The following topics are covered
- Information security vs. data protection – objectives, motivation, perspective, standardisation, overview
- Information security management system (ISMS) – BSI & ISO 27001
- ISO 27002 Controls & Control Objectives (exemplary application in practice from a data protection perspective)
- EU GDPR (General Data Protection Regulation) – the development
- Current trends
- NIS and NIS-2 (Network and Information Security Act) – What does this mean for data protection?
Your advantages
- Update on the legal framework: You will learn why the EU Data Act 2024, EU AI Act 2024 and NIS-2 are relevant for your company. Learn what steps you should take in your company now using practical examples.
- Data protection technologies: Learn about the latest technologies and tools that can be used in the area of data protection and data security. This includes, for example, encryption techniques, anonymisation methods, data protection frameworks and compliance software.
- Trends in data security and privacy practices: The training is designed to help participants identify and understand current trends and best practices in data protection using ISO 27001 and NIS-2. This may include analysing current data protection incidents, threat landscapes, security risks and data protection strategies.
- Implementing data protection in practice: The training is designed to provide participants with practical guidance and case studies to help them effectively implement data protection principles and policies in their organisations. This includes the design of data protection programmes, training for employees, data protection audits and collaboration with other departments such as IT and Legal.
Your lecturer: Manfred Spanner, MSc.
Manfred Spanner, MSc, is Head of Department Group Data Protection Office at OMV Aktiengesellschaft and is also responsible for compliance with the General Data Protection Regulation in his role as Data Protection Officer. Previously, as Group Chief Information Security Officer (Group CISO), he was responsible for information security at the ÖBB Group, where he successfully implemented the information security strategy and organised and implemented the initial preparations due to his involvement in the NIS Act. He also teaches at the St. Pölten University of Applied Sciences and is the author of several specialised books and has multiple certifications (CISA, CISM, CRISC, ISO 27001, etc.).
Prerequisites for participation
None.
Target group
The training is aimed at the following target group: (C)ISO, DPO or cyber managers as well as people who want an overview of these topics in just one day.
Date
10 June 2024 | Vienna