BS 10012 on Data Protection and PIMSs
The new British Standard 10012:2009, Data Protection - Specification for a Personal Information Management System, has been published.
British Standard 10012:2009 was the subject of an earlier draft for public comment (DPC) and I worked with the OWASP Industry Committee on a response.
BS 10012 is not an alternative to the excellent guidance for organisations now produced by the UK's Information Commissioner's Office, but instead is a specification for a personal information management system (PIMS). A PIMS is a governance process for all types of personal information within a company but could also be used for other types of sensitive data. BSI's slant on this is that a PIMS, and therefore BS 10012, could help maintain and improve compliance with the Data Protection Act (DPA) 1998.
A good start and one to watch.
Posted on: 09 June 2009 at 10:32 hrs

Comments are filtered automatically and should appear shortly after they been checked.