Information Security
Risk Assessment & Evaluation
The business continuity of companies in the creative industry increasingly depends on the reliable functioning of the ICT infrastructure and the security of its data. Customers of these companies therefore increasingly demand - and because they too must comply with legislation - that their data be handled with care. Particularly when it concerns sensitive information or digital material to which copyrights apply, or which has to do with the financial markets (e.g. annual reports of listed companies).
With this Information Security RI&E program you will identify step-by-step where the risks lie and how you can adequately cover them.
Our approach
We will start by taking stock of the current status of information security; ensuring that you are compliant with privacy laws such as the General Data Protection Regulation (the AVG); we will evaluate risks in a practical way and provide solutions to security risks such as on and off duty procedures, methods of backup, physical access security and determining who can see what information.
Basics
- The management of security risks concerning the data of the organization and its customers.
- The continuous improvement of awareness and prevention of data breaches and malware.
- Providing maximum assurance of safety and continuity to all involved.
Custom
From our broad experience in implementing Information Security, we have compiled the above method. The in-house consultants of the Dienstencentrum will assist you in this process on a customized basis using the concept we developed:
Enter
Your consultant will guide you through your information security journey. We start with the AVG Scan. We prepare a self-declaration and a legally required register of data processing activities. You will receive a brief report outlining the risks, their importance to your business and solution options.
Maintain
After setting up the information security system, it is important to keep your system continuously updated. Your in-house consultant will help you implement the technical and organizational measures and record them within the Data Security RI&E.
Conducting audit
Periodically performing internal controls (internal audits) is an essential part of an information security system. This way, the functioning of your system is kept up to date and you get a reliable picture of the situation regarding your information security
Certify
You can certify your Data Security RI&E in two ways: with the so-called SCCI self-declaration in which you account for how the Data Security RI&E was applied or by certification of the Data Security RI&E by the SCCI. Having an officially tested Datasecurity Risk Inventory and Evaluation helps you stand out as a company.