Customers: Asia-Invest bank
Contractors: Andek Product: Projects of external audit of IT and security (in tch PCI DSS and SUIB)Project date: 2013/03 - 2013/05
|
Content |
The Andek company announced on May 23, 2013 project completion on personal data protection in Asia-Invest Bank.
Compliance
According to the mission of Asia-Invest of Bank, before his representatives there was a problem of reduction of an order (process) of personal data processing (PDN) in compliance with requirements of the law.
As the partner in the project selected Andek company.
Specialists of the company received tasks: develop organizational and administrative documents in the order of processing and personal data protection, to build the system of security of personal data and to carry out conformity assessment of the information security (IS) of Asia-Invest of Bank to requirements of the standard of the Bank of Russia of service station of BR IBBS-1.0.
Actions
Project works are carried out in several steps. At the first stage audit of processing and personal data protection (PDN) is booked. Specialists of the company contractor studied documentation regulating an order of information security support and made a preliminary estimate of compliance to requirements of service station of BR IBBS-1.0. At the first stage recommendations for increase in level of compliance to requirements of the standard of the Bank of Russia were developed.
Reduction of an order of processing of PDN in compliance to requirements of service station of BR IBBS-1.0 within which documents on processing and protection of PDN were developed became the next stage, the system of security of personal data is designed and implemented, final conformity assessment to requirements of the standard of the Bank of Russia is carried out.
At the final stage of the project the conclusion about compliance of Asia-Invest of Bank to the standard is created.
Result
Project deliverable - the system of personal data protection corresponding to the legislation and also a full range of organizational and administrative documents regarding an order of processing and protection of PDN.