課(ke)程(cheng)描述INTRODUCTION
企業安全體系搭建培訓
日(ri)程安(an)排(pai)SCHEDULE
課程大(da)綱(gang)Syllabus
企業安全體系搭建培訓
課程背景 Course Background:
2018年5月25日,GDPR(歐盟通用數據保護條例,General Data Protection Regulation)正式生效,開啟了一個新的數據合規時代。1000萬到2000萬歐元,或企業全球年營業額2%到4%的罰款讓所有受其管轄的企業都必須將數據保護合規提升到生存高度予以應對。面對新法,企業的應對仍然顯得十分不足。2017年,英國政府在“四大”協助下發布了富時350指數網絡治理健康檢查報告,報告顯示近六成的受訪者表示對GDPR不太或并不了解,同時僅有8%的受訪者表示已經做了充分的準備,接近75%的人表示僅做了部分準備。那么從國內外來看,未來數據安全法規趨勢如何?網絡安全問題的本質是什么?企業如何規避不合規數據的風險?怎樣提供可切實實施的風險整改計劃?
CCP法商精英薈特邀EY安永法證及誠信合規服務部門資深合伙人陳熾先生來為我們解讀法規、分析案例、指點趨勢。
On May 25, 2018, the General Data Protection Regulation (“GDPR”) formally came into force, opening a new era of data compliance. A fine of Euro 10-20 million or 2-4% of annual global turnover forces the companies bound by GDPR to pay high attention to data protection compliance. However, enterprises’ response to GDPR seems to be quite inadequate. In 2017, the British government issued FTSE 350 Network Governance Report under the assistance of Big 4 Accounting Firms. The Report shows that nearly 60% of the respondents did not know much about GDPR, only 8% of them said they had made adequate preparations, and nearly 75% of them said they had made some preparations only. What is the future trend of the data security regulations at home and abroad? What is the nature of cybersecurity issues? How to avoid the risks of non-compliant data? How to develop a practical and feasible risk control plan?
Mr. Chen Chi, a senior partner of EY Forensic & Integrity Services was invited to interpret GDPR, analyze cases and explain the trends.
課程收益 Course Benefits:
1.了解GDPR、中國網絡安全法及其他相關法律法規要點
Understand the main points of GDPR, the Cybersecurity Law of the People’s Republic of China and other relevant laws and regulations
2.了解GDPR及其他相關法律對于企業所處行業的影響程度
Understand the impact of GDPR and other relevant laws and regulations on the industry
3.了解企業各個層級部門應如何應對外界監管規定
Understand how the departments of enterprises at each level should cope with the regulations
4.掌握提升企業數據合規、網絡安全的方式方法
Learn the ways and means to improve enterprise data compliance and cybersecurity
5.了解危機發生時應如何進行處理和應對的方法
Understand how to deal with crises
6.學習先進風險評估框架,并能運用到實際工作中
Learn advanced risk assessment frameworks and apply them to practical work
誰該來參加 Who Should Attend:
企業合規、法務、信息安全部門負責人,擁有合規、法務、信息安全職能的紀檢監察部門負責人,從事合規、法務、信息安全實務操作的部門主管及一般員工,其他對數據合規、網絡安全感興趣的有識之士,以及想提高企業綜合管理能力的優秀積極人士。
Persons in charge of corporate compliance, legal affairs and information security departments; persons in charge of discipline inspection and supervision departments with the functions related to compliance, legal affairs and information security; department heads and general employees engaged in compliance, legal affairs and information security practices; far-sighted persons interested in data compliance and cybersecurity; and activists who want to improve the comprehensive management capabilities of their enterprises.
課程大綱 Course Outline:
一、GDPR及相關法律法規
GDPR and relevant laws and regulations
1.GDPR概述
GDPR overview
2.中國網絡安全法概述
Overview of the Cybersecurity Law of the People’s Republic of China
數據隱私保護 Data privacy protection
網絡安全等級保護 Classified protection of cybersecurity
信息跨境傳輸 Cross-border information transmission
網絡安全監控與應急響應 Cybersecurity monitoring and emergency response
3.全球數據保護法律法規環境
Global data protection laws and regulations
二、數據合規、網絡安全的趨勢
Data compliance and cybersecurity trends
1.數據安全事件及處罰案件
Data security incidents and punishment cases
2.企業應對現狀
Enterprises’ response
3.從國內外大背景看趨勢
Trends from the perspective of domestic and international background
三、企業應對策略
Enterprises’ countermeasures
1.管理層應對策略
Countermeasures at the management level
2.業務層應對策略
Countermeasures at the business level
3.技術層應對策略
Countermeasures at the technology level
四、識別敏感信息
Identification of sensitive information
1.數據生命周期管理
Data lifecycle management
數據信息的收集與使用
Collection and use of data information
數據信息的加工、傳輸與共享
Processing, transmission and sharing of data information
數據信息的保存與銷毀
Preservation and destruction of data information
2.識別個人數據、重要數據、商業秘密數據
Identification of personal data, important data and trade secrets
五、建立風險評估矩陣
Establishment of risk assessment matrix
1.怎樣確定數據安全評估標準
How to establish data security assessment standards
2.定量化衡量風險等級及對企業的影響
Quantitatively measure risk levels and risk impact on enterprises
3.怎樣提供可切實實施的風險整改計劃
How to develop a practical and feasible risk control plan
六、建立數據治理框架
Establishment of data governance framework
1.數據治理的全過程
Whole process of data governance
2.應對型數據治理及主動型數據治理
Passive and active data governance
3.數據管理能力成熟度模型
Data management capability maturity model
七、搭建數據合規體系
Establishment of data compliance system
1.進行GDPR及網絡安全法適用性評估
evaluate the applicability of GDPR and cybersecurity laws
2.劃分數據類型及區別制定合規策略
Classify data and develop different compliance strategies based on the classification
3.更新與完善隱私政策
Update and improve privacy policies
4.建立風險評估、記錄與響應機制
Establish risk assessment, recording and response mechanisms
八、搭建網絡安全體系
Establishment of cybersecurity system
1.網絡安全威脅類型
Types of cybersecurity threats
2.常見的安全服務機制
Common security service mechanisms
3.構建網絡安全防護體系政策建議
企業安全體系搭建培訓
轉載://citymember.cn/gkk_detail/48419.html
已開課時間Have start time
安全管理內訓
- 辦公人員信息安全意識教育培 劉道軍
- 電力企業觸電事故防范與處理 姜力
- 網絡安全與數據安全 劉道(dao)軍
- 落實安全生產*法律法規、構 專(zhuan)家(jia)講
- 《班組長系列--全員參與現 鄭祖國
- 電力營銷安全風險防范 暨新 姜(jiang)力
- 安全大師課:從多行業案例看 徐老師
- 防臺風專題培訓 李開東
- 網絡安全管理知識 劉道軍
- 現場作業安全事故預防 李開東
- 網絡與信息系統安全 劉道軍
- 網絡攻防技術實踐培訓課程 劉道軍(jun)