UNIFIED DATA RISK MANAGEMENT
Cognitivo has an in-house developed data management framework which unifies 4 Data Risk Management topics unified under the ISO31000 standard for risk management:
Data Use and Quality – how does the organisation want to use, who should the data be shared with and what level of assurance do they need over the quality of that data.
Privacy & Confidentiality - What data needs to be explicitly restricted from certain parties for reasons of privacy and confidentiality
Retention & Disposal - How long we should retain certain data to, dispose of data we don’t need to either meet certain obligations or reduce storage costs.
Information Security - What our information security / access controls environment should be in enforcing the above business and policy objectives.
For example, compliance with GDPR’s right-to-forget requirement requires both a privacy and a retention. Your organisation cannot be dealing with these 4 areas of data risk in isolation.
Our approach utilises a fine-grain, attribute based approach to built to accomodate, customer-centric, API driven, cloud-based & zero/low trust architectures.
If you are still thinking about roles-based authentication and domain based data management (if you’ve been told to look at key data elements) your data management and information security
Refer to our blog post for more information on our unified data risk management framework or get in touch with our team.