IS/DPP for staff #1 - intro

31
- Internal - IS/DPP Baseline Training E-learning - Intro

Transcript of IS/DPP for staff #1 - intro

Page 1: IS/DPP for staff #1 - intro

- Internal -

IS/DPP Baseline Training

E-learning - Intro

Page 2: IS/DPP for staff #1 - intro

2- Internal - Page

IS/DPP

INFORMATION SECURITY

DATA PROTECTION

PRIVACY

Page 3: IS/DPP for staff #1 - intro

3- Internal - Page

IS/DPP

INFORMATION SECURITY

DATA PROTECTION

PRIVACY

Page 4: IS/DPP for staff #1 - intro

4- Internal - Page

IS/DPP

INFORMATION SECURITY

DATA PROTECTION

PRIVACY

Page 5: IS/DPP for staff #1 - intro

5- Internal - Page

Why Do We Need Training?

Page 6: IS/DPP for staff #1 - intro

6- Internal - Page

Training Objectives

Create awareness about IS/DPP

Page 7: IS/DPP for staff #1 - intro

7- Internal - Page

Training Objectives

Create awareness about IS/DPP

Give a high-level overview of the ACG policy framework on IS/DPP Refresh the basics and principles on IS/DPP

Page 8: IS/DPP for staff #1 - intro

8- Internal - Page

Training Objectives

Create awareness about IS/DPP

Give a high-level overview of the ACG policy framework on IS/DPP Refresh the basics and principles on IS/DPP

Answer the question: “What is my role, as a staff member, in IS/DPP?” Give some guidance on good and bad practice.

Page 9: IS/DPP for staff #1 - intro

9- Internal - Page

Training Objectives

Create awareness about IS/DPP

Give a high-level overview of the ACG policy framework on IS/DPP Refresh the basics and principles on IS/DPP

Answer the question: “What is my role, as a staff member, in IS/DPP?” Give some guidance on good and bad practice.

Provide signposting to where you can find more information and guidance

Page 10: IS/DPP for staff #1 - intro

11- Internal - Page

What will You Learn?

What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?

Page 11: IS/DPP for staff #1 - intro

12- Internal - Page

What will You Learn?

What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?

What are the general principles of IS/DPP?

Page 12: IS/DPP for staff #1 - intro

13- Internal - Page

What will You Learn?

What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?

What are the general principles of IS/DPP?

What are “layers of defense”?

Page 13: IS/DPP for staff #1 - intro

14- Internal - Page

What will You Learn?

What is information classification? Why is it needed? What are the different classification levels of data handled at ABC?

What are the general principles of IS/DPP?

What are “layers of defense”? How do I, as a staff member, contribute to those layers of defense?

Page 14: IS/DPP for staff #1 - intro

16- Internal - Page

For ACG

Page 15: IS/DPP for staff #1 - intro

17- Internal - Page

Centrally

Page 16: IS/DPP for staff #1 - intro

18- Internal - Page

You

Page 17: IS/DPP for staff #1 - intro

19- Internal - Page

For You

As a part of ACG handling ACG data

Page 18: IS/DPP for staff #1 - intro

20- Internal - Page

For You

As a data subject:

staff member, cardholder,…

As a part of ACG handling ACG data

Page 19: IS/DPP for staff #1 - intro

21- Internal - Page

IS/DPP is not… (just) hacking

Page 20: IS/DPP for staff #1 - intro

22- Internal - Page

IS/DPP is also… social engineering.

Page 21: IS/DPP for staff #1 - intro

23- Internal - Page

IS/DPP is also… incidents.

Page 22: IS/DPP for staff #1 - intro

24- Internal - Page

IS/DPP is also… thinking like an attacker

Page 23: IS/DPP for staff #1 - intro

25- Internal - Page

IS/DPP is not… new

Code of Conduct:

I. I act fairly, honestly and transparentlyII. I respect othersIII. I comply with the law and professional standardsIV. I comply with instructionsV. I manage conflicts of interestVI. I comply with data protection and information securityVII. I work in the customer’s best interestVIII. I protect ABC’s interestsIX. I act professionallyX. I report any irregularity observed

Insert ABC’s code of conduct principles, e.g.

Page 24: IS/DPP for staff #1 - intro

26- Internal - Page

ABC IS/DPP Policy Framework

Page 25: IS/DPP for staff #1 - intro

27- Internal - Page

ABC IS/DPP Policy FrameworkAbout continuously

Changes• In the regulatory environment• In processes• In people (JLT)• In technology

Page 26: IS/DPP for staff #1 - intro

28- Internal - Page

ABC IS/DPP Policy FrameworkAbout continuously

Environment

Physical

HumanDevice

Application

Repository

Carrier

Changes• In the regulatory environment• In processes• In people (JLT)• In technology

Net

wor

k

Data

3rd Parties

Page 27: IS/DPP for staff #1 - intro

29- Internal - Page

Blocks in the Course

Environment

Physical

HumanDevice

Application

Repository

Carrier

Changes• In the regulatory environment• In processes• In people (JLT)• In technology

Net

wor

k

Data

3rd Parties

1. Introduction

2. Why?

3. Data (Classification)

4. Layers

5. Access

6. Acceptable Use

7. Incidents

8. Monitoring

Page 28: IS/DPP for staff #1 - intro

30- Internal - Page

More Information on IS/DPP at ABC

Intranet: (insert hyperlink)

Page 29: IS/DPP for staff #1 - intro

31- Internal - Page

Relevant Points of Contact

IT Helpdesk Incidents

Information Security OfficerISO

Support relating to information security (= overall + more technical side)

Data Protection OfficerDPO

Support relating to personal data protection

Information Asset OwnerIAO

Centralization of information / documentation on an Information Asset

Human ResourcesHR

Support on Join, Leave, Transfer

Procurement Unit Support on Relationships with Third Parties

Legal Unit Support on agreements

Marketing Unit Support on use of (personal) data for marketing

Who is Who in IS/DPP?

Page 30: IS/DPP for staff #1 - intro

32- Internal - Page

What do we Expect of You?

General Mandatory “Please” “Pretty Please”Baseline Test X

Baseline Videos X

Higher Belt Test X

Extra Videos X

Policies X

Guidelines X

Monitoring X

Useful links X

Target Group Mandatory “Please” “Pretty Please”Classroom Training X

Test X

Page 31: IS/DPP for staff #1 - intro

33- Internal - Page

Be a Hero. Help us Protect.But Most of All…

IS/DPP