look at the resources.
00:49
So in the new function that we're looking at now, which is the second function under uh this privacy framework, um The government function is focused on looking at the development and implementation of the organizational governance structure to enable an ongoing understanding of the organizations
01:07
risk management, priorities that are informed by privacy risk.
01:11
So really what this is focusing on is ensuring that you have proper documentation in place from policies, processes and procedures. They're gonna govern um your privacy risk management framework um as well as looking at roles and responsibilities that
01:26
um will be managing your privacy risk management framework.
01:32
So in looking at the sub categories P one through P six, that's really what this is focused on, is making sure that you have policies, processes and procedures to manage and monitor the organizations, regulatory, legal risk, environmental and operational requirements and knowing that they're understood
01:51
and informing the management of privacy risk.
01:53
So you're gonna want to make sure that you have policies on data processing um uh that include things as such as like data uses and retention periods, um as well as ensuring that processes are in place to instill organizational privacy values within your systems, products, services,
02:13
um development and operations
02:15
and then ensuring that roles and responsibilities for the workforce are established with respect to privacy
02:22
and that privacy roles and responsibilities are coordinated in line with third party stakeholders such as service providers, customers and partners, as well as looking at your legal, regulatory, regulatory and contractual requirements regarding privacy and making sure that those are understood and managed and having a governance structure in place
02:40
um for your risk management, policies, processes, procedures to address privacy risk.
02:46
So when doing all this, it's really building your privacy framework structure. That's going to manage this privacy program as well as the privacy risks. So whether you choose um having a D. P. O. Within your organization or this is going to be managed by a committee with a different personnel from various business functions.
03:07
It's up to you how you choose that governance structure, um that's going to manage your privacy risk management program as well as making sure that you have the requisite policies, processes and procedures in place um on how to manage your privacy risk, who is conducting the risk assessments and having a process or procedure in place for that. Um And possibly even having dedicated privacy personnel,
03:30
you may or may not have the resources for that or it may be that you have people that serve a dual purpose that are doing
03:38
that have other roles and responsibilities, but also have a privacy role.
03:42
So you're really gonna want to look at the bandwidth and the resources within your organization to help determine the structure and create your policies, processes and procedures.
03:53
Um and the whole point of building really this governance structure is for accountability. You want to make sure everyone uh from individuals at the senior executive level, all the way down to those that may have an implementation or operations role,
04:08
um understand what their role is within the privacy risk management framework,
04:13
um and how they're going to work together. Um Having that governance structure allows there to be collaboration amongst different levels of people within your organization and make sure that everyone is accountable um for what their role is and being able to communicate what their role is or what the organization stands on privacy risk management is.
04:33
So as you can see here from the chart, we show that, you know, the senior executive level, um it's really their responsibility to express the mission um showing what the risk tolerances are, the privacy values, communicating the budget to other functions for what
04:48
um their budget is for creating privacy risk management programs as well as accepting or declining those risk decisions um at the business process or manager level, they may have the responsibility for developing the profiles that we mentioned before, both current and target, which we will get into in a later module. Um They would also be responsible for allocating the budget that the senior executive level creates
05:15
and informing others um sort of of what the policies, processes and procedures are. And then finally at that implementation or operations level, they'd be responsible for implementing the profiles that are developed by the business process and manager uh managers
05:32
as well as monitoring progress and they would actually be the ones conducting the privacy risk assessments.
05:39
Um So breaking it down in this context allows you to be able to see at each level of the organization, how each level um is accountable to the other as well as what part they play in the privacy risk management program.
05:58
So there is a resource um you did use this in the identify function. Business environment category, but it can also be utilized for the govern um govern policies, processes and procedures category here to help you determine
06:15
um really what policies are processes or procedures you need to create as well as what governance structure that you're looking for to sort of govern your program. So the same worksheet can be used for that. It's something you may even want to do in conjunction together. Um Typically when people are building out their current profile,
06:34
typically the identify and govern function or two of the areas they're going to focus on
06:40
because you're trying to see what components you may already have in place and how possibly you want uh to build out your program. So this worksheet is really valuable in helping you determine that.
06:54
So in this video we review the subcategories of the governance policies, processes and procedures category. We discussed how accountability is a key privacy principle, and then we discussed in this prime worksheet number one and how it's a valuable resource. So I hope you'll join me as we move into the next video.
Up Next