PIMS
Skill packages tagged with “PIMS”
ISO 27701 PIMS Extension Author
Guided elaboration of PIMS documentation as an extension to ISMS: PII processing inventory, privacy objectives, processing purposes and legal basis, controller/processor annex controls, and privacy policy drafting aligned to Clause 6 controller obligations.
ISO 27701 PIMS Internal Audit
Plan and document a PIMS-specific internal audit. Covers audit planning, execution checklist, findings, nonconformities, and corrective actions focused on privacy controls and PII processing compliance.
ISO 27701 PIMS Scope Definition
Define the Privacy Information Management System (PIMS) scope per ISO/IEC 27701:2019+AMD1:2024 Clauses 5.2.1–5.2.4 — organization role as PII controller, processor, or both (5.2.1); interested parties and their privacy needs (5.2.2); PII principal categories, applicable regulations (GDPR, LGPD, CCPA/CPRA, PIPEDA, PDPA, APPI, POPIA, PIPL), PIMS boundaries, cross-border transfers, privacy objectives, and exclusions (5.2.3); and ISMS linkage (5.2.4). Foundation skill for all ISO 27701 documentation.
ISO 27701 Security Controls Overlay
Create the privacy overlay for the 93 ISO 27002:2022 security controls. For each control in the SoA, document what additional privacy-specific implementation is needed per ISO 27701 Clause 6. Covers all four control themes (Organizational, People, Physical, Technological) with privacy augmentation guidance and evidence mapping.