TASK 2.2.3: AUDITING AND CERTIFICATION PROCESS OF ISO27001 ................................................ 14
Create A Project Plan .................................................................................................................... 14
Define The Scope f your ISMS ....................................................................................................... 14
Perform a Risk Assessment and Gap Analysis ............................................................................... 14
Design and Implement Policies And Controls ............................................................................... 14
Employee Education and Training ................................................................................................ 15
Document Presentation ................................................................................................................ 15
External Certification Audit ........................................................................................................... 15
TASK 3: DATA DISCOVERY, CLASSIFICATION, PROCESSING, LOSS PREVENTION AND PRIVACY
ENHANCEMENT ..................................................................................................................................... 16
3.1: Data Protection by Design and Default...................................................................................... 16
3.2: MECHANISM TO IMPLEMENT DATA PROTECTION BY DESIGN AND DEFAULT .......................... 16
DATA DISCOVERY .............................................................................................................................. 16
Data classification ............................................................................................................................. 17
Data Processing Impact Assessment (DPIA): .................................................................................... 17
Data Loss Prevention (DLP): .............................................................................................................. 17
Mechanism and privacy-enhancing technology (PET): ..................................................................... 18
REFERENCES .......................................................................................................................................... 18
INTRODUCTION
Data and information security are the very foundation of a nation, organisation, or company. The
effects of data and information breaches to an organisation could be enormous; it can lean lead to
huge monetary losses, reputational and brand damage, complete bankruptcy and many more. For an
individual, a data breach can cause fraud, identity theft, and financial losses, among others. The
European Union (2016) defines a data breach as a compromise of information leading to access to
protected data, loss of sensitive data, alteration, unauthorised disclosure of information.
There are many causes of data and information loss; they include cyber-attacks, stolen credentials,
application vulnerabilities, social engineering, and employee negligence. Cybercriminals continue to
expand their methods and operations, using different variety of tactics. These include social
engineering, malware, and ransom ware.
It is my duty as a cyber-security consultant to identify and mitigate against possible threats,
vulnerabilities, and attacks on the data and information systems of a firm, organisation, or nation.
AIMS AND OBJECTIVES
The aim of this paper is to do a critical review of cyber-attacks and information security for business.