A. Fundamental Principles of Privacy in IT
a. Organization privacy notice
b. Organization internal privacy policies
c. Organization security policies, including data classification policies and schema, data retention and data deletion
d. Other commitments made by the organization (contracts, agreements)
e. Common IT frameworks (COBIT, ITIL, etc.)
f. Data inventories
g. Enterprise architecture and data flows, including cross-border transfers
h. Privacy impact assessments (PIAs)
B. Information Security
a. Security requirements in commercial transactions and the law
b. Incident response—security and privacy perspectives
c. Security and privacy in the systems development life cycle (SDLC) process
d. Privacy and security regulations with specific IT requirements
C. Information Governance
D. The IT Professional