Meeting minutes
ISO 27560
The standard has progressed to the next stage. We will take up its implementation as soon as a document is circulated by the national standards bodies.
Data Breach as an extension of Security Incident
harsh: https://
georg: In a Security notification you have to be able to say what kind of breach, technologies involved, and the supplier and users of technologies, and what kind of security the technology had. In NIS2, there is a requirement for a due diligence report on the supply chain for technologies, which must be maintained. This means information about technologies is front and centre.
paul: https://
harsh: In the context of DPV, this means we need to consider Technology as a central concept. Currently we have a focus on specifying TOMs as associated with processing.
harsh: Data Breach, Security Incident, Incident. And Communication separately that has metadata. And then when we communicate about data breach, it has the additional fields regarding personal data affected, scale of data subjects, etc.
paul: Is the term “Data Breach” only limited to personal data? - in our scope yes it is, though 'data' can be non-personal data too.
… We do agree (4 yes, 2 abstain) 1) Parent taxonomy for Data Breach as Security Incidents 2) In DPV-Tech, consider technology specific measures 3) In Data Breach, associate breaches with technologies as well as personal data processing
AOB
jan: Items added to agenda regarding requesting CEN to provide privacy guidelines for eIDAS