DU&T Consulting

Mastering the Implementation and Management of a Privacy Framework

Summary

This five-day intensive course enables participants to develop the necessary expertise to support an organization in implementing and managing a Privacy Framework based on ISO 29100, the Generally Accepted Privacy principles and guidance from international information commissioners. Participants will gain a thorough understanding of how to design, build and lead organizations privacy programs covering business processes, ICT systems and services, through the use of best practices. The training provides a privacy framework which specifies a common privacy terminology, defines the actors and their roles in processing personally identifiable information (PII), describes privacy safeguarding considerations and provides references to known privacy principles for information technology. Based on this knowledge delegates will have the skills to build privacy frameworks that allow their organisation to maintain compliance to the many privacy directives and laws worldwide.

Who should attend?

  • Project managers or consultants wanting to prepare and to support organizations on implementing and managing a Privacy
  • Framework
  • Security auditors who wish to fully understand the Privacy Framework implementation process
  • Experienced IT security management professionals
  • IT security professionals interested in earning Privacy Management Framework certification
  • Privacy Officers, Data Protection Officers, and Compliance professionals with an interest in privacy legislation and risk
  • Security professionals with front-line experience
  • Information security staff
  • Expert advisors in information technology
  • Persons and organizations involved in tasks where privacy controls are required for the processing of PII
  • Legal practitioners who wish to understand the practical aspects of privacy frameworks

Learning objectives

  • To understand the core competences on Privacy Framework
  • To gain a comprehensive understanding of the concepts, approaches, standards, methods and techniques required for the effective protection of personally identifiable information (PII)
  • To define privacy safeguarding requirements related to PII within an ICT environment
  • To understand the relationship between the components of Privacy Framework with existing security standards and various applicable laws
  • To acquire necessary expertise in privacy governance, specifically in personally identifiable information governance
  • To acquire Introduction to Privacy Framework concepts as recommended by ISO 29100
  • Privacy Framework based on ISO 29100 and regulatory framework
  • Fundamental Principles of Privacy
  • Privacy Legislation US & Europe including the existing and new EU directives
  • Writing a business case and a project plan for the implementation of a Privacy Framework
  • Initiating the Privacy Framework implementation
  • necessary expertise in privacy risk management compliance connected with personally identifiable information
  • To develop knowledge and skills required to advise for improve organizations’ privacy programs through the use of best practices
  • To improve the capacity for analysis of privacy incident management
  • To understand the relationship between the components of Privacy Framework with existing security standards and various applicable laws and directives

Course Agenda

Day 1: Introduction to Privacy Framework concepts as recommended by ISO 29100

Day 2: Planning the implementation of the Privacy Framework

  • Preliminary analysis of Existing Controls
  • Leadership and approval of the Privacy Framework project
  • Defining the scope of a Privacy Framework
  • Development of a Privacy policy
  • Selection of the approach and methodology for risk assessment
  • Control Statement and management decision to implement the Privacy Framework
  • Definition of the organizational structure of Privacy

Day 3: Implementing a Privacy Framework

  • Implementation of a document management framework
  • Design of controls and writing procedures and specific policies
  • Implementation of privacy controls
  • Development of a training and awareness program and communicating about the privacy to Development of a training and awareness program and communicating about privacy
  • Incident management
  • Operations Management

Day 4: Privacy Framework measurement and continuous improvement

  • Monitoring, Measurement, Analysis and Evaluation
  • Internal Audit
  • Management Review
  • Treatment of problems and points of concern
  • Continual improvement
  • Competence and evaluation of implementers

Day 5: Certification Exam

Prerequisites

Knowledge on the Privacy Framework in Information Security is preferred.

Educational approach

  • This training is based on both, theory and practice:
    • Sessions of lectures illustrated with examples based on real cases
    • Practical exercises
    • Review exercises to assist the exam preparation
    • Practice test similar to the certification exam
  • To benefit from the practical exercises, the number of training participants is limited
Duration:             23-27 September, 2015 (5 days) Lead  AuditorVenue: DU&T Hall, Ikeja, Lagos.
Fee: N200,000; registration on/after  September 9 – N220,000 (cover Training, Material, Lunch and ISO Certificate). Discount of 10% for 4-9 participants, 15% for 10 and above.

Registration Details: DU&T Consulting, 0016102526 GTBank Plc
Enquiry: 08033746074, 08182704246 or [email protected]

DU&T Consulting, 371 Agege Motor Road, Challenge Bus Stop, Lagos.  www.dutconsulting.com