Ethical Hacking and the New European Data Protection Regulation

Ethical Hacking to comply with the provisions of EU Regulation 2016/679

miércoles, 16 de octubre de 2019 • 2 min read • Q2BSTUDIO Team

ethical-hacking-penetration-test

With the new EU Regulation 2016/679, pentesting or Ethical Hacking are implicit in the mandatory nature of data security.

It is in this risk adaptation where there is a connection between Ethical Hacking and the new European Data Protection Regulation, as established in Article 32, paragraph 2:

"When assessing the adequacy of the security level, PARTICULAR ACCOUNT SHALL BE TAKEN OF THE RISKS presented by data processing, in particular as a result of the accidental or unlawful destruction, loss or alteration of personal data transmitted, stored or otherwise processed, or the unauthorized communication or access to such data."

And what is Ethical Hacking if not the offensive security measures that analyze risks to prevent unlawful access to data or unauthorized communication or access to it?

Thus, and by legal imperative, before carrying out a consultancy and/or adaptation of an activity to personal data protection regulations, a prior computer security audit is essential, which can, and in my opinion should, include Pentesting and Ethical Hacking sessions to identify the specific risks affecting each data processing due to possible alteration or unlawful or unauthorized access to it.

After what we have seen, it is logical that the advisor or consultant must seek advice from the IT auditor on the best and most appropriate personalized security measures tailored to that specific computer system.

The aforementioned Article 32 only proposes pseudonymization and encryption of personal data as security measures and mentions the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, and the ability to restore the availability and access to data in a timely manner in the event of a physical or technical incident, as well as a regular process of testing, assessing, and evaluating the effectiveness of technical and organizational measures to ensure the security of processing.

Since the security policy of each entity is now designed for each data controller according to the real risks that such processing entails, the legal scope must rely on the technical scope, making it necessary for IT professionals to work together and understand the legal experts who design the consultancy or adaptation to data protection regulations.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.