Course Outline
Module Information – 1
- Recognize the key operational requirements of ISO/IEC 27701:2025 and how to go about assessing them
- Identify what and who should be audited and why
- Recall where to look for evidence when conducting audits
- Determine how to take a pragmatic business-focused approach to auditing your organization against requirements which can be open to interpretation.
Module Information – 2
- Develop internal auditing skills and boost information security/ privacy management knowledge
- Perform a gap assessment of the existing ISMS to the requirements of ISO/IEC 27701 and produce an action plan on how to address those gaps.
- Conduct a data mapping of the PII collected by the organization to understand the scope of PII collected and how it is used and shared with processors.
Module Information – 3
- Determine the organization’s role as a controller and/or processor based on internal or external factors that are relevant to its context, such as applicable privacy legislation, regulations, judicial decisions, or contractual requirements (among others).
- Review and update privacy policies to ensure they contain the required information.
- Develop policies and procedures applicable to the organization’s role.
- Begin the planning and implementation of the privacy by design and default principles.
