Extending ISO 27001 with ISO 27701 involves integrating privacy-specific controls into your existing Information Security Management System (ISMS).
While ISO 27001 focuses on managing information security risks, ISO 27701 adds a layer dedicated to privacy management. This extension includes guidelines for processing personally identifiable information (PII), addressing privacy risks, and ensuring compliance with privacy regulations like the Australian Privacy Principles (APPs) and the Notifiable Data Breach (NDB) Scheme.
By combining these standards, your organisation can create a unified approach that not only secures information but also protects privacy, demonstrating a comprehensive commitment to data protection and regulatory compliance.
01
Plan
We map out the scope of your privacy information management system, identify risks that need to be managed and determine the ideal strategies to treat them
02
Do
We prepare relevant policies and processes for your organisation, and privacy controls are implemented.
03
Check
We perform your initial audit of 27701, including the underlying ISO 27001 framework.
04
Act
We develop systems to implement improvements on a continual basis, such as any findings from the internal audit.