1 / 7100%
Running Head: ISE 690 aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa
aa aa aa a aa aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa 1
Milestone 2A: Revised privacy Statement
ISE 690 Cyber Security Capstone
ISE 690 aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa 2
Revised Privacy Statement
Callego would adopt a robust privacy and security model so that the use of
the Intelligent Virtual Assistant – Sonya would not compromise the security of its
clients or other stakeholders. The conversation that Sonya has with the clients of
Callego must be encrypted and stored in the cloud servers of the firm for better
safety and security. The customers and clients of the firm would be intimidated
about how the data relating to the customers would be collected, used, gathered
and processed in a secure manner. In addition to this, the customers of the
outsourced customer service provider would also be informed on why the data
would be processed by the business undertaking (PrivacyPolicies.com, 2019). The
organization would make sure to explain to its customers in a clear and
understandable manner why their data would be processed by it and how its
security would be ensured at all the levels.
The role of the Data Controller and Processor would be of paramount
importance to ensure that the proper security and privacy model is in place. Thus
there professionals would be identified as they would have the ownership to take
care of the security and privacy aspects of the sensitive and confidential data
(PrivacyPolicies.com, 2019). The privacy approach of the business undertaking
would be based on fairness, lawfulness and transparency so that the personal data
of clients and customers could be processed by the organization in a lawful
manner. The latest technology-driven tools and techniques would be implemented in
the business context so that it would have genuine control over the data.
Callego would ensure to introduce and implement more straightforward and
accessible privacy policies so that it would be in a position to effectively promote
ISE 690 aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a
aa aa aa aa aa aa aa aa 3
the fundamental rights of individuals. The firm would focus on data minimization
(The 6 GDPR privacy principles you must know - now, 2018). In other words,
the personal data of the customers and other stakeholders that would be vital for
the business function would be collected. In case any data is no longer required
by the organization, it would be removed in a safe and secure manner so that the
privacy aspect would not be compromised.
Explanation
The privacy statement that has been devised for Callego is in sync with the
security principles of the General Data Protection Regulation (GDPR). A high
degree of emphasis has been laid on the safety and privacy of the customer data.
The thinking, as well as the work process, relating to the revised privacy
statement revolves around the security principles of the General Data Protection
Regulation (The 6 GDPR privacy principles you must know - now, 2018). The
organization would make sure to inform the customers about why it needs their
data and how it intends to use and process it. This knowledge would ensure that
the individuals know how the organization plans to take care of their privacy and
safety. It would also lay emphasis on the accuracy and privacy aspects of the
customer data. GDPR privacy principles act as the fundamental framework that
would guide Callego to ensure that the introduction of the Sonya project would
not jeopardize the privacy of the customers and clients of the business.
The privacy statement shows that the organization would place the
customers in the central position so that their data could be securely and safely
handled by it (Microsoft's commitment to GDPR, privacy and putting customers in
control of their own data, 2018). It would act as a critical step forward that
ISE 690 aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa 4
would strengthen the privacy rights of the customers of the outsourced customer
service provider.
Justification
The revised privacy statement that has been designed for the Callego
business entity exhibits privacy principles and standards of due care that adheres to
the General Data Protection Regulation. This is evident from the fact that high
emphasis is being given to the level of transparency and confidentiality of
customer data. GSPR lays a high emphasis on individuals and their knowledge of
how their data is being used and processed by a business undertaking. The revised
privacy statement of Callego would ensure that the customers would be informed
about how their data would be collected, used, and processed by the business
entity in a safe and secure manner.
One of the core privacy policies of GDPR highlights the significance of
data minimization. As per the regulation, the personal data relating to the
customers would be collected which would be a necessity for the purpose of the
business function. So Callego would ensure that it would gather minimum data
relating to the customers that would be a fundamental necessity for it. The core
principles of GDPR would ensure that Callego would establish a robust privacy
model that would act as the foundation of trust for its customers (General Data
Protection Regulation (GDPR): The paradigm shift in privacy, 2018). It would
ensure that the organization takes necessary care to makes sure that the privacy
and security aspects of its customers are taken care of in an effective and
optimum manner. aa
Impact on organization
ISE 690 aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa 5
Callego is a well-known provider of outsourced customer service that has
clients in various industries such as healthcare, insurance, and the financial sector.
One of the core elements that impact its sustainability and reputation in the
operational business climate is its ability to take care of the needs and wants of
its clients and customers. The revised privacy statement that has been designed for
the business undertaking would have a significant implication on its mission,
operations, and organizational culture. aa Since the privacy statement is based on the
principles of GDPR, the business would give top priority to the safety and privacy
aspects of its customers. In addition to this, the business firm would make sure to
intimate the customers about how it plans on collecting using, processing and
storing their data in a safe and secure manner. The core security and privacy
principles would help Callego to build the organizational culture that gives high
importance to privacy and security. The leaders of the firm would play an active
role to ensure that a highly functional security framework is in place that supports
the Intelligent Virtual Assistant project – Sonya. Thus the firm could imbibe the
security element in its core business processes and values so that the privacy and
security of the customers could be taken care of.
ISE 690 aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a
aa aa aa aa aa aa aa aa 6
References
General Data Protection Regulation (GDPR): The paradigm shift in privacy. (2018).
Retrieved November 20, 2019,
Microsoft's commitment to GDPR, privacy and putting customers in control of their
own data. (2018, June 7). Retrieved November 20, 2019, from
https://blogs.microsoft.com/on-the-issues/2018/05/21/microsofts-commitment-to-gdpr-
privacy-and-putting-customers-in-control-of-their-own-data/.
PrivacyPolicies.com. (2019). Retrieved November 20, 2019, from
https://www.privacypolicies.com/blog/gdpr-privacy-policy/.
The 6 GDPR privacy principles you must know - now. (2018, January 25).
Retrieved November 20, 2019, from http://techgenix.com/6-gdpr-privacy-
principles/.
ISE 690 aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa aa a aa aa aa a aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa aa a aa
aa aa aa aa aa aa aa aa 7
Students also viewed