Solution

risk4all is a GRC tool that provides support during the different stages of compliance related to cyberrisk.

risk4all covers the requirements of the following norms and standards:

 

  • Information Security ISO/IEC 27001
  • Privacy Management ISO/IEC 27701
  • Data Protection GDPR
  • Business Continuity ISO 22301
  • National Security Scheme
  • ISO 31000 Risk Management
  • LFPDPPP – Federal Law on the Protection of Personal Data in Possession of Private Parties (MX)

risk4all is a multi-language, multi-company solution.

risk4all solution covers all your risks and compliance needs.

ISO / IEC 27001 – Information Security Management System

International standard that enables the assurance, confidentiality and integrity of data and information, as well as the systems that process it. Information Security Management is complemented by the good practices or controls established in the ISO/IEC 27002 standard.

ISO / IEC 27701 – Privacy Management System

Extension of ISO/IEC 27001 and ISO/IEC 27002 that sets out all requirements and specifies the guidance to be followed to implement, maintain and continually improve an Information Privacy Management System (IPMS).

GDPR – General Data Protection Regulation

European Regulation on the protection of individuals with regard to the processing of their personal data.  In Spain, the processing of personal data must also comply with the LOPDGDD.

ISO 22301 – Business Continuity Management System

An international business continuity management standard that helps organisations prepare for emergencies, manage crises and improve their operational resilience, secure the supply chain and protect their reputation in the event of a crisis.

ENS – National Security Scheme

Royal Decree which, in the field of electronic administration in Spain, aims to establish the security policy for the use of electronic media and is made up of basic principles and minimum requirements that allow adequate protection of information.

ISO 31000 – Risk Management System

International standard that provides guidelines and principles for managing organisational risk, where the design and implementation of risk management will depend on the diverse needs of each organisation, its specific objectives, context, structure, operations, processes, activities, services, etc.

LFPDPPP – Federal Law on the Protection of Personal Data Held by Private Parties

Mexican law that aims to regulate the right to informational self-determination. Its provisions are applicable to all natural or legal persons, in the public and private sector, both at federal and state level, who carry out the processing of personal data in the exercise of their activities.