RESOURCE ARTICLE

Bridging ISO 27001 to GDPR

This white paper analyzes the IAPP and OneTrust's mapping of the ISO’s 27001 to the GDPR.


Published: 24 March 2018

View PDF

The IAPP and OneTrust have undertaken the task of mapping the most common security operations standard, ISO’s 27001, to the world’s most influential piece of privacy legislation, the GDPR, so as to create a framework for understanding just how closely they align and how much of the work toward GDPR compliance that security has likely already done.

With this research project, we have identified six main areas of common ground that should help every organization align their security and privacy operations in a way that will create efficiencies and, hopefully, reduce the risk of a damaging incident while increasing productivity and customer trust.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Contributors:

J. Trevor Hughes

President and CEO, IAPP

CIPP


Tags:

Program managementU.S. federal regulationGDPRCybersecurity lawPrivacy
RESOURCE ARTICLE

Bridging ISO 27001 to GDPR

This white paper analyzes the IAPP and OneTrust's mapping of the ISO’s 27001 to the GDPR.

Published: 24 March 2018

View PDF

Contributors:

J. Trevor Hughes

President and CEO, IAPP

CIPP


The IAPP and OneTrust have undertaken the task of mapping the most common security operations standard, ISO’s 27001, to the world’s most influential piece of privacy legislation, the GDPR, so as to create a framework for understanding just how closely they align and how much of the work toward GDPR compliance that security has likely already done.

With this research project, we have identified six main areas of common ground that should help every organization align their security and privacy operations in a way that will create efficiencies and, hopefully, reduce the risk of a damaging incident while increasing productivity and customer trust.

CPE credit badge

This content is eligible for Continuing Professional Education credits. Please self-submit according to CPE policy guidelines.

Submit for CPEs

Tags:

Program managementU.S. federal regulationGDPRCybersecurity lawPrivacy

Related resources