▲ Back to Top
Compliance Management
This management process makes it possible to identify and manage the legal risks that the organization may face regarding incidents occurring on its information assets, which can arise across various components such as e-commerce, data protection, habeas data, computer incidents and their implications in terms of criminal and civil liability, IT and telematics contracting, employment contracting, and contracting with third parties.
STAGES
1. PLAN
2. DO
3. VERIFY
4. ACT
-
- Study the applicable legal areas that could generate risks for the organization and determine how their identification, assessment, and treatment would be approached.
-
- Identify and evaluate compliance risks and define their treatment. Implement the legal controls indicated in the treatment.
-
- Review the established legal controls to determine if they remain sufficient in light of changes that may arise in the business or the national and international legal environment.
-
- Perform the actions for change or improvement of the established legal controls.
Documents
ESG-SSI-PL01 - PLAN INSTITUCIONAL DE SENSIBILIZACIÓN Y ENTRENAMIENTO EN SEGURIDAD Y PRIVACIDAD DE LA INFORMACIÓN
ESG-SSI-PG01 - PROGRAMA INTEGRAL DE GESTIÓN DE DATOS PERSONALES - PIGDP
ESG-SSI-P03 - RECOLECCIÓN Y ALMACENAMIEO DE DATOS PERSONALES
ESG-SSI-P05 - USO Y CIRCULACIÓN DE DATOS PERSONALES
ESG-SSI-P06 - SUPRESIÓN DE DATOS PERSONALES
ESG-SSI-P07 - TRANSFERENCIA INTERNACIONAL DE DATOS PERSONALES
ESG-SSI-P13 - REGISTRO NACIONAL DE BASE DE DATOS
There are no documents for this filter.
OTRAS ETAPAS DEL MODELO
SGSI
SGSI
SGSI
SGSI
