By: Nana
Appiah Acquaye
The Nigeria Data Protection
Commission (NDPC) has organised a capacity-building programme for its staff as
part of efforts to strengthen information security and privacy management
practices in line with internationally recognised standards.
The training focused on the
Commission’s journey towards certification for an Information Security
Management System (ISMS) under ISO/IEC 27001 and a Privacy Information
Management System (PIMS) under ISO/IEC 27701.
The programme forms part of
the NDPC’s Strategic Roadmap and Action Plan on human capital development and
is aimed at enhancing the Commission’s institutional capacity to protect
information assets, strengthen organisational resilience and improve regulatory
effectiveness.
Participants were introduced
to key requirements of ISO/IEC 27001 and ISO/IEC 27701, including Clauses 4 to
10, information security risk assessment methodologies and the application of
Annex A security controls covering organisational, people, physical and
technological areas.
The training also examined
the Commission’s policy framework and the practical requirements involved in
establishing information security and privacy management systems capable of
meeting international standards.
According to the Commission,
the initiative is part of its broader effort to embed global best practices in
information security and privacy governance across its operations as it
progresses towards internationally recognised certification.
The NDPC said strengthening
its internal systems would enhance institutional accountability and public
confidence while supporting the development of a secure and privacy-conscious
digital ecosystem in Nigeria.
The initiative also forms
part of the Commission’s wider contribution to Nigeria’s digital transformation
agenda, where robust information security and privacy safeguards are
increasingly important to the growth of digital services.
The training was facilitated
by Oluwagbenga Bamgbose, Chief Consultant at GUUT Technologies Limited.