Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.
Breach notification runs on different clocks: 72 hours under the GDPR, the first hour in Argentine banking, up to 60 days under HIPAA.
The GDPR treats health data as a special category. What it asks of the people in a healthcare organization and what to prove in an audit.
On audit day your spreadsheet shows all green, but the auditor asks four questions a percentage can’t answer. What they are and why the Excel falls short.
Your compliance percentage measures completed courses, not how many people should have been trained. Why 100% can hide half your organization.
Control 6.3 of ISO 27001:2022 turns awareness into an auditable control. What it requires, what changed since 2013, and how you prove it in an audit.
Awareness compliance is continuous, not annual. Training expires silently and manual plans always run late. Why your spreadsheet is already lying.
Since March 1, 2025, Chile’s Law 21,663 sanctions regime is live. What it demands from the board, what from the employee, and how to prove it.
Article 21 of NIS2 requires training for all staff and the management body. What to cover, how to measure it, and how to prove it under audit.