Regarding compliance with regulatory and legislative changes, which misconception does Anton have?
Privacy compliance requires ongoing monitoring and periodic reassessment because regulatory changes can require updates to policies and procedures. A one-time analysis cannot reliably establish compliance for the following five years. NIST’s privacy risk-management guidance describes continuous monitoring and updating to address changing requirements and risks.
Community Discussion