課程背景 Course Background:
    2018年5月25日,GDPR(歐盟通用數(shù)據(jù)保護條例,General Data Protection Regulation)正式生效,開啟了一個新的數(shù)據(jù)合規(guī)時代。1000萬到2000萬歐元,或企業(yè)全球年營業(yè)額2%到4%的罰款讓所有受其管轄的企業(yè)都必須將數(shù)據(jù)保護合規(guī)提升到生存高度予以應對。面對新法,企業(yè)的應對仍然顯得十分不足。2017年,英國政府在“四大”協(xié)助下發(fā)布了富時350指數(shù)網(wǎng)絡治理健康檢查報告,報告顯示近六成的受訪者表示對GDPR不太或并不了解,同時僅有8%的受訪者表示已經(jīng)做了充分的準備,接近75%的人表示僅做了部分準備。那么從國內(nèi)外來看,未來數(shù)據(jù)安全法規(guī)趨勢如何?網(wǎng)絡安全問題的本質(zhì)是什么?企業(yè)如何規(guī)避不合規(guī)數(shù)據(jù)的風險?怎樣提供可切實實施的風險整改計劃?
    On May 25, 2018, the General Data Protection Regulation (“GDPR”) formally came into force, opening a new era of data compliance. A fine of Euro 10-20 million or 2-4% of annual global turnover forces the companies bound by GDPR to pay high attention to data protection compliance. However, enterprises’ response to GDPR seems to be quite inadequate. In 2017, the British government issued FTSE 350 Network Governance Report under the assistance of Big 4 Accounting Firms. The Report shows that nearly 60% of the respondents did not know much about GDPR, only 8% of them said they had made adequate preparations, and nearly 75% of them said they had made some preparations only. What is the future trend of the data security regulations at home and abroad? What is the nature of cybersecurity issues? How to avoid the risks of non-compliant data? How to develop a practical and feasible risk control plan?
    Mr. Chen Chi, a senior partner of EY Forensic & Integrity Services was invited to interpret GDPR, analyze cases and explain the trends.

課程收益 Course Benefits:
1. 了解GDPR、中國網(wǎng)絡安全法及其他相關法律法規(guī)要點
Understand the main points of GDPR, the Cybersecurity Law of the People’s Republic of China and other relevant laws and regulations
2. 了解GDPR及其他相關法律對于企業(yè)所處行業(yè)的影響程度
Understand the impact of GDPR and other relevant laws and regulations on the industry
3. 了解企業(yè)各個層級部門應如何應對外界監(jiān)管規(guī)定
Understand how the departments of enterprises at each level should cope with the regulations
4. 掌握提升企業(yè)數(shù)據(jù)合規(guī)、網(wǎng)絡安全的方式方法
Learn the ways and means to improve enterprise data compliance and cybersecurity
5. 了解危機發(fā)生時應如何進行處理和應對的方法
Understand how to deal with crises
6. 學習先進風險評估框架,并能運用到實際工作中
Learn advanced risk assessment frameworks and apply them to practical work

誰該來參加 Who Should Attend:
Persons in charge of corporate compliance, legal affairs and information security departments; persons in charge of discipline inspection and supervision departments with the functions related to compliance, legal affairs and information security; department heads and general employees engaged in compliance, legal affairs and information security practices; far-sighted persons interested in data compliance and cybersecurity; and activists who want to improve the comprehensive management capabilities of their enterprises.

課程大綱 Course Outline:

GDPR and relevant laws and regulations
1. GDPR概述
GDPR overview
2. 中國網(wǎng)絡安全法概述
Overview of the Cybersecurity Law of the People’s Republic of China
數(shù)據(jù)隱私保護Data privacy protection
網(wǎng)絡安全等級保護Classified protection of cybersecurity
信息跨境傳輸Cross-border information transmission
網(wǎng)絡安全監(jiān)控與應急響應Cybersecurity monitoring and emergency response
3. 全球數(shù)據(jù)保護法律法規(guī)環(huán)境
Global data protection laws and regulations

Data compliance and cybersecurity trends
1. 數(shù)據(jù)安全事件及處罰案件
Data security incidents and punishment cases
2. 企業(yè)應對現(xiàn)狀
Enterprises’ response
3. 從國內(nèi)外大背景看趨勢
Trends from the perspective of domestic and international background

Enterprises’ countermeasures
1. 管理層應對策略
Countermeasures at the management level
2. 業(yè)務層應對策略
Countermeasures at the business level
3. 技術層應對策略
Countermeasures at the technology level

Identification of sensitive information
1. 數(shù)據(jù)生命周期管理
Data lifecycle management
Collection and use of data information
Processing, transmission and sharing of data information
Preservation and destruction of data information
2. 識別個人數(shù)據(jù)、重要數(shù)據(jù)、商業(yè)秘密數(shù)據(jù)
Identification of personal data, important data and trade secrets

Establishment of risk assessment matrix
1. 怎樣確定數(shù)據(jù)安全評估標準
How to establish data security assessment standards
2. 定量化衡量風險等級及對企業(yè)的影響
Quantitatively measure risk levels and risk impact on enterprises
3. 怎樣提供可切實實施的風險整改計劃
How to develop a practical and feasible risk control plan

Establishment of data governance framework
1. 數(shù)據(jù)治理的全過程
Whole process of data governance
2. 應對型數(shù)據(jù)治理及主動型數(shù)據(jù)治理
Passive and active data governance
3. 數(shù)據(jù)管理能力成熟度模型
Data management capability maturity model

Establishment of data compliance system
1. 進行GDPR及網(wǎng)絡安全法適用性評估
Evaluate the applicability of GDPR and cybersecurity laws
2. 劃分數(shù)據(jù)類型及區(qū)別制定合規(guī)策略
Classify data and develop different compliance strategies based on the classification
3. 更新與完善隱私政策
Update and improve privacy policies
4. 建立風險評估、記錄與響應機制
Establish risk assessment, recording and response mechanisms

Establishment of cybersecurity system
1. 網(wǎng)絡安全威脅類型
Types of cybersecurity threats
2. 常見的安全服務機制
Common security service mechanisms
3. 構建網(wǎng)絡安全防護體系政策建議
Policies and suggestions for building a cybersecurity protection system

關于講師 About the Speaker:
    Chen, a forensic technology partner of EY Forensic & Integrity Services, specializes in proactive compliance monitoring and management systems, trade compliance, data compliance, information and privacy protection, antitrust analytics, predictive risk analytics and eDiscovery, all of which require in-depth analysis of large and disparate sets of structured and non-structured financial, operational and transactional data. He leads his team to help clients identify high-risk transactions or behaviors in a timely, efficient and effective manner by leveraging advanced data analytics techniques including but not limited to data visualization, statistical modeling and text mining. He has more than 16 years of combined advisory and audit experience in the US, Australia and China. Besides, he has served many Fortune 500 and multinational companies in a variety of industry sectors including life sciences, manufacturing, consumer goods, industrial products, construction, technology, financial services, energy and telecommunications.

