DSCI Privacy Assessment (DAF©)

Security (DAF-S)

Security as a subject and organization function has been expanding its scope and reach, which is articulated by DSF© in 16 distinct disciplines. Maturity of each discipline is becoming important for effective delivering objectives of security. Ever increasing complexity of the underlying infrastructure, extending nature of the business ecosystem, growing pace of adopting new technology solutions and innovative ways of connecting and accessing IT assets are increasingly organizations to evolving, advanced, persistent and targeted security threats. Managing the affairs of security is becoming more daunting, demanding and granular. A weakness, lacuna and deficiency in one area may lead to catastrophic damage the organization’s security. So maturity of security in each of the disciplines is becoming important for the overall maturity of the security. Secondly, competence in the specific disciplines such as − application security, threat and vulnerability management, monitoring & incident management and data security − are becoming critical to the performance of security in delivering a swift response to the security threats and protection of the critical information assets. Assessment of these disciplines for their competence, role, efforts, and performance would provide critical insight into an organization’s capability of delivering to the desired security expectations. DSCI Assessment Framework for Security (DAF-S)© is developed on the premise of discipline based approach to security.

Discipline specific security assessment solves many problems and challenges associated with assessment of security. Many of the contemporary methods fails on account of Ability to reach realities of security, Relevancy to the evolution of the subject, challenges & trends and Dynamism to incorporate or reflect the changes & evolutions. DSCI Assessment Framework – Security focuses on Bringing Reality, Relevance and Dynamism in Security Assessments.

Key features

Reality

Reach to the granularity of practices

Reveals deficiencies at architectural and technology competence level

Detect gaps in the coverage of the programs and initiatives

Identify gaps in the arrangements set up for integrating capabilities

Discover issues in the process design

Find inefficiency of operational elements

Relevance

Focus on contemporary approaches, technical evolutions, and trends associated with a specific discipline

Compile strategic options, tactical steps & operational practices evolving around the discipline, and benchmarking the organizational practices against them

Derive methods of evaluating and benchmarking organizational practices

Dynamism

Build continuously improving knowledge base around DSF©

Introduce the modular and adaptive approach for assessment to incorporate changes

Enhance competence of assessors and auditors through continual skills and knowledge improvements

Establish a collaboration mechanism for sharing of knowledge, learningg & experiences

Security Assessment using:: (DAF-S)

Assessment Objectives:

DSF© provides a set of maturity metrics for each of the disciplines. They articulate the objectives an assessment should look at while assessing practices in a specific discipline. Each of the parameters is elaborated as expectations and capabilities that an organization should deliver in order to improve its maturity in the discipline. The assessment objectives and the respective elaboration provide broad guidelines and directions for conducting the assessment. Auditor or assessor should take a careful note of these objectives outlined at the start of each discipline.

Assessment Areas:

Each discipline organizes the assessment questionnaire in 4 to 5 assessment areas. These areas resemble the competence that an organization needs to enhance to improve its maturity. From the perspective of assessment, an organization’s performance in a specific discipline can be derived by evaluating its performance in these areas. Secondly, these areas may become measurement parameters in a measurement scheme that may evolve around the (DAF-S)©. The total 71 competence areas in the 16 disciplines will help an organization provide a high level picture of the state of security, with an opportunity to drill down to a specific competence areas.

Assessment Questionnaire:

(DAF-S)© provides a detailed evaluation questionnaire for each of the disciplines, organized under the assessment areas. The assessment questionnaire provides aspects, dimensions, and characteristics need to be evaluated in judging the competence in a specific discipline. To satisfy the objective behind a specific question, an auditor should adopt various methods such as developing information filing forms, interview to understand the dimensions & perspectives, field visit for observations and collecting the evidences and conduct a technical assessment if required. The objectives, areas and questionnaire provided by (DAF-S)© can serve the purpose of doing self-assessment, provided that the one doing the assessment is familiar with all perspectives, dimensions and aspects of conducting the assessment. Additionally, DSCI will empanel the assessors for conducting the assessment and Organizations may avail services of these assessors to perform third party assessment. The assessors will be extensively trained and certified by DSCI, to allow them perform the third party audits. The organizations intend to conduct self-assessment may like to train and certify their resources to carry the discipline specific assessment. DSCI will make specific arrangements for managing the Assessment requests. This will entail managing of assessment request, working with empaneled auditors, managing the assessment reports and results, etc.

Privacy (DAF-P©)

In 2012, the DSCI Assessment Framework-Privacy (DAF-P©) was published to help organizations provide assurance to external stakeholders on the implementation of a privacy program based on DPF©. These frameworks have been utilized and referred by many organizations across industry sectors.

It consists of two parts, with each focusing on distinct aspects of privacy implementation – one focuses on Assessment of Organizational Competence in Privacy based on practice areas defined in DPF© while the other – Privacy Principles based Assessment focuses on implementation of global privacy principles. The first part is based on the nine practice areas listed under DPF© and the assessment questionnaire is thus designed to help organizations assess and mature their privacy program. The questionnaire is based on the practices defined in DPF©, with suggestive guidance parameters to aid the assessors when conducting assessments. The assessment could be conducted in either modes: Self-Assessment or External Assessment. The external assessment through DSCI empanelled auditors could help organizations attain DSCI Certification.

The second part is intended to help organizations assess and improve maturity in the implementation of global privacy principles across all the organizational processes that deal with personal information and in the process optimize their efforts while implementing privacy principles across global operations. To address the specific needs of the organizations having operations in India, this part of the (DAF-P)© also contains an assessment questionnaire that has been designed to help assess compliance against the privacy principles prescribed under section 43A of the IT (Amendment) Act, 2008. This part of the (DAF-P)© is intended for self-assessment only and, for now, will not entitle to any sort of DSCI Privacy Certification.

Privacy Principles based Assessment: (DAF-P)

Assessment Objectives:

DSCI pioneered the DSCI Privacy Framework (DPF©) which promotes best privacy practices in nine areas. DSCI has been encouraging its adoption by the Indian industry since the publication of DPF© in 2010. The framework has received good response from the industry and it has been adopted by some large enterprises to establish their privacy programs. As part of DPF©, DSCI has also developed DSCI Privacy Principles which are based on the study and analysis of global privacy principles including those of FIPPs, OECD, EU, APEC, etc. DSCI Assessment Framework for Privacy (DAF-P)© is the logical progression of DPF© and can be used as the much required instrument to provide privacy assurance to external and internal stakeholders.

Assessment Areas:

The privacy principles represent the core of privacy protection, and privacy concerns, till date, have more or less been addressed through use of privacy principles. There exist a lot of commonalities in existing data protection regimes, in how they use privacy principles as a tool to address privacy concerns. DSCI has identified nine fundamental Privacy Principles which are derived from globally accepted principles of privacy. These nine principles form a superset of privacy principles. Concepts such as data minimization, privacy by design, privacy enhancing technologies, individual control etc. can be subsumed under these privacy principles. These principles are intended to provide the baseline level of privacy protection to all individual data subjects and end users. These principles reflect the need for an assurance level that an organization should create in its transactions with the consumers and in its practices to keep intact privacy requirements.

Assessment Questionnaire:

The questionnaire has been divided into ten areas, corresponding to nine principles, with consent & choice having separate set of questions. Questions in each of these areas have been designed in a manner that ensures that the objective of each principle is met in implementation. In designing the questions, lot of emphasis was put on identifying all the possible perspectives / aspects related to the implementation of each privacy principle. These principles were mapped to different scenarios and the different levels (process or organizational) at which they can be implemented, in order to give more meaning and practicality to the assessment questions. To keep the assessment questionnaire contemporary, evolving issues, trends, approaches and practices were also taken into consideration by referring to latest discussions, new privacy approaches and principles, proposed revisions of privacy regulations and issues in the implementation of privacy principles. This approach, based on global privacy principles, is relevant for organizations having global operations. The assessment questionnaire is primarily intended to be used as a self-assessment tool. We have also designed an assessment questionnaire for helping organizations assess compliance against the privacy principles prescribed under section 43A of the IT (Amendment) Act, 2008 that can be used by the companies having operations in India.