Access and Feeds

Data Privacy Audits: Using Security to Achieve Privacy

By Dick Weisinger

New regulations like the General Data Protection Regulations (GDPR) in the EU and the California Consumer Privacy Act (CCPA) are putting a focus on how personal data is collected, used, and secured.

Andrew Struthers-Kennedy, managing director at Protiviti, said that “as much as organizations are focusing on cyber security and protecting their data, they’re still behind given the changing landscape, growing sophistication of cyber criminals, evolving regulatory requirements such as GDPR, and persistent gaps and process breakdowns that emerge as part of their ongoing transformation projects.”

In order to ensure compliance with new regulations, privacy audits become increasingly important. Privacy audits take into consideration some of the following areas (Infosec Institute):

  • IT Model – Are appropriate controls being used?
  • Workflows – How is information transmitted externally and internally, which users have access, and what is the sensitivity of the information transmitted?
  • Social Media – What policies are used to avoid accidental disclosure of information?
  • Wireless/mobile – Is there a bring-your-own-device policy? Off-premise Wi-Fi connections?
  • Data Processes – Is data encryption used? Database and system access controls? How is information restricted based on user role and job function? Multi-factor authentication?

A note in the ISACA cautions “that security does not mean privacy. Confidentiality is preserving authorized restrictions on access and disclosure, including means for protecting privacy and proprietary information. Privacy is a possible outcome of security.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)

Leave a Reply

Your email address will not be published. Required fields are marked *

*

twelve − 9 =