5. Protection of Personal Data Flashcards
Info Sec vs. Privacy
Security - focus on the control of data - building on risk management practices.
Privacy - focuses on the information itself and the people represented by the information.
Privacy: personal, sensitive, nonpersonal
InfoSec: public, confidential, highly confidential, restricted
Info Sec Controls (APT) & Categories of Info Sec Controls (PDC)
ISO27701?
Information Security Controls
- Administrative
- Physical
- Technical
Categories of Security Controls:
- Preventive
- Detective
- Corrective
ISO27701 - first mainstream global privacy management standard
Types of Controls (AART)
Administrative Controls - non-technical control measures established by management and derived from laws.
Access Controls - govern who has the right to access specific info
Role-Based Controls - ensures that only those who absolutely need access to certain information have it.
Technical Controls - ways to protect PII. i.e obfuscation & hashing
Privacy By Design - Embeds privacy into the design of technology, systems and practices to help ensure the existence of privacy.
PbD 7 Principles (P,PbD,PbD,FF,E2E,V&T,R)
Privacy By Design 7 Principles:
1. Proactive not reactive, Preventative not remedial
2. Privacy as the default
3. Privacy embedded into design
4. Full functionality - positive sum not 0 sum
5. End to End Security - Life Cycle Protection
6. Visibility and Transparency
7. Respect for User Privacy
Examples of Privacy Risk Models and Frameworks
Several Privacy Risk Models and Frameworks can be used in combination:
- FIPPs - Fair Information Practices Principles
- Factor Analysis of Information Risk (FAIR)
- NIST
- Risk Management Framework
- Cyber Security Framework
- Privacy Framework
Data protection/GDPR principles
- lawfulness, fairness, transparency
- purpose limitations
- storage limitations
- data minimization
- accuracy
- accountability
- Confidentiality. Integrity. Availability.
C.I.A.
Confidentiality. Integrity. Availability.
GDPR Article 25 (PbD & PbD)
Privacy by Design
Privacy by Default