
Dez Blanchfield50








































Q2: What are the biggest gaps for firms in preparing for #GDPR? Is there an opportunity here for new #technology? @dez_blanchfield @evankirstel @Kevin_Jackson @CAMainframe
http://www.via-cc.at...
http://www.via-cc.at...

Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
A2. Data classification. It only gets harder from here if you donโt classify your data based on contractual requirements, data sovereignty, PII, sensitivity and regulatory requirements.

Evan Kirstel
Each organisation works differently. In some, enterprise architects may be directly responsible for ensuring #GDPR #compliance. In others, architects may not have even been invited to the party. So the first thing for architects to do is buddy up!

Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
A2. You also need classification in order to effectively use SIEM. Check out https://www.ca.com/u...

Evan Kirstel
You must prioritize which #GDPR requirements to tackle first!

Craig Mullins
I agree with @kevin_jackson - how many orgs even know what all their data is (lack of metadata) to know what must be in compliance with GDPR. That is a big task to tackle!

Christopher Penn #THINK2018 Speaker
Data identification and unification. Virtualization of data to put everything in a seemingly local interface will let data architects find and identify data faster.

Jeff Cherrington
@Kevin_Jackson Kevin, what constraints are mainframe data centers facing when attempting to classify the unclassified accumulation of data from the decades the mainframe has been in use?

Dez Blanchfield
- so many companies are still seeming to struggle with just developing a basic Vocabulary and Language to even discuss the issues - I think for many just starting the conversation is a major 1st step ;-)

Dez Blanchfield
- and of course there's the fact that we now only have 55 left to actually get compliant ;-)

Chip Mason
@craigmullins Identifying and classifying data is the best first step to GDPR compliance. You need to know where your risk might be.

Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
@craigmullins managing the #Metadata is harder than managing the data!

Jeff Cherrington
Days until GDPR goes into effect https://howmanydayst...

Tripp Braden
Its about not having the right people focused on the critical activities, priorities and budget for the #GDPR challenge

Craig Mullins
@Kevin_Jackson If only people had adopted and actually used Metadata Repositories like CA Repository!

Christopher Penn #THINK2018 Speaker
from a marketing perspective, pivoting from PII to behavioral data is also a major step needed. Reduce dependence on collected data from customer records.

Marcel Mitran
Data classification and life-cycles are incredibly complex and living beast. In general you need to trade-off agility and innovation for control and management. Less than ideal!

Jeff Cherrington
Classifying data is critical for privacy, articles 25 & 32, and for right to access, article 15, right to be forgotten, article 17, and right to data portability, article 20

Ravi Patil
A2. Hoping firms do not wait for major fines to be levied before taking action on #GDPR.

Chip Mason
And don't forget, GDPR is not limited to EU companies. Many US companies have signed Commerce Dept Privacy which puts them under the regulation

Shira Rubinoff
basic overview - for those unsure...\ : According to GDPR orgs must: 1) only process data for authorized purposes 2) ensure data accuracy and integrity 3) minimize users identity exposure 4) implement data security measures

Tripp Braden
The larger elephant in the room is who will be held responsible for missing deadline, the CEO, Board or CIO?. Will their stock price take a hit? #GDPR

Tony Flath ๐ Podcast
Craig @craigmullins on the metadata point do you see converged data being more efficient and what role does #blockchain play here? @kevin_jackson #LetsTalkAboutData

Christopher Penn #THINK2018 Speaker
@TrippBraden That's a huge elephant. Everyone with P&L responsibility has a stake in #GDPR compliance.

Craig Mullins
@TmanSpeaks There may be more metadata available for converged data

Craig Mullins
@TmanSpeaks Not really sure how blockchain could help us to identify and classify all of our existing data

Shira Rubinoff
stats indicate that 65% of organizations will fail to meet GDPR deadlines - @TrippBraden who is responsible? I believe that the responsibility will vary per organization - but the finger will be pointed across the C- channels

Bud Walder
maybe an opportunity for a new GDPR insurance policy!

Shira Rubinoff
@kwwalder will happen - similarly to having a Cyber insurancy policy

Tony Flath ๐ Podcast
@craigmullins I was just more future thinking and effective data management with global #metadata but I'd leverage you and Dez on that front! #LetsTalkAboutData

Priya Dewan Doty
@Kevin_Jackson this is one place to start http://cainc.to/cNpN...

Evan Kirstel
@TrippBraden planning planning planning

Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
@TmanSpeaks #Blockchain can help a lot!

Chip Mason
@TmanSpeaks AMZ has a great solution, but for mainframe, no need to move the data. Keep it in place and identify risk of PII with CA DCD https://www.ca.com/u...

Craig Mullins
@Kevin_Jackson Interested to learn how Kevin?

Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
@craigmullins #Blockchain can be used to track data provenance.

Shira Rubinoff
Biggest gaps are budgets - as well as time factors. There are many areas the companies have to tighten up on - in order to get there budgets have to be allocated first

Craig Mullins
@Kevin_Jackson Certainly looking-forward but not really helpful for identifying and categorizing existing data - perhaps I was focusing my thoughts too narrrowly

Chip Mason
@TrippBraden Consensus seems to be that as long as you can prove 'significant effort' there will be leniency on compliance. But if you have a breach: the hammer will fall!

RADAR
Meeting the 72-hr notification timeframe will be a real challenge for US orgs, as most US laws allow for 30-45 days or even more vaguely "most expeditious time possible." 72 hrs will feel like a sprint in comparison! Automation can streamline the process.

Tripp Braden
@evankirstel Maybe a ready, fire, aim strategy might be more appropriate give the current status of their planning

Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
@jcherrington The challenge is in enforcing enterprise IT governance.