Privacy Gap Assessment - Pre Audit
Essentials
Evolving US Federal law provides protections to consumer information,
such as HIPAA, Gramm-Leach-Bliley Act (GLBA), and Fair and Accurate
Credit Transactions Act (FACTA, including Red Flags). States have
enacted their own laws providing additional protection, for example 48
state breach laws, Massachusetts’ 201 CMR 17. Similarly, numerous
international laws have been adopted, such as: European Directive,
Personal Information Protection and Electronic Documents Act (PIPEDA),
and the more than 50 countries that have enacted omnibus data privacy
laws covering the private sector (e.g., Mexico’s Federal Law on the
Protection of Personal Data Held by Private Parties). The SecureState
Privacy Gap Assessment compares your privacy program against applicable
law and industry best practices.
Privacy Principles
- Management
- Notice
- Choice and consent
- Collection
- Use, retention, and disposal
- Access
- Disclosure to third parties
- Security for privacy
- Quality
- Monitoring and enforcement
Benefits
- Identification and compliance with applicable privacy law and
regulatory guidance
- Proper 3rd party objective demonstration of compliance
- Avoidance of fines and regulatory action
- Client-centric program for safeguarding personally identifiable
information
- Reduction of the cost, confusion, and complexity of compliance
Expertise
SecureState’s Audit & Compliance consultants are experts in
understanding both the technical aspects as well as the business aspects
of your organization. Our experience and knowledge, developed while
working with some of the top Fortune 500 financial institutions in the
country and a governing body, provides your organization with a true
picture of your compliance with GLBA.
Did You Know?
- The Privacy Maturity Model was coauthored by International Privacy
Task Force sponsored by the American Institute of Certified Public
Accountants (AICPA) and the Canadian Institute of Chartered Accountants
(CICA)
- The Privacy Task Force was instrumental in the development of
Generally Accepted Privacy Principles (GAPP)
- The Privacy Maturity Model (PMM) is based on the requirements in
Generally Accepted Privacy Principles (GAPP)
- The Capability Maturity Model (CMM) – created and service marked by
Carnegie Mellon University – is a 1988 methodology leveraging data
collected by US Department of Defense contracted organizations
- The Privacy Maturity Model (PMM) is based on assessment levels of
the recognized Capability Maturity Model (CMM)
- A Privacy Gap Assessment – Pre-Audit should be performed annually.