MARC보기
LDR08525cmm u2200793Ii 4500
001000000316140
003OCoLC
00520230525175840
006m d
007cr cnu||||nuuu
008190110s2019 enk o 001 0 eng d
020 ▼a 9780429449970 ▼q (electronic bk.)
020 ▼a 0429449976 ▼q (electronic bk.)
020 ▼a 9780429832291
020 ▼a 042983229X
020 ▼a 9780429832277 ▼q (electronic bk. : Mobipocket)
020 ▼a 0429832273 ▼q (electronic bk. : Mobipocket)
020 ▼a 9780429832284 ▼q (electronic bk. : EPUB)
020 ▼a 0429832281 ▼q (electronic bk. : EPUB)
020 ▼z 9781138326170
035 ▼a 1996589 ▼b (N$T)
035 ▼a (OCoLC)1081315454
040 ▼a N$T ▼b eng ▼e rda ▼e pn ▼c N$T ▼d N$T ▼d EBLCP ▼d OCLCF ▼d CUS ▼d TYFRS ▼d 248032
049 ▼a MAIN
050 4 ▼a KJE6071.A432016
072 7 ▼a LAW ▼x 009000 ▼2 bisacsh
072 7 ▼a LAW ▼x 011600 ▼2 bisacsh
072 7 ▼a LAW ▼x 051000 ▼2 bisacsh
072 7 ▼a BUS ▼x 090010 ▼2 bisacsh
072 7 ▼a BUS ▼x 090030 ▼2 bisacsh
072 7 ▼a BUS ▼x 090000 ▼2 bisacsh
072 7 ▼a KJSA ▼2 bicssc
08204 ▼a 343.2409/99 ▼2 23
1001 ▼a Denley, Andrew, ▼e author.
24510 ▼a GDPR : ▼b how to achieve and maintain compliance / ▼c Andrew Denley, Mark Foulsham and Brian Hitchen.
260 ▼a Abingdon, Oxon ; ▼a New York, NY : ▼b Routledge, ▼c 2019.
300 ▼a 1 online resource.
336 ▼a text ▼b txt ▼2 rdacontent
337 ▼a computer ▼b c ▼2 rdamedia
338 ▼a online resource ▼b cr ▼2 rdacarrier
500 ▼a Includes index.
5050 ▼a Cover; Half Title; Title Page; Copyright Page; Table of Contents; The Authors; Acknowledgements; Introduction; Structure of this book; Italic text; The journey of GDPR to statute; Penalties; Practical application; GDPR history; Key roles defined; GDPR principles; Your GDPR project; Section 1: Does the GDPR apply to you?; What information is covered by the GDPR?; The GDPR is not just a European issue; Can you choose a Supervisory Authority (SA)?; Does the GDPR affect your whole organization?; Pan-national data; Section 2: GDPR principles; Consent; Section 3: Key roles
5058 ▼a Data Protection Officer (DPO)The role of the Data Protection Officer; Data controller; How to determine whether an organization is a data controller or a data processor; Data processor; Sub-processor; Section 4: Rights of the data subject; The right to be informed; Section 5: Your GDPR project; GDPR tools; GDPR: a breakdown; Create an action plan and from your project team(s); The role of IT; Review what data your suppliers hold; Audit your suppliers; Create a data privacy governance structure; Review your right to process; Check your incident response plan
5058 ▼a Disaster Recovery and Business Continuity PlanTransitioning to BAU; Change management; Controller obligations in BAU; Data subject rights in BAU; Risk management and information security in BAU; HR and communications in BAU; Section 6: Information security best practice; The need for a robust information security framework; ISO27001/2:2013; Implementing ISO27001; The ISO2700 series of standards; NIST security framework; Cyber essentials; Security testing; Vulnerability scanning; Penetration testing; Tiger Attack; Risk; Understanding risk; Assessing your suppliers for security
5058 ▼a Key areas of security you should considerSection 7: Awareness; Information security policy; Induction; Refresh and update; Awareness; Security testing; Incident response plan; Whistle-blowing policy/Hot-line; Section 8: Data handling and management; Data holdings and retention; Understand the value of your data; Data ownership; Data Protection Impact Assessment -- DPIA; Data protection by design and default; The data flows; Reflections; Data coming in; Data going out; Risk assessment; Risks to the individual; Anonymization and pseudonymization; Data retention; Binding corporate rules
5058 ▼a Lawful processingLawfulness of processing special categories of data; Consent; Transferring data outside of the EU; Defensive data; Data protection by design and default; Section 9: Data breaches; Penalties; Compensation; Breaches; Incident response plan; Who should be involved?; Victim or villain?; Monitoring; Perimeter; Security testing; Section 10: Your technology environment; Introduction; Website; Intranet; Extranet; Mobile apps; Social media; On-line file sharing; Bring your own device -- BYOD; Backend systems; Legacy systems; Where do you process your data?
520 ▼a Following the implementation of the new General Data Protect Regulation on 25 May 2018, organizations should now be fully compliant with their national interpretation of this far-reaching data protection standard. The reality is that most are not; whether through their inappropriate use of online cookies or ineffective physical data security, businesses continue to struggle with the increasing pressure from regulators to apply the Regulation. Non-compliance is widely due to misinterpretation, lack of real-world thinking, and challenges in balancing costs against business practicalities. This book provides insight into how to achieve effective compliance in a realistic, no-nonsense and efficient way. The authors have over 100 years' collective international experience in security, compliance and business disciplines and know what it takes to keep companies secure and in-line with regulators' demands. Whether your organization needs to swiftly adopt GDPR standards or apply them in "Business as Usual" this book provides a wide range of recommendations and explicit examples. With the likelihood of high-profile penalties causing major reputational damage, this book explains how to reduce risk, run a remedial project, and take immediate steps towards mitigating gaps. Written in plain English, it provides an invaluable international reference for effective GDPR adoption.
5450 ▼a Andrew Denley is a GDPR Compliance Consultant with 35 years' experience in the research, intelligence, government and commerce sectors in both technical and consultancy capacities. In recent years he has championed and implemented information security risk analysis and framework compliance for a number of commercial companies with considerable success. An ISO27001 Lead Auditor, he has been listed on the International Register for Certified Auditors. Mark Foulsham is Chief Digital Officer at Scope, CEO of Surrey Innovations, and Director of CIO Connect, UK. He has experience spanning over 30 years in leading both business and technology disciplines within organizations and has supported businesses from the Financial Services, wider commercial sector, universities and social enterprises in achieving their GDPR compliance programmes. Brian Hitchen is a GDPR Compliance Consultant and author with 30 years' experience working as an IT Security Manager for a number of financial services organizations. With an interest in cyber crime and the impact on small to medium businesses, Brian now writes to help companies better understand IT security, risks and issues, contingency planning and data analysis and plan what they need to do to counter the latest threats and deal with legislation.
5880 ▼a Online resource; title from PDF title page (EBSCO, viewed January 11, 2019).
590 ▼a Master record variable field(s) change: 072
61020 ▼a European Parliament. ▼t General Data Protection Regulation.
650 0 ▼a Data protection ▼x Law and legislation ▼z European Union countries.
650 0 ▼a Privacy, Right of ▼z European Union countries.
650 7 ▼a LAW / Business & Financial. ▼2 bisacsh
650 7 ▼a LAW / Privacy. ▼2 bisacsh
650 7 ▼a LAW / International. ▼2 bisacsh
650 7 ▼a Data protection ▼x Law and legislation. ▼2 fast ▼0 (OCoLC)fst00887963
650 7 ▼a Privacy, Right of. ▼2 fast ▼0 (OCoLC)fst01077444
650 7 ▼a BUSINESS & ECONOMICS / E-Commerce / Internet Marketing ▼2 bisacsh
650 7 ▼a BUSINESS & ECONOMICS / E-Commerce / Online Trading ▼2 bisacsh
650 7 ▼a BUSINESS & ECONOMICS / E-Commerce / General (see also COMPUTERS / Electronic Commerce) ▼2 bisacsh
651 7 ▼a Europe ▼z European Union countries. ▼2 fast ▼0 (OCoLC)fst01269470
655 4 ▼a Electronic books.
7001 ▼a Foulsham, Mark, ▼e author.
7001 ▼a Hitchen, Brian, ▼e author.
85640 ▼3 EBSCOhost ▼u http://search.ebscohost.com/login.aspx?direct=true&scope=site&db=nlebk&db=nlabk&AN=1996589
938 ▼a EBL - Ebook Library ▼b EBLB ▼n EBL5630606
938 ▼a EBSCOhost ▼b EBSC ▼n 1996589
990 ▼a 관리자
994 ▼a 92 ▼b N$T