Fernando Rossi

Fernando Rossi Email and Phone Number

Senior Advisor, Data Protection Officer (DPO), Information Security & Business Continuity consultant @
Fernando Rossi's Location
Milan, Lombardy, Italy, Italy
About Fernando Rossi

I define and implement Data Protection solutions in line with business objectives, in compliance with standards, legal regulations and sector regulations.I lead the company to reach and maintain the ISO27001 and ISO22301 certification, PCI-DSS, and to comply with GDPR requirements. I define the security and continuity impacts on the processes and services provided due to new regulatory requirements, reorganizations, technological changes.Roles: Data Protection Officer (DPO), Information Security Manager (ISM), Business Continuity Manager (BCM), Project Manager (PM), AuditorAreas of expertise: Banking (e-money and payments, private banking, retail), Insurance, ICT services, After-sales services, Industry, Telco, Public Administration, Logistics.

Fernando Rossi's Current Company Details
Security Lab Advisory (Lugano)

Security Lab Advisory (Lugano)

Senior Advisor, Data Protection Officer (DPO), Information Security & Business Continuity consultant
Fernando Rossi Work Experience Details
  • Security Lab Advisory (Lugano)
    Senior Advisor, Dpo
    Security Lab Advisory (Lugano) Sep 2017 - Present
    Lugano
    Information Security activity:• Preparation for ISO27001 certification.• Planning and implementation of the ISMS in compliance with the ISO27001 standard.• Compliance with FINMA requirements related to IT operational risks and service outsourcing.• Drafting of security policies and procedures.• Internal audit on the effective application of security controls.• Measurement of safety objectives through specific KPIs.• Risk Analysis and updating of the Risk Treatment Plan.• Preparation for ISMS review.DPO activity• Verification of compliance with EU Regulation 2016/679• Periodic update on personal protection regulations• Support in drafting the contents of the information to the data subjects, Privacy policies, Records of processing activities and the Impact Analysis (DPIA)• Periodic audits• Periodic reports to the managementPrivacy - Compliance with EU Regulation 2016/679 (GDPR) activity.• Gap analysis and GDPR adjustment plan• Definition of roles and responsibilities in the treatment of personal data.• Determination of the content of contracts with suppliers / outsourcers.• Risks Analysis associated with the processing of personal data• DPIA (Data Protection Impact Assessment).• Content of the Records of processing activities and definition of the maintenance process• Disclosures, consents, appointments of managers and authorized processors• Review of security policies and procedures relating to privacy aspects.• Introduction of the principle of Privacy by design and Privacy by default in the life cycle of information systems.• Definition of the Data Breach process.• Definition of the process for managing the exercise of the rights of the interested party.• Definition of the Personal Data Protection Management System.Preparation of contents for the training of those authorized to process.Main companies in which I worked: April Italia, Banca Arner, COREPLA, equensWorldline, Wellcomm Engineering
  • Equensworldline
    Information Security & Business Continuity Consultant
    Equensworldline Mar 2012 - Dec 2016
    Milan
    Main activities in Information Security:• ISMS planning and implementation, comply with standard ISO27001.• Writing the security policies and procedures.• Measurement the security objectives by specific the KPI.• Risk analysis review and Risk treatment plan update.• Preparation of the certification/renewal of standard ISO27001.• Adding the PCI-DSS requirements to the security controls and support for the certification.Main activities in Business Continuity:• BCMS planning and implementation, comply with standard ISO22301 and the guidelines / circulars of Banca d’Italia and DNB.• Business Impact Analysis review, Risk Impact Analysis, BC Plan, DR Plan, BC Test Plan.Main activities concerning Privacy:• Periodic checks of compliance with regulatory requirements on privacy.• Privacy policy and procedures• Check if new personal data process, or changes to existing processes.• Data classification• Incident management• Risk assessment• Documentation for training of the employees on personal data process and security awareness.• Log management• Control of the system engineers’ activities (prov. 27 November 2008).
  • Beta 80 Group
    Project Manager - Information Security & Risk Management
    Beta 80 Group Jul 2006 - Jan 2012
    Milan
    • Preparation of the certification standard ISO27001.• Privacy: writing the Security Policy Document, Records of processing activities, Risk Analysis, roles and responsibilities, privacy policy and procedures, data classification, incident management, log management, security controls, information and consent, check the security clauses in the supplier contract, system administrators activity control.• Data Retention management: retention of data relating to the professional activity carried out by employees, in accordance with the Data Protection law. It includes:• Log Management.• Security Dashboard.• Writing the Security Policies.• Risk Assessment. • System strong authentication (RSA).Main companies in which I worked: Danieli, Equens, i-Faber, IPZS, T-Systems, Vodafone
  • Prismasec Italia
    Project Manager - Information Security & Risk Management
    Prismasec Italia Mar 2004 - May 2006
    Milan
    • Privacy: writing Security Policy Document, Records of processing activities, Risk Analysis, roles and responsibilities, security controls, information and consent, check the security clauses in the supplier contract, system administrators controls.• Business Impact Analysis, Business Continuity Plan, comply with guideline of Banca d’Italia. • Audit on contracts concerning outsourcing ICT services.Main companies in which I worked: ASL C Roma, Banca BSI, Comune di Piacenza, Deborah, Fedon, SDF-Same
  • B-Source Sa
    Software Analyst
    B-Source Sa Jun 2001 - Feb 2003
    Lugano-Ch
    • Development and maintenance THE BOSS banking information system in Retail area.
  • Atos Origin
    Pm Information Systems
    Atos Origin Jan 1992 - May 2001
    Milano
    • Information System Post-sales technical support concerning consumer electronics products.• Information System for the Call Center.• Customer Database for marketing and customer services.• Migration and downsizing of information systems.• Information System of the Custodian Bank.• Payment Systems.• Central Credit Information System.Main companies in which I worked: Deutsche Bank, Enidata, Philips Electronics, SIA, Whirlpool
  • Philips Benelux
    Project Manager - Information Systems
    Philips Benelux Jan 1990 - Dec 1991
    Milano
    • Information System Post-sales technical support concerning consumer electronics products.
  • Artsana Group
    Software Analyst
    Artsana Group Feb 1972 - Apr 1989
    Como Area, Italy
    • Customizing the ERP system for managing the sales cycle of finished goods, and the company's distribution network.• Information system for the deposit warehouses.• IBM mainframe System Operator.

Fernando Rossi Skills

Iso 27001 Iso 22301 Regulation Eu 2016/679 Information Security Isms Business Continuity Disaster Recovery Bcms Guidelines Of Banca D'italia On Business Continuity Privacy Regolamento Ue 2016/679 D.lgs 196/2003 Risk Analysis Process Innovation Digital Innovation Security Audit Banking Telco Logistics Information Technology Aftersales Helthcare Privacy Officer Project Management Microsoft Office Sicurezza Management Cloud Computing Itil Pci Dss Innovazione Integrazione Industry Gdpr Lpd Ism Bcm Dpo Data Protection Psd2 Information Security Management Privacy Compliance Standards Compliance Process Improvement Auditing Healthcare

Fernando Rossi Education Details

Frequently Asked Questions about Fernando Rossi

What company does Fernando Rossi work for?

Fernando Rossi works for Security Lab Advisory (Lugano)

What is Fernando Rossi's role at the current company?

Fernando Rossi's current role is Senior Advisor, Data Protection Officer (DPO), Information Security & Business Continuity consultant.

What schools did Fernando Rossi attend?

Fernando Rossi attended Politecnico Di Milano, Mip-Politecnico Di Milano, Mip-Politecnico Di Milano, I.p.s.i.a. Leonardo Da Vinci - Como, Cefriel - Politecnico Di Milano.

What are some of Fernando Rossi's interests?

Fernando Rossi has interest in Teatro, Basket, Promuovere Lo Sport Giovanile, Organizzare Meeting.

What skills is Fernando Rossi known for?

Fernando Rossi has skills like Iso 27001, Iso 22301, Regulation Eu 2016/679, Information Security, Isms, Business Continuity, Disaster Recovery, Bcms, Guidelines Of Banca D'italia On Business Continuity, Privacy, Regolamento Ue 2016/679, D.lgs 196/2003.

Not the Fernando Rossi you were looking for?

Free Chrome Extension

Find emails, phones & company data instantly

Find verified emails from LinkedIn profiles
Get direct phone numbers & mobile contacts
Access company data & employee information
Works directly on LinkedIn - no copy/paste needed
Get Chrome Extension - Free

Aero Online

Your AI prospecting assistant

Download 750 million emails and 100 million phone numbers

Access emails and phone numbers of over 750 million business users. Instantly download verified profiles using 20+ filters, including location, job title, company, function, and industry.