CYBERSECURITY & CASL AUDITS

CYBERSECURITY AUDITS

A cybersecurity audit assesses data security practices within an organization and identifies gaps that could result in information systems being compromised.

With the assistance of experienced technology partners, PRIVATECH have extensive experience in conducting information security assessments and providing services related to enhancing an organization’s security program, including:

  • Assessing Physical Security of Data Centres and Logical Security of Databases

  • Ensuring Adequate Protection of Data at Rest and in Transit

  • Development of a Security Incident Plan

  • Training on Event Monitoring and Identification of Suspicious Audit Logs

  • Forensic Analysis and Reporting

  • Vulnerability Assessments

  • Penetration Testing

  • Security Policy Development

  • Security Maturity Assessment

PRIVATECH and our trusted partners are committed to helping you effectively implement your security policies and strategies, as well as reduce the risk of a security incident.

CASL AUDITS

Canada’s Anti-Spam Law (“CASL”) came into force on July 1, 2014 with respect to the sending of commercial electronic messages to a Canadian electronic address. CASL proves to be one of the most onerous anti-spam laws in the world, and it is critical for organizations to take the necessary steps to comply with this law. With a Spam Reporting Centre staffed with CASL investigators, and the ability to reprimand organizations with heavy fines, it is clear that the CRTC is taking its enforcement powers seriously.

PRIVATECH’s CASL audit process for CEMs involves:

  • Providing a questionnaire to be completed by key groups on CEMs sent by the organization;

  • Review of CEMs and requesting necessary clarification;

  • Determining gaps between existing practice and CASL requirements;

  • Recommending changes including database structure, consent wording and procedural changes;

  • Preparing custom CASL guidelines and checklists; and

  • CASL training for key groups to ensure compliance going forward.

REMEMBER, RESPONSIBILITY FOR YOUR DATA CANNOT BE OUTSOURCED!

PRIVACY DOCUMENTATION DRAFTING