Victorian Protective Data Security Framework
Victorian Information Security Network – PARTNERS Forum December 2016
Victorian Protective Data Security Framework Victorian Information - - PowerPoint PPT Presentation
Victorian Protective Data Security Framework Victorian Information Security Network PARTNERS Forum December 2016 C ommissioner for P rivacy and D ata P rotection Introductions Pr Presenter esenter Commissioner Privacy and Data Protection
Victorian Information Security Network – PARTNERS Forum December 2016
Commissioner for Privacy and Data Protection
2
Pr Presenter esenter
Commissioner Privacy and Data Protection David Watts
Data Pr Data Protect
ion Branch
Assistant Commissioner, Data Protection Anthony Corso Senior Data Protection Advisor Laurencia Dimelow Senior Data Protection Officer Anna Harris GRC Security Manager Karl Will Specialist Data Protection Advisor Martin Harris
Contact details Email: Email: security@cpdp.vic.gov.au Ph.
VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
3 VISN – What the VPDSF means for you…
David W David Watts atts
Anthony Anthony Corso Corso & the & the Data Pr Data Protection Branch (DPB)
Commissioner for Privacy and Data Protection
4 VISN – What the VPDSF means for you…
During the event we will be using an online tool (Sli.do) offering you an opportunity to interact with
questions. For those using the tool you will have the option of posting anonymously and can also download the presentation and a summary infographic onto your local device. The team will moderate the tool and will post any relevant comments or material to the audience…
Commissioner for Privacy and Data Protection
5 VISN – What the VPDSF means for you…
PAR ARTNERSVISN TNERSVISN
Commissioner for Privacy and Data Protection
6 VISN – What the VPDSF means for you…
Funded Agencies Research Bodies / Educational institutions External Third Party Organisations Private Industry
Commissioner for Privacy and Data Protection
7 VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
8
Awareness video of the Victorian Protective Data Security Framework
VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
9 VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
10
The Victorian Protective Data Security Standards (VPDSS) were formally issued on 28th of July, 2016.
VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
11 VISN – What the VPDSF means for you…
Any information obtained, received or held by an agency or body to which Part 4 of the Privacy and Data Protection Act (2014) applies. This includes both hard and soft copy information, regardless of media or format!
Commissioner for Privacy and Data Protection
12
VISN – What the VPDSF means for you…
CPDP - CPDP -
Office of the Commissioner for Privacy and Data Protection
Indir Indirect obligations - ect obligations -
Organisations with access to Victorian public sector data, have indirect protective data security obligations Public sector body Head
Dir Directly in scope - ectly in scope -
Applicable agencies or bodies set out under Part 4 of Privacy and Data Protection Act (PDPA) 2014
Commissioner for Privacy and Data Protection
IPP 4 13
Information Sharing Arrangements Other legal & regulatory
Contractual
Health Privacy Principles (HPP4) Information Privacy Principles (IPP4)
VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
14 VISN – What the VPDSF means for you…
Enable VPS organisations achieve their business
Have confidence in the information you are using Support secure information sharing practices (within and beyond government) Ensure the right people have access to the right information at the right time… Offer a level of assurance around your security practices
Commissioner for Privacy and Data Protection
15 VISN – What the VPDSF means for you…
Ident Identify ify
your information assets Determine the 'value
value'
information Identify any
risks risks to this
information
Apply Apply
security measures to protect the information
Manage Manage
risks across the information lifecycle
Commissioner for Privacy and Data Protection
16
Applicable VPS organisations must ensure that any contractual arrangements or information sharing agreements (including Memorandum of Understandings) have the relevant protective data security requirements embedded into the terms or conditions of the agreement.
VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
What does this mean for partner organisations?
IPP 4 17 VISN – What the VPDSF means for you…
to provide CPDP a -
partner organisations Instead, VPS agencies who are in scope for the VPDSF will require partner
Responses from partner organisations will inform the SRPA and PDSP of the VPS agency. How VPS agencies will seek this assurance form their partners will differ, depending
Commissioner for Privacy and Data Protection
18 VISN – What the VPDSF means for you…
Protective Data Security Plan (PDSP) Security Risk Profile Assessment (SRPA)
By July 2018
each applicable organisation must provide CPDP a copy of their:
assessment
Compliance self-assessment
(including an attestation by your Public sector body Head of current implemented security controls)
Commissioner for Privacy and Data Protection
19 VISN – What the VPDSF means for you…
‘BIL ‘BIL’ Mobile App ’ Mobile App
Currently available for download on table devices (iPad and Android) Simply search for ‘CPDP CPDP’ in the app store to download your own copy
CPDP Mobile App CPDP Mobile App
Commissioner for Privacy and Data Protection
20
VISN – What the VPDSF means for you…
Commissioner for Privacy and Data Protection
21
For any other feedback or enquiries please direct your comments to the the security@cpdp.vic.gov.au mailbox
VISN – What the VPDSF means for you…
Opportunity for you to ask questions through Sli.do Sli.do or to take questions from the floor…
Commissioner for Privacy and Data Protection
22
VISN – What the VPDSF means for you…
Help us:
and in the future
Reference (TOR)
collaboration across your business ,between partner groups and with the VPS. This includes those who haven’t traditionally been engaged in protective data security activities and programs
Commissioner for Privacy and Data Protection
23
VISN – What the VPDSF means for you…