CAN/DGSI 100-8, Data Governance - Part 8: Framework for Geo-Residency and Sovereignty
Public Review
This Standard specifies the minimum requirements for Organizations to protect data assets in their custody from jurisdictional risks, while taking advantage of the global technology ecosystem.
The Standard is not intended to prescribe how an Organization should implement specific security controls. Instead, the standard will guide Organizations using jurisdictional and technology-agnostic approaches that can be adapted to address specific business requirements.
Considerations are given to:
- Identification and categorization of data assets;
- Development of an appropriate threat model;
- Identification of potential risks, including from laws in foreign jurisdictions;
- Options to mitigate associated risks; and
- Adherence to data sovereignty due diligence and transfer requirements under applicable law and regulations
DATE POSTED: November 28, 2024
DEADLINE FOR COMMENTS: January 31, 2025
Comments
Close