ARMOR

ייעוץ פרטיות ורגולציה

Privacy & Regulatory Compliance
תיקון 13 · תקנות אבטחת מידע · ממונה הגנת פרטיות · ISO 27001

Privacy & Regulatory Compliance

Amendment 13 · Data Security Regulations · DPO · ISO 27001
Compliance you can demonstrate to a regulator, a client or an auditor
ARMOR IT & SECURITY LTD.

עמידה ברגולציה שאפשר להוכיח

מאז תיקון 13 לחוק הגנת הפרטיות, כל ארגון שמחזיק מידע אישי צריך לדעת בדיוק אילו מאגרים יש לו, מה רמת האבטחה שחלה על כל אחד מהם, מי אחראי, ומה הוא עושה כשמשהו משתבש. אנחנו מלווים חברות, עמותות ומוסדות מהמיפוי הראשון ועד למסמכים חתומים, לנהלים שעובדים בפועל ולהסמכה, בשפה שההנהלה מבינה ובלי לייצר בירוקרטיה מיותרת.

ARMOR IT & SECURITY LTD.

Compliance you can prove

Since Amendment 13 to the Israeli Privacy Protection Law, every organization that holds personal data must know exactly which databases it has, which security level applies to each, who is accountable, and what happens when something goes wrong. We guide companies, non-profits and institutions from the first mapping to signed documents, procedures that work in practice and certification, in language management understands and without creating unnecessary bureaucracy.

SCOPE

מה כולל השירות

מיפוי מאגרי מידע וסיווג

איתור כל מאגרי המידע בארגון, סיווג לפי סוג המידע ומספר הנושאים, וקביעת רמת האבטחה שחלה על כל מאגר: בסיסית, בינונית או גבוהה.

תקנות אבטחת מידע · תקנה 1

היערכות לתיקון 13

בדיקת החובות החדשות שחלות על הארגון: חובת מינוי ממונה הגנת פרטיות (DPO), חובות דיווח ורישום, הסמכות הרשות להגנת הפרטיות והעיצומים הכספיים, ותוכנית סגירת פערים.

תיקון 13 · בתוקף מאוגוסט 2025

מסמך הגדרות מאגר ונהלים

כתיבת מסמך הגדרות המאגר, נוהל אבטחת מידע, נוהל ניהול הרשאות, נוהל אירוע אבטחה ונוהל עבודה עם ספקים, מותאמים לגודל הארגון ולא מועתקים מתבנית.

תקנות אבטחת מידע 2017

ממונה הגנת פרטיות חיצוני

מילוי תפקיד ה-DPO עבור ארגונים שחייבים במינוי או בוחרים בו: תוכנית עבודה שנתית, הדרכות, מענה לפניות נושאי מידע, וקשר שוטף מול הרשות להגנת הפרטיות.

DPO as a Service

ליווי להסמכת ISO 27001

ניתוח פערים מול התקן, בניית מערכת ניהול אבטחת מידע, הצהרת ישימות, ניהול סיכונים, מבדק פנימי והכנה למבדק ההסמכה מול הגוף המסמיך.

ISO/IEC 27001:2022

הדרכות ומודעות

הדרכות פרטיות ואבטחת מידע לעובדים, להנהלה ולדירקטוריון, כולל תיעוד ההדרכה כנדרש בתקנות, ותרגול תגובה לאירוע ברמת ההנהלה.

תקנה 7 · הדרכה תקופתית
SCOPE

What the service covers

Database mapping and classification

Identifying every personal-data database in the organization, classifying it by data type and number of data subjects, and determining the applicable security level: basic, medium or high.

Data Security Regulations · Reg. 1

Amendment 13 readiness

Review of the new obligations that apply to the organization: mandatory DPO appointment, reporting and registration duties, the Privacy Protection Authority's enforcement powers and fines, and a gap-closure plan.

Amendment 13 · in force since August 2025

Database definitions document and procedures

Writing the database definitions document, the information security procedure, access-management, security-incident and vendor-management procedures, tailored to the organization rather than copied from a template.

Data Security Regulations 2017

Outsourced Data Protection Officer

Serving as the organization's DPO where appointment is mandatory or chosen: annual work plan, training, handling data-subject requests, and ongoing contact with the Privacy Protection Authority.

DPO as a Service

ISO 27001 certification support

Gap analysis against the standard, building the information security management system, statement of applicability, risk management, internal audit and preparation for the certification audit.

ISO/IEC 27001:2022

Training and awareness

Privacy and security training for staff, management and the board, documented as the regulations require, plus incident-response exercises at management level.

Reg. 7 · periodic training
METHOD

איך אנחנו עובדים

חמישה שלבים, כל אחד מסתיים בתוצר שאפשר להציג לרשות, ללקוח או למבקר.

1

מיפוי ופערים

ראיונות עם בעלי התפקידים, סקירת מערכות וחוזים, ומפת פערים מול החוק, התקנות והתקן.

2

תוכנית עבודה

תעדוף לפי סיכון וחובה חוקית, לוחות זמנים ואחריות, מאושר על ידי ההנהלה.

3

יישום

כתיבת המסמכים והנהלים, הגדרת בקרות, ליווי צוותי ה-IT והספקים בהטמעה.

4

בקרה והטמעה

הדרכות, בדיקת יישום בפועל, מבדק פנימי ותיקון ממצאים לפני הסמכה או ביקורת.

5

ליווי שוטף

עדכון שנתי של המסמכים, מעקב אחר שינויי רגולציה, ומענה לאירועים ולפניות.

METHOD

How we work

Five stages, each ending in a deliverable you can show a regulator, a client or an auditor.

1

Mapping and gaps

Interviews with role holders, review of systems and contracts, and a gap map against the law, the regulations and the standard.

2

Work plan

Prioritized by risk and legal obligation, with timelines and owners, approved by management.

3

Implementation

Writing documents and procedures, defining controls, supporting IT teams and vendors through rollout.

4

Verification

Training, checking actual implementation, internal audit and fixing findings before certification or inspection.

5

Ongoing support

Annual document updates, tracking regulatory changes, and handling incidents and requests.

STANDARDS

תקנים ורגולציה

חוק הגנת הפרטיות ותיקון 13תקנות הגנת הפרטיות (אבטחת מידע) 2017ISO/IEC 27001:2022ISO/IEC 27701תורת ההגנה בסייבר 2.0GDPR לארגונים עם לקוחות באירופה

תוצרים

  • דוח מיפוי מאגרים ופערים עם רמת אבטחה לכל מאגר
  • מסמך הגדרות מאגר ומערך נהלים מלא
  • תוכנית עבודה מתועדפת מאושרת הנהלה
  • מינוי ממונה הגנת פרטיות ותוכנית עבודה שנתית
  • תיק הסמכה ל-ISO 27001 ומבדק פנימי מתועד

התחייבויות

  • בגובה העיניים. מסמכים שהעובדים באמת קוראים ומבינים, ולכן גם מיישמים.
  • מידתיות. הדרישות מותאמות לגודל הארגון ולרמת האבטחה שחלה עליו בפועל, כך שההשקעה הולכת למקום הנכון.
  • אחריות אישית. אותו יועץ מלווה את הארגון מהמיפוי ועד להסמכה ולביקורות שאחריה.
  • סודיות. כל המידע שנחשף בעבודה מטופל תחת הסכם סודיות ונשמר לפי תנאי השמירה שסוכמו.
STANDARDS

Standards and regulation

Privacy Protection Law and Amendment 13Privacy Protection Regulations (Data Security) 2017ISO/IEC 27001:2022ISO/IEC 27701INCD Cyber Defense Doctrine 2.0GDPR for organizations with EU customers

Deliverables

  • Database mapping and gap report with a security level per database
  • Database definitions document and a complete set of procedures
  • Prioritized work plan approved by management
  • DPO appointment and annual work plan
  • ISO 27001 certification file and documented internal audit

Our commitments

  • Plain language. Documents your people actually read and understand, and therefore follow.
  • Proportionality. Requirements sized to the organization and to the security level that actually applies to it, so the investment goes where it matters.
  • Personal accountability. The same consultant accompanies the organization from mapping through certification and the audits that follow.
  • Confidentiality. Everything we see is handled under NDA and retained according to the agreed terms.

מתחילים ממיפוי

שיחת היכרות קצרה, ותוך ימים ספורים תדעו איפה אתם עומדים מול תיקון 13.

לחץ כאן ליצירת קשר
ארמור אי.טי. אנד סקיוריטי בע"מ · רחוב תוצרת הארץ 3, פתח תקווה · info@armor.co.il

חזרה לכל השירותים

Start with a mapping

A short intro call, and within days you will know where you stand against Amendment 13.

Contact us
Armor IT & Security Ltd. · 3 Totzeret HaAretz St., Petah Tikva, Israel · info@armor.co.il

Back to all services
כל הזכויות שמורות לחברת ארמור בע"מ © 2026 · מדיניות פרטיות · הצהרת נגישות© 2026 Armor IT & Security Ltd. All rights reserved. · Privacy policy · Accessibility