Browse Definitions :
Definition

BS 10012:2009 (British Standard 10012:2009)

British Standard 10012:2009 (BS 10012:2009) is a standard enacted by the U.K. government in order to further the privacy of sensitive personal information held by British corporations.

BS 10012:2009 came into effect May 31, 2009, and mandates the implementation of a personal information management system (PIMS) within corporate security programs. Two of the most salient points of the standard are that corporations should commit not to take or use customer data unless absolutely necessary, and to inform customers exactly how and under what circumstances their information will be used.

The standard provides guidelines for how to create a PIMS as a framework for enacting data privacy and protection, not strict technical regulations. In this way, the standard functions more like COBIT than the Payment Card Industry Data Security Standard (PCI DSS).

The standard is intended to help companies comply with the Data Protection Act 1998 by giving guidelines for areas such as employee security awareness training, risk assessments, data retention and disposal and others.

This was last updated in October 2010
SearchCompliance
  • OPSEC (operations security)

    OPSEC (operations security) is a security and risk management process and strategy that classifies information, then determines ...

  • smart contract

    A smart contract is a decentralized application that executes business logic in response to events.

  • compliance risk

    Compliance risk is an organization's potential exposure to legal penalties, financial forfeiture and material loss, resulting ...

SearchSecurity
  • buffer overflow

    A buffer overflow occurs when a program or process attempts to write more data to a fixed-length block of memory, or buffer, than...

  • biometric verification

    Biometric verification is any means by which a person can be uniquely identified by evaluating one or more distinguishing ...

  • password

    A password is a string of characters used to verify the identity of a user during the authentication process.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • change control

    Change control is a systematic approach to managing all changes made to a product or system.

  • disaster recovery (DR)

    Disaster recovery (DR) is an organization's ability to respond to and recover from an event that affects business operations.

SearchStorage
  • What is RAID 6?

    RAID 6, also known as double-parity RAID, uses two parity stripes on each disk. It allows for two disk failures within the RAID ...

  • VRAM (video RAM)

    VRAM (video RAM) refers to any type of random access memory (RAM) specifically used to store image data for a computer display.

  • PCIe SSD (PCIe solid-state drive)

    A PCIe SSD (PCIe solid-state drive) is a high-speed expansion card that attaches a computer to its peripherals.

Close