No owner, or no list of who can view
A camera with no owner has nobody to answer for it, and footage with no list of viewers has no access rule. With ISO/IEC 27001 in scope: an owner for every asset (A.5.9), access control rules (A.5.15), physical security monitoring (A.7.4) and the privacy requirements of law (A.5.34); GDPR and UK GDPR Art. 32 ask for security, including that people with access act only on instructions; APP 11 asks for reasonable security steps.
- When it is raised
- Raised on a camera whose owner column or who can view column is blank or none. A list with neither column gets one note for the whole register instead.
- The question
- Who owns this camera and its footage, and who may view it?
- For
- your privacy lead
- The column that settles it
- owner
- On the row
- a numbered delta and the words "no owner" in small capitals; an outlined delta where it rests on a blank column
Clauses by regime
ISO/IEC 27001 (information security management)
ISO/IEC 27001 A.5.9Inventory of information and other associated assetsInventory of information and other associated assets. The organization is to build and keep current an inventory of its information and other associated assets, with their owners recorded. Purpose (stated in ISO/IEC 27002:2022): identifies the organization's information and associated assets so they can be protected and properly owned. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.9.
ISO/IEC 27001 A.5.15Access controlAccess control. Rules that govern both physical entry and logical access to information and associated assets are to be set and applied on the basis of business and information security requirements. Purpose (stated in ISO/IEC 27002:2022): ensures access to information and associated assets is authorized and unauthorized access is prevented. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.15.
ISO/IEC 27001 A.7.4Physical security monitoringPhysical security monitoring. Premises are to be watched continuously for unauthorized physical entry. Purpose (stated in ISO/IEC 27002:2022): detects and deters unauthorized physical access. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 7.4.
ISO/IEC 27001 A.5.34Privacy and protection of personal identifiable information (PII)Privacy and protection of personal identifiable information (PII). The organization is to identify, and then satisfy, the requirements for preserving privacy and protecting personally identifiable information that arise from applicable laws, regulations and contracts. Purpose (stated in ISO/IEC 27002:2022): ensures compliance with requirements on the information security aspects of protecting PII. As an Annex A reference control, it is compared with the controls determined in risk treatment (6.1.3 c) and recorded in the Statement of Applicability as included or excluded, with the justification and implementation status (6.1.3 d); implementation guidance is ISO/IEC 27002:2022 5.34.
GDPR (the EU General Data Protection Regulation)
GDPR Art. 32Security of processingSecurity of processing. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons. Those measures include, as appropriate, the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services, the ability to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. Assess the appropriate level of security against the risks presented by the processing, in particular accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data transmitted, stored or otherwise processed. Take steps to ensure that any person acting under the controller's or processor's authority who has access to personal data processes it only on instructions.
UK GDPR
UK GDPR Art. 32Security of processingArticle 32 Security of processing. Controllers and processors must implement technical and organisational measures ensuring security appropriate to the risk, taking into account the state of the art, costs, the nature and purposes of processing and the risks, including as appropriate pseudonymisation and encryption, the ongoing confidentiality, integrity, availability and resilience of systems and services, the ability to restore availability and access in a timely way after an incident, and a process for regularly testing, assessing and evaluating the measures. The assessment must weigh the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Codes or certification may help demonstrate compliance, and anyone acting under the controller's or processor's authority must process data only on instructions.
Australian Privacy Principles (APPs)
APP APP 11Security of personal informationAPP 11 - Security of personal information. Take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and destroy or de-identify it when no longer needed.