Unified Communications tools and platforms have become a mainstay of the modern technology stack. Offering companies a way to synchronise internal conversations, align employees, and drive productivity, these tools are now a must-have for virtually any organisation. However, though it’s impossible to ignore the benefits of the right UC solution, it’s worth noting that today’s digital tools do come with some risks. While many UC platform vendors are taking steps to assist customers with processes for reducing security risks and compliance threats, business leaders still need to implement their own strategies for data protection compliance. After all, in the communications landscape, businesses are producing huge amounts of data on a daily basis. This information needs to be protected, not only to ensure companies can remain compliant with regulations, but also to defend brands against damage to their reputations. “In many initial interactions with clients, we find a common belief that ISO 27001 covers all security and privacy compliance needs. However, ISO 27001 is no longer the golden standard it once was, and many cloud service operators and managed service providers need heightened requirements to comply with regulatory regimes and contracts. Pairing ISO 27001 with ISO 27017, 27018 and 27701 is becoming the new baseline for many companies in today's modern era of data protection. – Dr. Scott Allendevaux, Practice Lead: Cyberlaw and Privacy Law at Allendevaux & Company. So, how do organisations achieve data protection compliance in UC?
Step 1: Explore Compliance Frameworks
Discovery is a crucial first step in developing an effective strategy for data protection in the UC space. Any reputable data protection company will always work with a business to examine their threat vectors, explore potential risks, and develop compliance requirements. However, businesses can also start the discovery process on their own. A good way to begin is by looking at the current compliance space, and which regulations the business might be subject to. For instance, the most common framework business leaders need to be aware of in regard to data protection today, is GDPR. While it’s easy to assume this framework only applies to UK and European-based businesses, it’s worth remembering it’s also relevant to any company working with EU and UK companies. GDPR has transformed the way virtually every business handles data, influencing everything from personal data management to data portability and privacy. Alongside GDPR, certain companies may also be subject to various other regulations, such as the California Consumer Privacy Rights Act, or the CDPA (Consumer Data Protection Act). Understanding the rules and restrictions of each regulatory framework will help businesses develop the right strategy for success.
Step 2: Identify Potential Risks
After learning more about the compliance guidelines they’re going to be subject to, business leaders investing in UC protection should also begin to evaluate the possible risks in their existing landscape. A comprehensive audit of the UC ecosystem can provide insights into possible issues businesses might encounter with maintaining and protecting data. For instance, in the hybrid workplace, companies may need to be aware of how different devices and connection points may impact the security of data. Companies may need to look at how cloud technologies, such as UCaaS influence the way they manage information. Some security and compliance companies can even assist business in performing full ISO 27005 risk assessments, evaluating how they manage, share, and store information. A comprehensive risk assessment can lead the way to the development of a full risk management plan, where businesses can identify unmanaged risks, look for ways to mitigate issues like data loss, and develop policies for how information is managed in the Unified Communications space.
Step 3: Create Internal Controls and Documents
As mentioned above, implementing the right UC platform, complete with access to zero-trust architecture, access and privacy controls, and encryption can help to minimise the risks in a UC landscape. However, it’s also important to have the right internal control strategies and policies in place to reduce threats. After all, 82% of data breaches are caused by human error. Based on a comprehensive threat assessment, companies can implement standard operating procedures and policies into the workplace that help to protect both customers, and employees. Organisations can define which Information Security Management Systems (ISMS) need to be implemented based on the structure and functionality of their UC service. They can manage which documents need to be encrypted, which tools employees should use to mitigate risks, and even what should happen when an employee needs to report an issue. With the right help, companies can even create policies which ensure their team members adhere to the best practices of guidelines like ISO/IEC 27002. Plus, it’s possible to develop guidelines for disaster recovery management, and incident management.




