Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)
Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249) 5.3(a): 5.3(a) Network and TLS inspection tuned to prevent permanent logging of employee activity

Monitoring every online activity with inspection tools such as TLS interception, next-generation firewalls or unified threat management is disproportionate and intrudes on the confidentiality of communications, so less invasive means should be explored first. Where some interception is strictly necessary, the tool should be set up to avoid permanent logging, for instance by blocking suspicious traffic and sending the user on to a portal where they can ask for a review, and if general logging is strictly needed, by storing logs only when an incident is flagged and keeping as little as possible.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Sections 5.3 and 5.4: Monitoring ICT use at and outside the workplace – Article 29 Working Party Opinion 2/2017 on Data Processing at Work (WP249)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.