Validating the loss of availability
Once the risk is documented, the legal officer must validate whether the current status can be accepted in accordance with GDPR.
Existing validations are reviewed by clicking ‘View validation log’ and ‘View more’.
New validations are reviewed by clicking ‘+ Add validation’.
From each validation:
- Select ‘Reject’ if the risk cannot be accepted, or there are uncertainties that need further investigation.
- Select ‘Accept’ if there are currently no actions to be taken regarding the risk.
- Include any relevant comments, such as possible problems or uncertainties regarding the risk, which controls are implemented, etc.