August 24, 2018
August 24, 2018
Contributor: Laurence Goasduff
The new EU regulation is a wake-up call to draft new data security strategies.
The European Union’s General Data Protection Regulation (GDPR), which comes with potentially high fines for noncompliance, is forcing chief information security officers (CISOs) at organizations of all sizes to rethink how they manage data privacy. Yet many still don’t have a data security governance strategy.
“Although GDPR guidelines have been in effect since 25 May 2018, it’s clear that many organizations lack such a strategy or the tools needed to effectively protect sensitive data and maintain privacy and protection,” says Deborah Kish, principal research analyst at Gartner.
Their delay in formulating a strategy is due to a myriad challenges. These include compliance mandates such as the NIST Cybersecurity Framework in the U.S., Australia's new breach notification law, and Japan's Act on the Protection of Personal Information (APPI), national access laws and international staff access requirements. As a result, organizations are at different levels of GDPR compliance.
“None of them are completely GDPR ready,” explains Kish. She adds that “CISOs should remember that GDPR is not the ‘silver bullet’ that will resolve all their security governance issues. They need to evolve their organization’s guidelines to ensure data security governance.”
Before drafting a security strategy, CISOs need to consider several key questions, such as how to prioritize the subject’s rights. As these questions cannot be answered solely by the security team, CISOs need to collaborate with other data security governance stakeholders who, for example, have an understanding of the data stored or processed on the organization’s systems.
Kish recommends that CISOs take the following five steps to develop a data security governance strategy and make their organization GDPR-compliant.
“CISOs need to realize that GDPR can be the foundational privacy and data security standard, and can function as a standard approach to protect other datasets,” says Kish.
Join your peers for the unveiling of the latest insights at Gartner conferences.
Recommended resources for Gartner clients*:
Gartner clients can read more in “CISO Playbook: Adapting to the Changing Regulatory Environment.”
*Note that some documents may not be available to all Gartner clients.