Security Vision has launched its Security Vision Personal Data Management product, which maintains a registry of information systems that process personal data, calculates security levels, models threats, and generates a comprehensive set of documents.
Security Vision Personal Data Management ensures compliance with three key regulatory and legal acts:
- Federal Law of July 27, 2006 No. 152-FZ "On Personal Data"
- Decree of the Government of the Russian Federation of November 1, 2012 No. 1119 "On approval of requirements for the protection of personal data when processing them in personal data information systems"
- Order of the Federal Service for Technical and Export Control of Russia dated February 18, 2013, No. 21 "On approval of the composition and content of organizational and technical measures to ensure the security of personal data when processing them in personal data information systems"
Personal Data Management meets the needs of all personal data operators — from small companies to large organizations with branch networks and subsidiaries — and can be integrated with various local systems without loss of functionality.
The product includes the following features:
- Formation of processes related to the processing of personal data (PD)
- Formation of personal data information systems (PDIS)
- Determining the level of security of personal data processed in the information system of personal data
- Accounting and monitoring of requests from personal data subjects
- Monitoring consents and revocations of consents of personal data subjects
- Accounting and control of machine-readable media with personal data
- Accounting for personal data protection measures
- Accounting and control of computer incidents related to personal data
- Modeling threats to personal data security
- Formation of basic measures for the protection of personal data with the possibility of adaptation, clarification and supplementation
- Conducting an assessment of compliance with personal data security (protection) requirements
- Planning measures to protect personal data
- Formation of a documentation package based on the requirements of regulatory legal acts
Process accounting and ISPDN
Lists of processes and information systems that process personal data are formed on the basis of questionnaires sent to responsible persons in the organization, or by entering existing data into the system.
When creating an ISPD, a full range of information on the processing and protection of personal data is entered, including:
- Purposes of processing
- Legal basis
- Categories, categories of subjects, list of personal data and actions on them
Data is collected and accumulated from all available information systems for personal data, with the ability to generate the necessary notifications to Roskomnadzor.
Determining the level of security and developing protective measures
The level of security for personal data processed in the personal data information system (ISPD) , which is necessary for building further protection, is automatically calculated for each ISPD. Based on the determined security level, a basic set of personal data protection measures is also automatically generated, with the ability to adapt, refine, and supplement them for a specific ISPD.
Threat modeling and compliance assessment
Modeling of threats to the security of personal data can be carried out in accordance with the methodological document of the Federal Service for Technical and Export Control of Russia “Methodology for Assessing Information Security Threats”.
Two modeling approaches have been implemented:
- a new section on threats, including threat groups, threats within groups, and the corresponding methods for implementing these threats
- a general list of threats, methods of their implementation and scenarios, based on the sequence of tactics and corresponding techniques, to determine the current methods of implementing information security threats
Compliance with personal data security requirements is assessed in accordance with the regulatory legal acts specified above. The assessment is conducted by completing information on the current status of personal data protection in the Personal Data Information System (PDIS), with the option to delegate (in whole or in part) the questionnaires to the appropriate specialists.
Based on the results of the compliance assessment, a list of unimplemented requirements is compiled, followed by the creation of an action plan and necessary tasks.
Monitoring consents, responses, and requests from personal data subjects
We've implemented the ability to store consents from personal data subjects for personal data processing and monitor their revocation after a request. All requests from personal data subjects are recorded in a log of requests and inquiries, with a record of the request completion deadline and the assignment of tasks to performers based on the specific request type. We also monitor the established deadlines for completing requests.
Documentation
Following the completion of the product's core processes, a complete documentation package is generated based on regulatory legal requirements and developed templates. If necessary, the documentation can be adapted to the organization's local requirements.
Key metrics and the current state of processes in the organization are monitored at any given time using a set of dashboards.