Customers: Amway Contractors: Microtest Product: Projects of external audit of IT and security (in tch PCI DSS and SUIB)Project date: 2011/07
|
Microtest completed the first phase of the complex project on personal data protection in the Russian representative office of Amway.
Personal data about the independent entrepreneurs of Amway (IEA) working in Russia, and their financial performance should be reliably protected. The company bears responsibility for safety of this information according to the law "About Personal Data". Besides, Amway in Russia it is obliged to fulfill the requirements and legislations of the USA where there is a company headquarters.
In selection process of the contractor the company considered not only project experience of contractors of area of IT security for multinational companies in Russia, but also an opportunity to provide fulfillment of requirements of the American legislation.
Within the first stage of the project – audit of personal data information systems - specialists Microtest studied processing of personal data, defined relevant security risks, developed models of threats. Development of requirements to the system of personal data protection taking into account provisions of the Russian legislative and regulating documents and also the recommendations of the NIST Special Publication 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) standard became a result of works.