Privacy Assessments
The US privacy sector is a legislative patchwork, consisting of state-level privacy laws, sector-specific regulations, and evolving federal standards.
Considering the massive amount of personal information being created, transferred and stored today as well as the economic, political and social concerns over data flows, adherence to privacy laws and standards has proven to be a challenging imperative of doing business and maintaining a company’s reputation.
Whether driven by statutes or common law, accounting for these business and legal obligations can be onerous from state to state.
Schellman’s deep expertise provides a thorough view of an organization’s data protection and privacy posture and helps to consolidate efforts to address a changing landscape.
We can assist with most US privacy assessments including but not limited to:
Schellman performs each assessment with your end goals and preparation for future key compliance initiatives in mind. Effective communication and timely coordination of project activities are central to our methodology.
The planning phase occurs at least two months in advance of fieldwork in accordance with the timing outlined in the job arrangement letter (JAL) or statement of work (SOW) executed with the client. Planning includes the completion of an intake questionnaire, confirming timing of interviews with key points of contact, and deployment of and evidence gathering for the information request list provided via AuditSource 2.0. Schellman will be available to the client to answer any questions associated with the assessment to ensure both parties are aligned on scope and expectations.
Schellman will hold a kickoff meeting to start fieldwork. Fieldwork consists of various testing procedures to evidence the requirements are met. The testing procedures may include one of the following:
Schellman has a no surprises policy and regular contact with the client during fieldwork, allowing clients to be apprised at all times of conformance status.
Schellman's assessment is focused on creating a deliverable that is clear, concise, and accurate. The draft report is provided within 2-3 weeks of the last day of fieldwork. The final deliverable is available within 5 business days of the client approving the draft version.
Chris is a Director and Privacy Technical Lead at Schellman based out of Atlanta, GA. With more than five years of experience in information assurance, Chris has a concentration in privacy-related engagements.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: