HECVAT Category

Privacy Change Management

Privacy Change Management covers controls and questions related to that domain. It outlines expectations institutions typically require from vendors. The category helps assess risk posture and operational maturity. It provides structure for consistent evaluation during security reviews.

Assessment Questions

HECVAT Privacy — Privacy Change Management: assessment questions and what each one covers
IDQuestionWhat it covers
PCHG-01Does your change management process include privacy review and approval?Privacy in change management is the focus: whether your change process builds in a dedicated step to review and approve changes from a privacy standpoint.
PCHG-02Do you have policy and procedure, currently implemented, guiding how privacy risks are mitigated until they can be resolved?Interim privacy risk handling is the subject, asking whether you have implemented policy and procedure for mitigating privacy risks until they can be fully resolved. Privacy risks are potential threats to personal data that could lead to unauthorized access, disclosure, alteration, or destruction of that data.

ResponseHub is the product I wish I had when I was a CTO

Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.

As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!

I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

Signature
Neil Cameron
Founder, ResponseHub
Neil Cameron