Following are the measures that have been described in Sean (2004):
a. The type of data and the particular treatment is performed thereof.
b. The size and structure of information systems.
c. The state of technology.
The safety requirement regulating law developed by this Regulation, it is an obligation of means, i.e. forces us to take the necessary measures to protect data, but recognizes that no company can guarantee 100 %, with the adoption of such measures will not occur or exist incidents. So long as the File Manager can establish that was established and followed safety measures required in each case, avoid a possible sanction by the US Agency for Data Protection. Their behavior will always be assessed based on the circumstances and requirements of each treatment, weighing upon him the burden of proving that it took all necessary measures to avoid or reduce harm.
Uses of Measures
Technical and organizational measures imposed by Regulation should be applied to:
The computer files, defined as any organized set of personal data, whatever its form or method of creation, storage, organization and access.
Treatment centers, defined as the authorized places where the computers, and servers that store information.
The premises, defined as those places where they are physically located and staff teams that processes data.
Equipment: all hardware material available to treat and store personal data electronically.
Systems and software that deal with personal data.
People who access the data: workforce, according to their functions and obligations involved in any stage of the processing of data (collection, recording, storage, processing, modification, blocking, erasure, consultation, etc
Level of performance by the system
The level of performance is determined by the technical and organizational measures to ensure the confidentiality, integrity and availability of information containing personal data in order to preserve them ...