Art.32 Security of processing
Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and pur
5
artefacts
0
held by a system
2
at each review
hard
to go live
Policy repository / GRC workspace
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
none for this control
periodic reviewEvidence produced at each review
- The security risk assessment per processing activity, expressed as risk to the rights and freedoms of individuals rather than only as risk to the organisation · Policy repository / GRC workspace
- The regular testing programme Article 32(1)(d) requires: penetration tests, vulnerability scanning and control effectiveness reviews, with findings closed out · Vulnerability scanner / patch tooling
governing documentDocuments that govern the control
- Encryption and pseudonymisation coverage at rest, in transit and in backup, with the decision recorded where either was judged not appropriate · Policy repository / GRC workspace
- Restoration testing results showing personal data was actually recovered inside the intended timeframe, with the date and outcome · Policy repository / GRC workspace
- Evidence the measures were reassessed after material change in processing, technology or threat · Document repository
First move
This control is evidenced by people and documents, not systems. Put the document under version control with an owner and review date, and log each review as a record with reviewer and date. Do not try to automate it.
Common gaps auditors find
- Risk assessed as impact to the business, so processing that is low risk to the organisation and high risk to individuals attracts weak measures
- Backups taken and never restore tested, so the ability to restore in a timely manner is assumed rather than demonstrated
- Article 32(1)(d) treated as satisfied by an annual perimeter penetration test, with the organisational measures never evaluated at all
- Encryption stated as in place while key management, backup copies and third party copies sit outside its scope
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetArt.31 Cooperation with the supervisory authority · Art.33 Notification of a personal data breach to the supervisory authority