Marriot’s’ 500 Million Data Breach Scandal

Jan 22 • 4 min read

A Politically Inclined Attack Or Just A ‘Simple’ Lack Of Security Awareness?

Whatever the case, the cyber-attack that hit Marriott was huge. This was the joint second largest data breach to take place, after Yahoo in 2013 and Equifax in 2017. A cyber attacker stole personal information including names, emails, addresses, passport numbers, and credit card information of Marriot’s guests. All this lasted for four years! The data breach, which affected approximately 500 million guests (yes, million), was made public in late November 2018, two months after it was discovered by the hospitality giant.
The amount of data that was stolen from the Starwood Hotels (a company purchased by Marriott in 2016) system of reservations was massive. And what’s most surprising and shocking is that the first breach went undetected for four years, and thus the Starwood Hotels was still purchased and no attention was payed to the breach issue.
By purchasing Starwood in 2016, Marriott became the largest hospitality company in the entire world, but it also suffered some side effects of this expansion since cybercriminals had penetrated the reservation systems of Starwood back in 2014 – undetected! According to Bloomberg Intelligence, “the company could face up to $1 billion in regulatory fines and litigation costs”.
Since the news originally came out, news came out that even the Marriott’s own security team was hit by an attack in June 2017. Clearly, something does not add up.
Another ‘not-so-controversial’ side to this story is that the data breach attack on Marriott hotel was politically influenced. The New York Times reported that the hackers were suspected of working on behalf of the Chinese Ministry of State Security. “The cyber attack on the Marriott hotel chain that collected personal details of roughly 500 million guests was part of a Chinese intelligence-gathering effort that also hacked health insurers and the security clearance files of millions more Americans, according to two people briefed on the investigation.”, the article further added. Surely, this side of the story will take a while until it unveils the whole picture.
In addition, in an emailed statement, Marriott spokeswoman Connie Kim stated “Our primary objectives in this investigation are figuring out what occurred and how we can best help our guests,” She further added “We have no information about the cause of this incident, and we have not speculated about the identity of the attacker.”

The Dearth Of Security Awareness

Taking into consideration how the story unfolded, anyone can blame and criticize Marriott and even Starwood for what seems like a line of big errors. Yet, the reality is that nowadays, it could occur to any business or company. Cyber Security preventive measures have become a lot more sophisticated than they used to be, but so have the cybercriminals. Basically, it’s a chicken and egg scenario. We are aware of the fact that legitimate companies are kept in ‘chains’ by laws – criminals are not. Unfortunately, this puts criminals at a highly favorable position to innovate and stay ahead of the good guys. The security teams, in this case, are playing a constant and dangerous game of catch-up which at some point will be catastrophic, as it happened with Marriott.
The main current issue in this aspect is the fact that security is still not a top priority for the top management of organizations. Despite having prominent organizations constantly being attacked, – such as it occurred in 2018 with Ticketmaster, Under Armour, British Airways and more, and a “when not if”, caution being typified by the security industry for many years now – many businesses have not yet realized the vital importance of security.
Simply put, the fact that a security review may have not been part of the Starwood purchase by Marriott, – or if it was, it was not conducted properly – is further evidence that security has not been given the right importance during the last few years.

Profit, People & Planet With ISO 20121

Jan 22 • 4 min read

The Three Pillars of Sustainability

The concept of the “triple bottom line” was firstly introduced in 1994 by John Elkington, with the idea of organizations preparing three different bottom lines in order to measure their financial, social and environmental performance. The first bottom line stands for the traditional measure of corporate profit, specifically for the profit and loss account. The second line puts to light how socially responsible has the company been, and how much should it have been throughout its operational history (also referred as “people’s account”). Last but not least, the final bottom line, the company’s “planet” account, materializes the environmental measurement of a specific company. In this light, it is considered that only a company that possesses the “3 P’s” is perceived as responsible, by taking into account the full costs of the impacts of doing business.
Essentially, the TBL tries to convey the “what you measure is what you get” message, because what you measure is what you are most likely to pay attention to. Consequently, when organizations measure their strategic operations, including how they’re affecting the social and environmental spheres, they are socially, as well as environmentally liable organizations.
The ISO 20121:2012 standard reflects on the TBL methodology by focusing on helping organizations of all sizes in the events and hospitality industry – by integrating sustainability into their every-day operational practices. It is also worth mentioning that this standard was launched the same year when the London Olympics were held (2012) because the Olympics Committee used the standard to help organize the most sustainable Olympic Games until that point in time.
In line with other ISO standards, ISO 20121:2012 standard uses the Plan-Do-Check-Act (PDCA) method as well.
The standard has been designed to be flexible in order to be applicable to all types of organizations including but not limited to:
  • Large Events, show grounds, race tracks
  • Hotels, Holiday Parks and leisure complexes
  • Music festivals, marathons and harbor festivals
  • Trade fairs & large conferences
The ISO 20121:2012 is generally projected for internal use, as a tool for ameliorating the sustainability operations, and it utilizes the ISO standard framework that allows it to be in harmony with the existing management systems such as ISO 14001 (Environmental Management), or ISO 9001 (Quality Management). The significant benefits of implementing this standard lay in the fact that it uses a systematic and detailed approach whilst identifying and controlling the impacts that an event may have.

What are the benefits of ISO 20121 standard?

  • Increased profit – The ISO 20121 standard helps organizations find out when and where their resources are being used, as well as how the waste is being generated. This opens the doors for a step-wise analysis of the data and increases opportunities for reduction, as well as leads to cost savings.
  • Effectively managed risk – ISO 20121 helps organizations minimize the impact of their activities and any obstacle on local resources that could result in objections from regulators and planners.
  • Increased sales – By implementing ISO 20121 guides, organizations invest towards increasing brand awareness and improve their image with regard to social responsibility. This would lead to a potentially large public and private sector client attraction.
  • Improved relationships with third parties – ISO 20121 assures regulators, investors, and other interested parties that the organization has its impacts under control and that it can foresee a conflict with the local communities.
In conclusion, ISO 20121 is a standard that can be applied to any event, be that small or large. It can also be implemented internally by organizations to run their events, or by professional event organizers. What makes ISO 20121 special is the ‘The Bottom Line’ (TBL) comprehensive approach to social, environmental and economic aspects, which fundamentally accentuates the responsibility that organizations should have in order to operate.
It’s 2018, and the publicity that ISO 20121 is generating with events certifying is becoming massive. It is very likely that in the near future, all event organizers will require some proof of reliable sustainability management regime. For most organizations, that reliability is achieved with ISO 20121.

12 Reasons For Risk Management Failure

Jan 22 • 6 min read

Risk management has gained an increased attention and interest in recent years, both from industry professionals and academics. The main focus of thorough risk management is the continuous identification and treatment of the potential risks. Its objective is to add maximum continual value to all the activities within the organization. In addition, in developed and emergent countries, capital markets have become more significant and as a result, nonfinancial corporations and banks recognized that the number, type, and extent of their threat landscape and inherent risk have increased significantly. Finally, a wave of unpredictable financial payment related enhancements can be considered both a source of risk and a method to mitigate.

Risk management has also gained attention considering the ongoing and widely publicized failures having roots in its erroneous implementation. Risk Management failures prohibit organizations from meeting their goals, thus determining repetitive and sometimes of exponential magnitude, business and project failures. Although the risk management approach varies among firms, enterprise risks management is an organizational pivot point in achieving corporate goals. Risk and performance are inevitably connected. By establishing a reliable and controlled process for managing risks, organizations can develop the predictability of their outcome. Enterprise risk management enables enhanced decision making, consequently enabling significant cost savings. Additionally, if properly implemented, Risk Management connects risks across various levels in the organization and leveraging other processes such as Program Management enables threat to opportunity conversion.
While considering the valuable role of risk management, it is also essential to understand the many circumstances in which risk management failures may occur.
Enterprise Risk Management can adjust with the business hypothesis and intensively help in overcoming potential business failures. In the Risk management failures and challenges literature, Matei et al. (2012) emphasize that organizations fail because of unexpected losses created by three main factors:
  1. Insufficient capital
  2. Model errors
  3. Risk ignorance

Consequently, management system and risk mitigation may be unsuccessful for more delicate and indirect reasons. At this point, there are three other well-known reasons why risk management fails:

  1. Agency risk.
  2. Shift or changes threat landscape and inherently in the form of risk.
  3. Incremental failure.
Agency risk refers to the risk that a manager or employee, unintentionally or decisively, does not succeed to pursue procedures intended to manage and moderate risks. Next, there is often an affinity for risk to shift or change form. Although an organization may moderate its risk by acquiring insurance, these proceedings do not decrease systematic risk in the economy. Furthermore, there is a tendency for risk management process to fail incrementally across a long period of time. The incremental failure is frequently caused by an extensive incubator duration coming from an evenly degradation of the risk management processes, which gather over a long period of time.
Once risks are identified and quantified, they must be inferred at the organizational upper management level. Inability to properly communicate risks to the top management may cause overall risk management failure. These failures are an indicator of unnecessary risk acceptance and or exposure In the Risk management failure literature, Stulz (2008) showed that failures on risk management can be divided into six classes:
  1. Mismeasurement of known risks
  2. Failure to take risks into account
  3. Failure in communicating the risks to top management
  4. Failure in monitoring risks
  5. Failure in managing risks
  6. Failure to use appropriate risk metrics or measurement system
Risk management failure can be caused by the use of improper risk metrics which induces inaccurate measurements. A practical example is weather forecasting. The most common risk metrics in modern risk management is “Value at Risk” (VaR). Despite the fact that VaR has been proven to be quintessential risk measure, meaningfulness is directly dependent on the quality of the associated answer and inherent question.
Taking into account factors which may be accountable for risk management failure it is consequently appropriate to affirm that operators and operational failure are the two main groups in which risk management failures may fall into.

How To Avoid Or Overcome These Failures?

As discussed above, risk management failures can cause consequences for the organization in both time and cost. Therefore, understanding the strategy of how the organization is making profits and the risks inherent in the business model is essential in order to avoid such failures. Subsequently, top management must recognize empower and manage positions of trust; the employees whose activities can subject the organization to considerable or significant risk events must be carefully selected, trained and continuously evaluated. Establishing responsibility for outcomes and building a procedure for timely escalation in addition to building a common risk language, shared definitions, a common culture of risk awareness and comprehensible procedures for measuring, monitoring, communicating and dealing with risks are some of the main things an organization should consider when targeting a mature Risk Management approach.
Communication is another key process within any organization. Communicate regularly on risks that are more complex to measure and for which results cannot be forecasted with minimal confidence. Available, defined and detailed risk appetite is vital when defining unacceptable risk exposures.
Taking into consideration risk management failures, organizations should consistently manage risks by identifying, assessing, evaluating, prioritizing and monitoring them, continuously looking for opportunities to improve their risk stance. Concrete plans to support these processes should be enforced top-down.
These plans should include, balancing:
a) Risk and benefit
b) Risk and cost.
With all above in place, a useful and proven scheme for effectively managing many risks may be applied to streamline Risk Management and align it to best practices. Such a solution involves adopting an internationally recognized standard such as ISO 31000, which is built on the most relevant best-practice scenarios from organizations worldwide and it is general enough to reduce or eliminate bias. ISO 31000 explains the mechanism of risk management implementation. It provides a framework for implementing a risk management suite, rather than merely a framework for supporting the risk management process. Moreover, with due cognizance of its own internal and external contexts, an organization must recognize the applicable and relevant laws and should put into practice a system of controls to attain compliance. Additionally, ISO 31000 distinguishes the significance of feedback by means of two mechanisms: communicating and consulting and the monitoring and reviewing of performance. Communicating and consulting ensures the engagement of relevant internal and external stakeholders while monitoring and reviewing guarantee that the organization observes risk performance, thereby gaining knowledge of experience and practices.
PECB is a certification body for persons, management systems, and products on a wide range of international standards. As a global provider of training, examination, audit, and certification services, PECB offers its expertise on multiple fields, including ISO 31000 courses.

A Management System For Educational Organizations

Jan 22 • 3 min read

The International Standardization Organization – ISO – being one of the oldest and most experienced in the field of industry standardization, ranging from quality management to food safety, has proven to be a global benchmark of standardization which impacts businesses, organizations, policy-makers, and various regulations around the globe.

One of its latest published standards is ISO 21001 – Management Systems for Educational Organizations (EOMS). This standard focuses on educational organizations and their respective services and products. Although its primary aim is to enhance learners and other beneficiaries’ satisfaction, its principles clearly outline that being more socially responsible and offering educational services that are accessible and equitable are the core components of ISO 21001 as well.

ISO 21001 Content Layout

In terms of the content layout, those who are familiar with ISO management systems will find the usual Annex SL layout in ISO 21001. However, in this standard there are specific requirements in regards to educational providers and their services and products, and in contrast to other ISO standards, the Annex A of ISO 21001 (normative) points out additional requirements for early childhood education.
It must also be added here that its annexes, especially Annex A, B & E are quite extensive, and provide considerable information and guidance in regards to ISO 21001 requirements and education related concepts.

ISO 21001 Terminology And Perspectives

When considering the standard and its requirements from the perspective of the educator or someone who is directly involved in education-related research, it must be stressed out that the standard does a solid job in offering a comprehensive document which includes detailed requirements towards educational service design and development controls. These are specifically stated throughout clause 8 Operation and its subclauses: 8.3.4.4 Summative assessment design and development controls; 8.3.4.3 Curriculum design and development controls; 8.3.4.2 Educational service design and development controls; and so on.

Special Needs Education

What is most impressive about this standard is the language used and the emphasis it places on special needs education.
It can be noted that they took special precautions not to use any deficiency terms, which view students as having a deficiency but rather employed terms such as students with special needs, exceptionalities, etc. which are more in line with the current disability studies in education. This is further supported by stressing out the need for a special education focus from the leadership perspective (clause 5), to the requirements set for facilities which ought to be accessible and “ensure that the dimensions of the facilities are adequate to the requirements of those using them” (clause 7.1.3.1), and continued with the requirements for curriculum and instruction modification/adaption (clause 8.3.4.3), in order to meet the diverse pool of learners’ needs.
Although not directly stressed out, which is common for ISO/standardization documents, it can be seen that requirements on special needs education were well elaborated and reflect – to an extent – the work of Universal Design (UD) and Universal Design for Learning (UDL) principles – whose main focus is to offer all students (no matter their dis/abilities, background, etc.) accessible educational services, products and environments.
Conclusion
The ISO 21001 standard provides a great basis for educational providers to enhance the quality of their products and services. Although, there might be a general wariness in regards to standardization, due to the educational fields’ overtly reliance on standardized performance tests and the controversial debates surrounding it. However, if the standard is implemented, and complemented with best practices in the field of education, it will help organizations yield positive results for its beneficiaries – be it students, parents, community, and/or others.

Be Prepared For The Unexpected With A Business Continuity Plan

Jan 22 • 5 min read

In today’s world, organizations are exposed to numerous disruptive events. Each year hundreds of businesses fail as the result of an unexpected crisis. Hence, managing risk and planning for a catastrophic event should be an important strategic decision for all organizations to take no matter their size. Definitely, IT infrastructure is the core element for any organization to operate and in the case of an unforeseen IT system failure, the organization’s efficiency will be directly affected, therefore, it is essential to be prepared for the unexpected. Having a rapid recovery after a disaster is very important, and in order to forestall, you should develop a business continuity plan so that your business will survive when an unforeseen disruption occurs. Subsequently, having a plan that demonstrates how to respond to an event is a valuable asset for any organization and it minimizes the impact of a disaster.

What Is Business Continuity?

Business Continuity is strategic planning done by the organization in order to prevent, detect, prepare and respond effectively and swiftly. It involves more detailed planning that emphasis on the long-term organizational success and continuous viability within the industry space. A Business Continuity plan states the steps that need to be taken before, during and after the event. ISO 22301 is designed to assist businesses in the implementation of a business continuity management system that meets their requirements and needs to remain resilient. When implementing the standard, it requires involving the whole organization in order to have improved communication, segregation of duties and satisfied employees. Significantly, with business continuity, you will minimize major losses, maximize the recovery time of critical functions and in addition, your data backups will be secured.
Disruptive events that could affect your organization are:
  • Natural disasters
  • Theft
  • Fire
  • IT system failure
  • Terrorist attack
  • Loss of power
  • Cyber attacks
  • Hurricane
  • Riots
  • Data Loss
  • Loss of life
  • Breach of regulatory requirements
  • E.T.C

Why Is It Important To Plan For A Potential Disruption?

To prepare for and protect your organization from the impact of possible crises, it is essential to have a detailed plan in place that allows you to recover quickly from disruptions and continue business operations without facing massive impacts such as financial loss and reputational damage. Indisputably, this planning is important for all businesses. It is even important for small businesses since they usually have limited recourses to survive in a crisis. While you try to recover your business, you may risk losing your customers, and you may never get back on your feet again.
When planning you should:
  • Identify possible disruptions that can impact your organization’s services, processes, and activities
  • Determine how you expect to reduce the risks of these disruptive events to an acceptable level in view of your organization’s risk appetite
  • Test the plan regularly to ensure continuous relevance and effectiveness in the case of a real disaster
  • Define and explain in the business continuity plan how you will respond if a disaster occurs

What Are The Benefits Of ISO 22301?

Business Continuity Planning assures an organization that they hold the necessary resources accessible and critical know-how in order to proactively continue to assure the stability of the organization when the disaster occurs. Given that, having a Business Continuity Plan means that your organization is prepared for the unexpected and also:
  • Ensures flexibility during disasters – Your organization will recover from the disruption effectively within a short period of time.
  • Marketing edge – With a business continuity plan you will assure your customers/stakeholders that no matter the destructive nature of the event, your organization is well-positioned to continue to deliver goods and services to customers’ desired expectations.
  • Increased employee morale and confidence – Having a plan in place for the staff when things are not going well is an important aspect which gives them the confidence to rely on it. As a result, they will give their best to accomplish the expectations of the top management.
  • Improved value/trust for stakeholders and customers – Organizations that are faced with different disruptions and deal with them effectively, demonstrates that they are a more valuable and trustful investment than the others.
  • Identifying risk – Through risk assessments, all the threats and vulnerabilities will be identified and it will minimize the impact in the event of risk occurrence within the organization.
  • Cost savings – Having an effective Business Continuity Program, the expenditures of any potential disruption will be considerably reduced.
  • Improved Communication – Communication is one important aspect of the business continuity plan; the ability to provide the work to the right person and to inform them at the right time.
  • Reduce insurance premiums – A disruptive event not only affects your organization but it affects your insurance providers as well. Business Continuity Planning proves your commitment to deal with risks and your insurer will take this into consideration when calculating your insurance premium.
  • Safe data – Regardless of the damage that happens within your workplace, or what kind of hardware is stolen, with cloud backups of your data, you are directly minimizing the threats of losing your records.
Organizations that are keen to know how to continue to operate efficiently within a short period of time after disaster strikes can refer to PECB training. We are dedicated to Business Continuity Planning and continually adding value to this portfolio by developing training and offering certification services.

4 Key Stages Of Asset Management Life Cycle

Jan 22 • 6 min read
What ‘Asset’ Means And Why Asset Management Is Important?

Assets have been managed and maintained professionally by public sector managers for decades. Nevertheless, economic and financial developments of recent years alert that what we have been doing in the past will not be satisfactory to deal with challenges in the future. Realistic, advanced methods for enhanced managing physical assets have been increased and sophisticated over the past several years. In addition, such techniques have been gradually incorporated into a holistic management framework.

Assets are defined as follows: “An asset is an item, thing or entity that has potential or actual value to an organization”. Based on ISO 55000, asset management is described as “coordinated activity of an organization to realize value from assets”. Consecutively, this is broader than physical assets which bring a significant target and focus for more companies.
The process of optimizing the delivery of a value and making the appropriate decision is asset management. Asset Management comprises of opportunities, balancing of costs and threats against the desired level of performance of assets, which is essential for the greatest return on investment and to attain the main objectives of the organization. One of the main objectives is minimizing the overall life cost of assets which can be affected by other indicators such as business continuity or risk during the decision making process. Additionally, it makes possible for an organization to study and observe the performance of assets in different stages. Throughout the application of asset management, the organization is able to analyze different approaches towards managing an asset during life cycle stages, which will be discussed later on.
The asset management team is within a financial company which is devoted to running and organizing client assets. In client assets are included cash, investments etc. Monitoring machines is a fundamental enterprise task which assists regulatory and license compliance, security, and software and hardware management. Therefore, an appropriate asset management strategies and financial resources can save both time and cost of the company.
Such a strategy is crucial for monitoring all of your hardware and software assets. By implementing an asset management strategy, it will be easier for the company to track all the changes of the assets, their location and how they are configured.

The Asset Life Cycle

A key process within asset management is the understanding of asset life cycle. There are four key stages of the asset lifecycle, which this section will classify and describe. The four key stages of the asset lifecycle are:

Planning

Planning is the first stage of the asset life cycle. This stage establishes and verifies asset requirements. Establishment of asset requirements is based on evaluation of the existing assets and their potential to meet service delivery needs. Identification of management strategies is required in order to include and analyze the need for an asset. Throughout all stages of planning, it is crucial to make sure that the ongoing development adds value to the organization.
If the company uses effectively planning in all asset management cycle stages, it will help in:
  • assessing the practical sufficiency of existing assets
  • ensuring resources are available when necessary
  • recognizing excess or under-performing assets
  • estimating options for asset provision and funding asset acquisition
  • ensuring assets are maintained and liable
The progress of an asset management project as component of the organization’s planning procedures gives the most excellent means of delivering value-added asset management.
Acquisition
Taking the best decision on choosing the best option can only be made after defining the cost and the requirements. The choice will be the phase of further planning, the acquisition planning. The acquisition planning includes activities involved in purchasing an asset with the aim of ensuring cost effective acquisition. This covers activities such as designing and procuring an asset. Appropriate application of these activities guarantees that the asset is fit for use.
Initially, the organization should decide whether the asset will be perpetually bought or built. Next, establish a budgeting for asset acquisition along with a time frame for its acquisition and a purchasing requirement. A practical budget and cash flow should be put as deficient funds or otherwise project management can put at risk the process of asset acquisition. Whenever these requirements are met, a project team should run the process to make sure that all acquisition process activities will be completed to meet service delivery and other organization objectives.
Operation and maintenance
The operation and maintenance stage indicates the application and management of an asset, including maintenance, with the aim of delivering services. The plan of asset management should have a high focus on asset maintenance issues. Long lived assets, in the majority of public sector assets, especially roads and buildings require particular maintenance during their life cycle.
Throughout this time, the asset should be focus to appropriate maintenance, monitoring and potential improvement to overpass any adjustment in operational requirement.
Disposal
When an asset reaches its end of a useful life, it can be treated as a surplus, or otherwise is considered as an underperforming asset. Disposal should be treated in the perspective of the effects of the decision on service delivery and any departmental responsibilities. A special focus should be placed on cultural heritage where there are detailed requirements that organization should take into consideration. If in the near future an asset is to be disposed, in order that statutory maintenance to be taken, the maintenance strategy should be properly adjusted.
Any organization, in either public or private sector, will need to deal with asset handling. Recognizing asset’s value, future value and costs are essential, therefore developing a strategic asset management plan is highly preferred and required. Such a strategic asset management plan would enable an effective and well- organized asset and deliver services.
There are already different systems, methods, software, and standards which are used to manage different types of assets. It is up to companies what to consider an asset and what to include in asset portfolio. Sometimes assets are managed as a group, rather than individual. Such groupings of assets may be by asset types, asset systems, or asset portfolios.
One of the newest standards for managing asset is ISO 55001 Asset Management. According to ISO 55001, this new standard leaves an open topic to organizations to determine what to consider asset, so ISO 55001 specifies the requirements for the establishment, implementation, maintenance and improvement of a management system for asset management, referred to as an “asset management system”.
Also managing assets should not be looked from isolated mode. At the time where most of the assets managed are IT and even cyberspace related, care should be looked from the Information Security Management point of view as well as Cyber Security point of view.
ISO 55001 is an opportunity to manage the Cyber Security or Information Security form looking at the asset. This mean a correlation with standard related to business continuity Management ISO 22031, Information Security Management ISO 27001/2 ; Building Cyber Security Framework ISO 27032.

With Less Than 90 Days To Go, Are You Ready For GDPR Enforcement?

Jan 22 • 3 min read
With Less Than 90 Days to Go, Are You Ready for GDPR Enforcement?
We have so many security threats and concerns when our personal information gets leaked or reaches to any unknown source, this is why GDPR (General data protection Regulations) was introduced to make Banking and IT sector safer, permitting people to work without worrying about their personal data getting leaked. GDPR training in Jordan is designed to help you learn potential hacking threats, and how to overcome these problems from occurring in these sectors whilst securing data of Banking or IT sector.
What are the advantages of using GDPR in IT and Banking Sector and its impact?
Nowadays, GDPR is enforced throughout IT and Banking sector. All the companies are forced to search from scratch whatever data they have collected and delete if any unnecessary data has been kept of a client. There is no purview for anyone if they are in IT or banking sector, companies have to apply GDPR according to given guidelines as people now days are highly aware of their information passing out on internet.
Since the enforcement of GDPR, IT sector companies have hired professionals for overviewing data collection and process the data according to given guidelines of GDPR. Companies have to design a new cyber security system according to required demands of General Data Regulation, and eliminate security threat that breaches their system to minimize any leakage of personal information which was previously done. People have been provided with knowledge of how to use GDPR for their own benefits, like right to know why their data is collected, for what purpose the company is using their data and the company is bound to respond to them on the given time. We all know that security threats to personal data or banking information is a big issue, since the introduction of GDPR banking section, banks have reengineered their format and security platform. Great change has been observed and chances of losing any confidential data have been reduced significantly.
Who should enroll in PECB training in Jordon?
A person who wants to master cyber security, comprehend its usage and is eager to become a DPO should enroll in GDPR security training in Jordon. GDPR helps you protect data of customer and you can utilize it according to the instruction provided by GDPR.

The Joy Of Tidying Up With Six Sigma

Jan 22 • 3 min read
Worldwide companies are advancing and growing by learning and applying a variety of new techniques in order to optimize their processes and make them more efficient and effective. To add value to your career and be able to help such companies in optimizing their work, you need to get certified in six sigma green belt. Getting six sigma training in Jordan will enhance your abilities and expertise in comparison to your peers, it will give you an edge and increase your standing in organizations in contrast to other engineers. Six sigma green belt will aid you to enhance your problem solving, leadership and managerial skills and will enable you to work effectively.
The role of Six Sigma in an engineer’s career is of immense significance, as they work in a very complex environment for projects assigned by clients. Six sigma is popular and beneficial for industrials engineers as they manage and overlook the entire industry focusing to improve different units; Six Sigma can be applied to various jobs and areas.

Designing Area: You can utilize six sigma in early stage of any project development to figure out the problems occurring in the products/ services.

Processing Area: You can utilize six sigma in processing areas when manufacturing/ delivering any product/ service, identifying and improving problems discovered and eliminating them in this most effective manner.

System Area: In system area you can utilize six sigma to produce cost effective products/ services and assign the given resources according to the project.

Benefits of getting six sigma training in Jordan:
When you are Six Sigma green belt certified, you can easily fulfill variety of roles for any organization that requires your services. You can analyze data of the company and continuously give them improvement for their products/ services. It enables you to identify current pain in the processes and work on eliminating it to the minimum yielding a better outcome. Six Sigma also enhances your managerial and leadership skills. Therefore, your output of working for a company will be different and more effective in comparison to other engineers.

Which engineers should enroll?
Engineers who are looking for growth in their engineering skills and careers, are keen on improving their skills of processing and enthusiastically work as team members in any large scale organization, where there is scope of improving products/ services should enroll in Six Sigma Green belt program.

AAC MENA IS NOW CERTIFIED AS THE FIRST & ONLY GOLD PARTNER FOR PECB IN JORDAN

Jan 22 • 2 min read
Working in this competitive industry where competition is persistent in all aspects left, right and centre, it is mandatory for an individual or corporation to be vigilant and strive for growth. Constantly learning and striving for excellence is crucial for breakthrough performance and reach the peak of your goals. Which is why AAC, in partnership with PECB, brings various certification courses and trainings for your benefit, including ISO training in Jordan, GDPR training in Jordan and Six Sigma Training. A credible leading source added to AAC to render optimized education, there has never been a better time to be alive for working professionals.
What is PECB?
PECB is an internationally acclaimed, certification firm for enterprises, individuals, management systems and services/products based on various international standards. PECB’s expertise lays in all sectors and industries and provides trainings, audits, examinations and certifications across the globe.
Via providing premium training, AAC & PECB work to bridge the gap between a person and success or an organization and success. Their various certification, which adhere to internationally recognized standards, empowers the participant to be more competent, diligent and agile in their applications. Accredited via IAS, PECB has been benefiting the corporate industry at large for years with excellence.
AAC is full service training and management consultancy which is established with the agenda to aid organizations to harvest their maximum potential and enhance their operations via premium ISO training and consulting, innovation and security solutions and leadership management solutions. Thus, providing robust solutions and strategies to firms. Accredited by a global certification body, AAC delivers competent trainings adhering to all internationally recognized standards.
AAC comprises of immensely qualified trainers who are proficient in providing quality education owing to their years of hands on field experience.
We looking forward for more partnerships in order to serve our clients at the highest standards and stay at their favourite lists for training and development.

How To Keep Your Organization On Improvement Track?

Jan 22 • 2 min read
Organizations need to adopt a methodology which ensures ongoing positive improvement and changes. In order to reap this; Kaizen, of Japanese origin, is considered to be one of the most suitable tools which can become a culture where every single employee is concerned with getting up with systems, processes, and procedures.
Continuous improvement, the heart of kaizen, tends to believe that there is always an optimization possibility. It can be achieved starting by having all employees engaged in order to get a thorough definition of what issues, opportunities, and risks the company faces, and then developing appropriate solutions to roll out any negative outcomes and seize any positive opportunity. Taking into consideration, the importance of measurement and analysis of the obtained results.
After applying these steps successfully, a company cannot let go! the whole process has to be done cyclically in order to preserve the continuity of achieving preset objectives.
Some other companies may implement Kaizen using Shewhart or what is known as PDCA cycle where the abbreviation refers to Plan, Do, Check, Act; meaning people need to plan to the improvements they need, implement the changes, check the findings, and then act to hold the gain or start again.
Implementing Kaizen effectively guarantees long-term value since it expands the employees’ ways of thinking and creates a consistent sustained culture of pursuit towards continuous improvement.
Here, in AAC MENA/ Aswar Akka Consultancy we provide a comprehensive consultation that evaluates how close you are from Kaizen effective implementation and help you to walk the required steps to reach the obtained improvements. In addition to our expertise to arrange both practical and theoretical courses of Kaizen best practices tailored to your organization.