Download presentation
Presentation is loading. Please wait.
Published byKristopher Hopkins Modified over 9 years ago
1
Using Risk Management to Improve Privacy in Information Systems 1
2
Potential Problems for Individuals 2 Loss of Self Determination Loss of Autonomy Exclusion Loss of Liberty Physical Harm Loss of Trust Discriminatio n Stigmatization Power Imbalance Economic Loss
3
3 Fram e Asses s Respon d Monito r
4
Senior Management Product Manager 4 Engineer Controls Objectives Metrics Governance Risk Model Risk Assessment Requiremen ts System Design Evaluation
5
The Right Tool for the Job Many current privacy approaches are some mixture of governance principles, requirements and controls. Transparency Individual Participation Purpose Specification Data Minimization Use Limitation Data Quality and Integrity Security Accountability and Auditing Authority and Purpose Accountability, Audit, and Risk Management Data Quality and Integrity Data Minimization and Retention Individual Participation and Redress Security Transparency Use Limitation NIST SP 800-53, Appendix JUSG FIPPs
6
NISTIR NIST Process 2015 6 Workshop 2 Sep 2014 Draft Proposal for Objectives and Risk Model Aug 2014 Workshop 1 April 2014
7
Draft Privacy Engineering Objectives The objectives are characteristics or properties of the system. The objectives support policy Part of broader risk management framework, including security, etc. 7 Predictability Manageability Unlinkability or Obscurity?
8
Security Risk Equation 8 Security Risk = Vulnerability * Threat * Impact
9
Identifying System Privacy Risk 9 Privacy Risk Likelihood of Problemati c Data Actions Impact Personal Informatio n Contex t Data Actions
10
Frame Business Objectives Frame Org Privacy Governance Assess System Design Assess Privacy Risk Design Privacy Controls Monitor Change
11
Resources NIST website: http://csrc.nist.gov/projects/privacy_engineering/index.html 11
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.