inflearn logo

Service Privacy and Security Review (Advanced Course)

This training explores the service privacy reviews pursued by Naver, Kakao, and Toss. It is designed to improve the capabilities of domestic consulting and privacy protection teams by identifying where service-specific privacy protection should be applied and explaining what to check during service reviews. Rather than covering only general laws or standard review checklists, this is an in-depth review training program that also provides a checklist.

1 learners are taking this course

Level Intermediate

Course period 6 months

ISMS-P
ISMS-P
AI
AI
CPPG
CPPG
Engineer information security
Engineer information security
security training
security training
ISMS-P
ISMS-P
AI
AI
CPPG
CPPG
Engineer information security
Engineer information security
security training
security training

What you will gain after the course

  • Creation of a Personal Information Flowchart(Deep)

  • Personal Information Processing System Inspection (Deep)

The institutions I have consulted have had no deficiencies identified during external or internal audits, and have never experienced a data breach to date.

Many recent data breach incidents and supervisory improvement directives have been made public. It is necessary to determine whether this is because organizations are receiving inadequate consulting or because their privacy teams’ own management systems and regular inspection practices are insufficient.


This training course is intended for domestic privacy protection consultants and privacy protection teams,

It provides inspection methods and inspection checklists to enhance the review of measures for ensuring the security of internal personal information processing systems,

Provides guidance on practical matters for each provision, including checking internal and external interconnected systems and verifying overseas transfers, thereby enhancing the internal personal information management system (the foundation is the enhancement of the personal information flowchart).


When applied, the direction is the same as the privacy officers and leap-forward goals of the three companies—Naver, Kakao, and Toss.

It lies in proactively preventing incidents and inspecting the prevention system.


In consulting, I establish a management system that considers how to handle customers’ sensitive personal information, as well as relationships between internal employees and departments.

Establishing an incident response team and incident response system to prevent actual hacking, and conducting drills identical to real-world scenarios.

Additionally, rather than producing reports merely for show, it serves as an organization that supports the development of actual services, basing its approach on personal information utilization strategies to secure revenue.


Looking at some of the top domestic consulting materials, many cases merely reviewed the law or deemed things satisfactory based on just a few pieces of evidence.

Problems arise, such as issues persisting because an adequate inspection plan was not properly established, resulting in inadequate inspections.


Now that the representative’s legal responsibility has been newly established, it is necessary to improve the supervisory system under the direction of the person in charge. Through proper inspections and an understanding of the overall process in the reports submitted to the representative, the same management system as that of the three companies mentioned above can be maintained without significantly increasing the budget or investment. This is a strategy that can also be sufficiently operated under a management system in which non-specialist personnel are replaced every three years (reason: because consulting is provided).


For organizations where the person in charge, team leader, and 담당자 are already made up of specialists, it would be good to check whether they are currently being properly reviewed and addressed, and whether the timing, evidence, communication system, and frequency are appropriate. (This is a lecture without audio.)


The consulting price is almost free. It is essential to select a company that can communicate and work harmoniously with the IT department.


🔥 Are you still wrapping up your personal information protection inspection after looking at just a few screens and pieces of evidence?

These cases are common when inspecting personal information processing systems.

📄 Review the Privacy Policy
🖥️ Review the Personal Information Processing System screens
📋 Interview the person in charge
📁 Review a few pieces of evidence

And the assessment is complete.

However, if you cannot properly understand how personal information enters the actual service, where it moves, which systems store it, who accesses it, and when it is deleted, can you really call that a “service personal information security review”?, thì liệu có thể gọi đó là “đánh giá tính bảo mật dữ liệu cá nhân của dịch vụ” hay không?

This “Service Personal Information Security Review Training” is not simply training to check whether laws and regulations are being complied with.

🚨 How to understand the actual service structure, track the entire process of personal information processing, and identify blind spots overlooked by privacy officers

It also focuses on the service personal information security review checklist so that you can apply it in practice.


🔍 Are you creating your personal information flowchart based solely on screen design documents?

When creating a personal information flow diagram, relying solely on the personal information visible on screens and interviews with the person in charge to understand the current state may result in actual personal information processing activities being omitted.

For example, more systems and companies are connected than you might think when a customer uses a service.

🔗 Identity verification providers
💬 Text message and email delivery providers
📊 CRM and customer management systems
☁️ SaaS and cloud services
📈 Data analytics systems
💾 Backup servers and backup databases
🏢 Partner, outsourced, and sub-outsourced companies

The problem arises when privacy officers or consultants create the flowchart based only on “the personal information visible on the screen,” without properly understanding these connection structures.

In this training, we will cover how to use a personal information flowchart not merely as a document, but as a tool for verifying the actual service structure and the movement of personal information. 🔎

We trace, based on the actual service, where personal information is collected, which systems it is integrated with, for what purposes it is stored, and whether it is provided to other systems.


🏢 Is it enough to compile outsourcing, partnerships, and re-outsourcing information just once a year?

“We asked each department to submit its outsourcing status and compiled the information.”

Have all the actual personal information processing activities occurring in the service really been identified?

In actual services, new solutions may be introduced, external vendors may be added, onward outsourcing may occur, and the way personal information is processed may change after a contract is signed.

In this training, we will review the status of outsourcing, partnerships, and re-outsourcing from the following perspectives.

✅ Does the person in charge of personal information check before outsourcing or partnering takes place?
✅ When the status of personal information processing changes after the contract is signed, are the management records also updated?
✅ Do the personal information actually provided and the personal information items defined in the contract match?
✅ How is the status of onward entrustment being identified?
✅ Are the personal information processing systems of entrusted parties and sub-entrusted parties actually being inspected?
✅ Are the inspection results and deficiencies reported to the person in charge?
✅ Is follow-up carried out through the implementation of improvement measures?

Explore how to manage the entire lifecycle of personal data processing, from initiation and changes to termination, rather than simply “compiling the current status”. 📋


🌍 International transfers—are you sure “not applicable” is correct?

As new services such as AI, SaaS, and cloud solutions are introduced, the environment for processing personal information continues to become more complex.

However, when we look at the current state of personal information processing, it is still often managed as “No overseas transfer applicable”.

In this training, we cover how to review the current status of cross-border data transfers from a service perspective, including how to determine whether the service architecture allows access to or retrieval of personal information from overseas and how to identify the points where personal information is actually connected to overseas locations. 🌐


🗑️ Destroying personal information doesn’t end with deleting it from the DB.

The member has been withdrawn from the personal information processing system.

In that case, has all the personal information really been destroyed?

💾 Operational DB
☁️ External solution servers
🗄️ Backup servers and backup DBs
📎 Attachments uploaded by customers
📜 Logs
📊 Data analysis and marketing systems
💻 PCs used by personnel handling personal information

Personal information may actually remain in various locations.

In this training, we will review the destruction of personal information by tracking the entire actual service, rather than merely checking whether the database has been deleted.

In particular, it covers how to check each personal information processing system’s backup environment, external solutions, attachments, logs, and more, along with how to actually inspect each area where personal information is processed. 🔥


🔐 A Security Review of Personal Information Processing Systems: Don’t Just Look at the Admin Screen

The key to reviewing the security of personal information in a service is not just checking the screens of the personal information processing system.

If it is a system that actually processes personal information, the following areas must also be reviewed.

🖥️ Personal Information Processing System
🗄️ Database
🛡️ Server Access Control
🔐 DB Access Control
👤 Account and Permission Management
📥 Download and Print Functions
🌐 External Access and Administrator Pages
💾 Backup Server and Backup Database

In this training, we explain through a checklist how far you should expand the scope when inspecting a single personal information processing system.


👤 “Is it really okay to give people the same permissions just because they’re in the same department?”

When reviewing access privileges for personal information, it is difficult to identify substantive issues by simply checking whether an account exists or whether an access-approval process is in place.

⚠️ Employees who do not need to download can still download
⚠️ Permissions needed temporarily remain active for 365 days
⚠️ The same permissions are granted in bulk to employees in the same department
⚠️ Management of administrator and handler accounts is unclear
⚠️ Administrators still manually grant permissions even after integration with the HR database
⚠️ A permission matrix exists, but there is no record of verifying its appropriateness

In this training, we will cover the perspective of reviewing not whether a permission exists, but whether it is actually necessary for the job, as well as how to identify blind spots in access privilege management for each personal information processing system. 🔑


📊 Is reviewing access logs complete if you only look at the solution’s results?

Even when using an access log management solution, there are still many things to check during the actual inspection process.

🔍 How are direct DB connections managed?
🔍 Are there any gaps where required access log items are omitted?
🔍 Are download reasons and lookup reasons being entered repeatedly in a merely formal manner?
🔍 Are the personal information fields available for download minimized?
🔍 Are output fields minimized by user and by task?
🔍 Can misuse of personal information be detected proactively rather than audited afterward?

In this training, we will go beyond simply “storing” access logs and explore how to enhance an actual inspection system, including direct DB access, downloads and printing, reasons for inquiries, and the misuse of personal information.


🎯 The key focus of this training is “properly understanding the service.”

The most dangerous moment when handling personal information protection work may be the moment you think, "We already know everything about how personal information is processed."

However, actual services are constantly changing.

New systems are integrated 🔗
external solutions are added ☁️
subcontracting occurs 🏢
data is moved to new systems 📊
backup environments expand 💾
and AI and cloud services are introduced 🤖

Therefore, privacy protection officers must move beyond simply compiling submitted materials and be able to directly understand and verify how the service is actually operated.

In this “Service Personal Information Security Review Training”, we cover everything from understanding personal information flows to outsourcing, partnerships, and re-outsourcing, overseas transfers, disposal, access privileges to personal information processing systems, encryption, access logs, downloads and printing, misuse of personal information, and backup servers and backup databases!

🔥 How far you need to track and review personal information based on actual services
🔥 Why the current status of personal information processing is omitted from existing assessments
🔥 What personal information officers need to check before and after service changes
🔥 A service personal information security review checklist that can be applied immediately in practice

It focuses on providing these resources.

📌 Personal Data Protection Officer
📌 Personal Data Protection Consultant
📌 ISMS-P and PIA Practitioner
📌 Personal Data Processing System Operations and Development Officer
📌 Processor and Personal Data Processing System Inspection Officer

then through this training, you can gain a new perspective on reviewing personal information with a focus on actual services and systems, moving beyond the existing “evidence-centered personal information inspections”.

🚀 Personal data protection must not end with reviewing documents.
🔍 You need to directly understand how personal data is processed within actual services and identify blind spots.

Right now, through “Service Privacy Security Review Training”,
take your standards for service-based privacy protection inspections to the next level! 🔐🔥

Recommended for
these people

Who is this course right for?

  • Personal Information Flowchart Coordinator

  • Person Responsible for Ensuring the Security of the Personal Information Processing System

Need to know before starting?

  • Personal Information Impact Assessment Experience

  • ISMS-P Certification Audit Experience

Hello
This is jueygrace

428

Learners

43

Reviews

4.0

Rating

51

Courses

A top domestic privacy expert with over 8 years of experience in privacy education, advisory, and consulting (performed 1st-tier financial sector ISMS-P/ISO27701/internal audits/regular evaluations; achieved S-grades for all consulting firms in public institution protection level evaluations for 6 years; conducted public institution impact assessments; served as a privacy instructor for major corporations for 3 years; established mid-to-long-term strategies (master plans) for manufacturing companies; and performed AI security reviews/deliberations, etc.)

 

Experience and Performance

 

1. Tutoring

2. Education

3. Consulting

4. Project Design/Support

5. Q&A (Inquiry Response)

6. Task delegation

7. Establishment of procedures

8. Procedure improvement

9. Status survey, diagnosis, and reporting

10. Establishment of plans for introducing new technologies, etc.

11. Establishment of Information Security/Personal Credit Information Protection Master Plan (Establishment of Mid-to-Long-term Strategy)

12. ISMS, ISMS-P evidence preparation and audit response

13. ISO27001, ISO27701 evidence preparation and audit response

14. Preparation of evidence and report writing for Personal Information Protection Level Assessment

15. Cybersecurity Status Assessment

16. Support for the enactment and revision of regulations, guidelines, procedures, manuals, and guides

17. Support for ongoing information security evaluation

18. Personal information leakage incident simulation drill

19. DRP, BCP Business Continuity Drill

20. Establishment of DRP and BCP business continuity plans

21. PbD(Privacy by Design) procedure and system menu planning

22. Establishment of SbD (Security by Design) procedures and security review criteria

23. Establishment and improvement of DevSecOps procedures

24. AI System Security Review

25. AI system personal information protection inspection (customized)

26. Support for pseudonymization, including review of pseudonymization adequacy

27. Designation of pseudonymization officers and definition of business R&R

28. Inspection of the storage and transmission system for personal information in access control systems (smart gates, fingerprint authentication, in-house apps)

29. Promotion, campaign planning and support

30. Planning and production of promotional materials, quizzes, and participatory events

31. Establishment of improvement plans for information security and personal information protection organizations

32. Checking the adequacy of information security and personal information protection budgets and establishing improvement plans

33. Support for collecting opinions on the revision of regulations and procedures, and support for conducting surveys

34. Support for exception handling for non-encrypted personal information and inquiry reason input

35. Support for producing Information Protection Committee reporting materials, preparing agenda for the Personal Information Protection Working-level Council, and supporting the attendance of advisory members

36. Support for personal information processing system inspection

37. Support for creating personal information flow tables and personal information flowcharts

38. Support for H/W and public/private cloud asset identification and establishment of asset classification standards

39. Support for asset C/S/O assessment and risk assessment report preparation

40. Support for drafting protection measures and improvement plan reports

41. BPF malware inspection

42. Inspection of shared folder usage status

43. Creation of critical data flow diagrams

44. Establishment of control system security monitoring plan

45. Support for trustee status investigation

46. Support for status survey of fixed video data processing devices

47. Support for status survey of mobile visual data processing devices

48. Support for personal information file updating survey

49. Support for investigating targets of personal information impact assessments

50. CPO Best Practice Sharing

51. Sharing CEO Best Practices

52. Establishment of open source management guidelines

53. Establishment of cloud management system

54. Vulnerability analysis and evaluation of electronic financial infrastructure

55. Vulnerability analysis and evaluation of critical information and communications infrastructure

56. Security Review Committee

57. Evaluation of the adequacy of firewall and security equipment (WAF, VPN, etc.) policies

58. Investigation of Account and Permission Status and Evaluation of Adequacy

59. Investigation and adequacy assessment of log and backup status

60. Investigation and adequacy assessment of personal information collection, storage, and provision status

61. Investigation of status and adequacy assessment of collection, storage, and provision of critical information

62. Adequacy assessment of security threats and security management for PC integrated security solutions, antivirus, DLP, DRM, data transfer, email, SSO, etc. (Solution bypass)

63. Assessment of Server Access Control and DB Access Control Policy Adequacy

64. Investigation and adequacy assessment of EOS and patch status

65. IP and Port Scanning

66. Investigation and inspection of app personal information protection status

67. Privacy Center Operation

68. 24/365 Personal Information Protection Help Desk Operation

69. Consent withdrawal system planning

70. Personal information inquiry and access system planning

71. Preparation of reporting materials for CISO/CPO/CEO

72. R&D Project

73. Consent form inspection checklist

74. Privacy Policy Review Checklist

75. Children's Privacy Inspection

76. Access log (inquiry, download) misuse and abuse consulting

77. CCTV De-identification Consulting

78. Penetration Testing

79. Web Vulnerability Assessment

80. App Vulnerability Assessment

81. CS Vulnerability Assessment

82. Mock Training

83. Tabletop Exercise (TTX)

84. Network Penetration

85. Inspection of Internal Management Plan Implementation Status

86. Personal information management status inspection

87. Trustee Inspection

88. On-site inspection of trustees

89. Service Security Inspection

90. On-site service security inspection

91. Creation and management of the list of handlers to keep it up to date

92. Review of access rights and establishment of criteria for differential granting

93. Creation of Security Pledge and Personal Information Pledge

94. Establishment and revision of access control policies

95. Personal information meetings, inspections, and support for affiliated and subordinate organizations

96. Discussion of group company personal information protection policies and measures

97. Establishment of personal information destruction plans and investigation of destruction status (destruction methods, destruction results)

98. Review of legal grounds for personal information retention and inspection of separate storage status

99. Establishment of procedures for requesting personal information access and investigation of current status

100. Improvement of procedures and status survey for requests such as viewing personal video information (including objections)

101. Support for applying and improving matters regarding refusal of automated collection and requests for withdrawal of consent, and support for improvement

102. Support for the application and improvement of the right to data portability for personal information

103. Support for personal information processing policy review and improvement measures (appropriateness, understanding, readability, etc.)

104. Personal information collection, use, and provision inquiry consent form review and system consent status check (minimum collection, form review)

105. Investigation of consent status (Investigation of CI/DI collection, comparison of DB storage status, default consent checks, etc.)

106. Personal information file consolidation survey and new personal information file survey

107. Inspection of the appropriateness of the grounds for processing personal information files

108. Review and re-establishment of password creation rules

109. Full investigation of access control (IP, duplicate login restriction, session blocking)

110. Full investigation of encryption status for internal and external transmissions

111. Personal Information Exposure Check

112. Source code inspection

113. Establishment of internal employee personal information management standards (labor-management consultation)

114. Production and design review of personal information processing policies in the form of webtoons, posters, easy-to-understand versions, and versions for children/the elderly and employees

115. Disclosure of outsourcing status via QR, bulletin boards, etc., use of icons and characters, and disclosure of personal information processing policy in mobile environments

116. Appropriateness of personal information consent and agent identity verification during landline processing at call centers, branch offices, etc.

117. Review of appropriateness for recording servers and STT (Speech to Text)

118. Review of the adequacy of transmission and storage for SMS/Email/Notification Talk transmission servers

119. Identification of business processes (by unit task), review of security and personal information protection adequacy

120. Generative AI utilization training and promotion (Cyber Security Diagnosis Day, Personal Information Protection Day)

121. Preparation of Personal Information Protection Master Plan and Personal Information Protection Implementation Plan

122. Support for information disclosure and public data provision tasks

123. Computerization of consent forms (improvement of AlimTalk viewing consent)

124. Review of overseas personal information protection laws

125. Information security inspection for new technology environments and personal information protection inspection business support

126. Support for the task of changing consent forms->information guides

127. Destruction status and appropriateness of destruction (cases of reports due to notifications such as emails to data subjects because data remained)

128. Cases of exposure of resident registration numbers, etc., via email due to employee error (establishment of prevention systems)

129. Establishment and application of procedures to block personal information uploads on internal and external bulletin boards, etc.

130. Consultation on requesting safety measures for the use or provision of personal information for purposes other than intended, or for personal information partnerships, and review of the reply regarding safety measures.

131. Support for trustee contract renewal (contract modification)

132. Comparison of pros and cons for SNS simple login reorganization and change support (SNS simple login vulnerabilities)

133. Vulnerability assessment of identity verification methods such as resident registration cards or mobile phone identity verification (numerous incident cases)

134. Consultation on changes to the division of duties

135. Internal management plan employee training

136. Establishment of reward and incentive plans

137. Support for PET (Privacy Enhancing Tech) implementation and training/consulting on synthetic data

138. Personal information protection consulting in new technology environments (Cloud, 5G, Generative AI, AI systems, drones), etc.

139. Deriving a plan to strengthen personal information security measures

140. Analysis and evaluation of internal management plans

141. Legal Compliance Assessment

142. e-Privacy Plus certification preparation and audit response

143. APEC CBPR certification preparation and audit response

144. CSAP certification preparation and audit response

145. Disclosure of ESG Information Security and Personal Information Protection Activities

146. Preparation and response for research institute institutional evaluation

147. Preparation and response for central administrative agency evaluations

148. Writing news press releases and creating slogans

149. Zero Trust Maturity Assessment

150. Establishment of improvement plans for trustee management

151. CVE Inspection

152. Management of trustee personal information processing flow and provision ledger

153. Investigation and inspection of personal credit information masking status

154. Inspection of wireless LAN usage status

155. Establishment and advancement of security management systems for public/private cloud environments

156. Individual Business Trustee Inspection

More

Curriculum

All

3 lectures ∙ (12min)

Published: 
Last updated: 

Reviews

Not enough reviews.
Please write a valuable review that helps everyone!

jueygrace's other courses

Check out other courses by the instructor!

Similar courses

Explore other courses in the same field!

Limited time deal

$354,556.00

25%

$17.60