Requirements and acquisition
Goal: Ensure requirements include explicit privacy and security criteria.
- Define functional, privacy and security requirements. Include purpose limitation and data minimization requirements.
- Conduct Privacy Impact Assessment (PIA) and update risk register.
- Translate risks into measurable security requirements like encryption, RBAC, logging and retention.
- For procurement: include security clauses, acceptance criteria and tender security evaluation.
- For third parties: require evidence of prior security audits and contractual data protection obligations.
No Comments