using risk management to improve privacy in information systems 1

11
Using Risk Management to Improve Privacy in Information Systems 1

Upload: kristopher-hopkins

Post on 31-Dec-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Using Risk Management to Improve Privacy in Information Systems 1

1

Using Risk Management to Improve Privacy in Information Systems

Page 2: Using Risk Management to Improve Privacy in Information Systems 1

2

Potential Problems for Individuals

Loss of Self Determinati

on

Loss of AutonomyExclusionLoss of LibertyPhysical Harm

Loss of Trust

Discrimination

StigmatizationPower

Imbalance

Economic Loss

Page 3: Using Risk Management to Improve Privacy in Information Systems 1

3

Frame

Assess

Respond

Monitor

Page 4: Using Risk Management to Improve Privacy in Information Systems 1

Senior Management

Product Manager

4

Engineer

Controls

Objectives

Metrics

Governance

Risk Model

Risk Assessment

Requirements

System DesignEvaluation

Page 5: Using Risk Management to Improve Privacy in Information Systems 1

The Right Tool for the JobMany current privacy approaches are some mixture of governance principles, requirements and controls.

TransparencyIndividual ParticipationPurpose SpecificationData Minimization

Use LimitationData Quality and IntegritySecurityAccountability and Auditing

Authority and PurposeAccountability, Audit, and Risk ManagementData Quality and IntegrityData Minimization and Retention

Individual Participation and RedressSecurityTransparencyUse Limitation

NIST SP 800-53, Appendix J

USG FIPPs

Page 6: Using Risk Management to Improve Privacy in Information Systems 1

6

NISTIR

NIST Process

2015Worksho

p 2Sep

2014

Draft Proposal

for Objective

s and Risk

Model

Aug2014

Workshop 1

April 2014

Page 7: Using Risk Management to Improve Privacy in Information Systems 1

7

Draft Privacy Engineering Objectives• The objectives are characteristics or properties of the system.

• The objectives support policy

• Part of broader risk management framework, including security, etc.

Predictability

ManageabilityUnlinkability

orObscurity?

Page 8: Using Risk Management to Improve Privacy in Information Systems 1

8

Security Risk Equation

Security Risk = Vulnerability * Threat * Impact

Page 9: Using Risk Management to Improve Privacy in Information Systems 1

Identifying System Privacy Risk

9

Privacy Risk

Likelihood of

Problematic Data Actions

Impact

Personal Informati

on

Context

Data Action

s

Page 10: Using Risk Management to Improve Privacy in Information Systems 1

Frame Business

Objectives

Frame Org Privacy

Governance

Assess System Design

Assess Privacy

Risk

Design Privacy Controls

Monitor Change