<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>privacy audit - Perlman Sandbox</title>
	<atom:link href="https://dev.staging-perlmanandperlman.com/tag/privacy-audit/feed/" rel="self" type="application/rss+xml" />
	<link>https://dev.staging-perlmanandperlman.com</link>
	<description>Perlman Sandbox</description>
	<lastBuildDate>Fri, 14 Dec 2018 20:31:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.2</generator>
	<item>
		<title>Privacy Audit – Make it Your Organization’s New Year’s Resolution!</title>
		<link>https://dev.staging-perlmanandperlman.com/privacy-audit-make-organizations-new-years-resolution/</link>
					<comments>https://dev.staging-perlmanandperlman.com/privacy-audit-make-organizations-new-years-resolution/#respond</comments>
		
		<dc:creator><![CDATA[Jon Dartley]]></dc:creator>
		<pubDate>Fri, 14 Dec 2018 20:31:59 +0000</pubDate>
				<category><![CDATA[Nonprofit]]></category>
		<category><![CDATA[Nonprofit & Tax Exempt Organizations]]></category>
		<category><![CDATA[Technology, Digital Privacy & Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[privacy audit]]></category>
		<guid isPermaLink="false">https://dev.staging-perlmanandperlman.com/privacy-audit-make-organizations-new-years-resolution/</guid>

					<description><![CDATA[<p>It&#8217;s the time of year when its typical to focus on self-betterment, so let’s not leave the organization you work for out. Nonprofit organizations hold a variety of personal information on behalf of their constituents and employees. Unfortunately, most organizations could be doing more to protect this information. The fact is that with each passing [&#8230;]</p>
<p>The post <a href="https://dev.staging-perlmanandperlman.com/privacy-audit-make-organizations-new-years-resolution/">Privacy Audit – Make it Your Organization’s New Year’s Resolution!</a> first appeared on <a href="https://dev.staging-perlmanandperlman.com">Perlman Sandbox</a>.</p>]]></description>
										<content:encoded><![CDATA[<p>It&#8217;s the time of year when its typical to focus on self-betterment, so let’s not leave the organization you work for out.  Nonprofit organizations hold a variety of personal information on behalf of their constituents and employees.  Unfortunately, most organizations could be doing more to protect this information.  The fact is that with each passing year, the number of data breaches grows, and the financial cost and reputational harm along with it.  Additionally, the regulatory landscape is becoming more complex, requiring organizations to comply with an increasing number of requirements or face penalties.  The good news &#8211; a significant portion of data breaches and related risks can be avoided or minimized with a bit of due care. As such, it has never been more critical to have a more practical understanding of the types of personal information collected, stored and shared by your organization.  A first step for any organization wishing to better understand (and minimize) their privacy risk is to conduct a privacy audit. </p>
<p>A privacy audit is essentially a process to identify, across the organization (and chapters), the types of personal information collected, the ways in which it is protected, and with whom such information is shared.   The following risk assessment methodology is a good place to start.<br />
•<strong>Inventory</strong>    Locate the places in the organization (and vendors operating on its behalf) that house/store Personally Identifying Information (“PII”), identifying both electronic files/databases and physical files.<br />
•<strong>Safeguards</strong>    Assess the safeguards in place – including the physical, administrative and technical controls – and whether they are adequate and reasonable considering the type of PII being stored (SSN vs. email address for example might have different levels of protection).<br />
•<strong>Gaps</strong>  Determine the compliance gap – essentially the difference between that what it should be doing, and the organizations actual practices.<br />
•<strong>Risk Assessment</strong>    For most organizations there will be a number of gaps.  As a first step, for the PII held in various locations and with various vendors, assess the risk of non-compliance, determine the impact of non-compliance and likelihood of risk occurrence, and use this to help prioritize compliance efforts.<br />
•<strong>Remediation</strong>   Depending upon the finding/conclusions in the previous steps, remediation should be a joint effort among various members of the organization to address and remedy any identified shortfalls/gaps.</p>
<p>The above are general guidelines. As a first step, I typically provide clients with a customized, detailed checklist that is an essential tool for our audit.  Not surprisingly, most of these audits reveal a variety of gaps and poor practices, which once addressed and remedied, reduces the likelihood of a breach, and leaves the organization better prepared should one occur.</p><p>The post <a href="https://dev.staging-perlmanandperlman.com/privacy-audit-make-organizations-new-years-resolution/">Privacy Audit – Make it Your Organization’s New Year’s Resolution!</a> first appeared on <a href="https://dev.staging-perlmanandperlman.com">Perlman Sandbox</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://dev.staging-perlmanandperlman.com/privacy-audit-make-organizations-new-years-resolution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
