The policy was changed in order to implement industry best practices in cybersecurity for the protection of personally identifiable information. These changes are compliant with ISO 27701 and help implement the requirements of tithe UNDP privacy policy for the protection of personal data.- The new version of the UNDP Information Security Policy takes into account the provisions of the new UNDP Data Protection and Privacy policy as well as the recommended industry best practices for managing personally identifiable information (PII) as defined in ISO 27701.- The new version designates the UNDP ...
The policy was changed in order to implement industry best practices in cybersecurity for the protection of personally identifiable information. These changes are compliant with ISO 27701 and help implement the requirements of tithe UNDP privacy policy for the protection of personal data.
- The new version of the UNDP Information Security Policy takes into account the provisions of the new UNDP Data Protection and Privacy policy as well as the recommended industry best practices for managing personally identifiable information (PII) as defined in ISO 27701.
- The new version designates the UNDP Chief Information Security Officer role as the party responsible for governance and monitoring of privacy safeguards within the BMS/ITM. It also explicitly designates BMS/ITM as a custodian (aka PII Processor) and not the owner of the PII data.
- The new policy section on PII also contains policy statements compliant with the ISO 27701 privacy standard for industry best practices.