privacy and Data protection(cloud privacy and security)
ITC568 Cloud Privacy and Security
Business Requirements and Jurisdiction
Week 4
Dr Peter White
Business requirements for data sensitivity
Legal and regulatory issues for data
Agenda
© Peter White, 2017
2
We will concentrate on the data that the enterprise has and collects.
Generally, this data may be categorised as:
Transactional - data that results from a transaction by or with the enterprise.
Financial - data that relates to the finances of the enterprise.
Strategic - data that relates to the strategic plans and decisions of the enterprise.
Personal - data that it holds about persons that it has dealings with. These can be customers, staff, contractors or employees of other enterprises that it deals with.
Confidential - data that it holds that it does not want to be publicly available. This may include such things as contracts, proposals, pricing data, documents under a Non Disclosure Agreement, or similar types of data.
Publicly available - data that the enterprise holds, or manages but makes freely available to members of the public.
Data
© Peter White, 2017
3
Which category of data needs some form of protection and why?
Transactional
Financial
Strategic
Personal
Confidential
Publicly available
Data protection
© Peter White, 2017
4
This will depend on your jurisdiction & the type of data that you hold
What is the jurisdiction of the organisation?
Where is it located?
Has it offices in more than one state?
Does it have offices in other countries?
Does it offer goods for sale in other countries?
What type of data is being held?
PII data?
Then a number of Privacy acts may apply
Which one takes priority?
Personal Financial data, such as credit card information
Payment Card Industry Data Security Standard (PCI DSS) compliance will be required
Corporate data
What protection is required?
Legislation and Regulation
© Peter White, 2017
5
APP 1 — Open and transparent management of personal information
APP 2 — Anonymity and pseudonymity
APP 3 — Collection of solicited personal information
APP 4 — Dealing with unsolicited personal information
APP 5 — Notification of the collection of personal information
APP 6 — Use or disclosure of personal information
APP 7 — Direct marketing
APP 8 — Cross-border disclosure of personal information
APP 9 — Adoption, use or disclosure of government related identifiers
APP 10 — Quality of personal information
APP 11 — Security of personal information
APP 12 — Access to personal information
APP 13 — Correction of personal information
© Peter White, 2017
6
Australian Privacy Principles
From: https://www.oaic.gov.au/agencies-and-organisations/guides/app-quick-reference-tool
Should enterprise data be classified?
Should data have a Dissemination Limiting Marker (DLM) showing the classification of each set of data?
Would that affect how the data is used?
Would it affect who could access the data?
How would it affect data movement within the enterprise?
© Peter White, 2017
7
Classification
© Peter White, 2017
8
Business Impact Guides
From: https://www.finance.nsw.gov.au/ict/sites/default/files/NSW%20Government%20Information%20Classification%20Labelling%20and%20Handling%20Guidelines%20V.2.2_0.pdf
Data Governance is “a system of decision rights and accountabilities for information-related processes, executed according to agreed-upon models which describe who can take what actions with what information, and when, under what circumstances, using what methods.”
Every data governance program will have essentially the same three-part mission :
to make/collect/align rules,
to resolve issues, and
to monitor/enforce compliance while providing ongoing support to Data Stakeholders.
© Peter White, 2017
9
Data Governance
From: http://www.datagovernance.com/the-basic-information/
An enterprise needs to move to formal Data Governance when one of four situations occur:
The enterprise gets so large that traditional management isn’t able to address data-related cross-functional activities.
The enterprise’s data systems get so complicated that traditional management isn’t able to address data-related cross-functional activities.
The enterprise’s Data Architects, SOA teams, or other horizontally-focused groups need the support of a cross-functional program that takes an enterprise (rather than siloed) view of data concerns and choices.
Regulation, compliance, or contractual requirements call for formal Data Governance.
© Peter White, 2017
10
Data Governance
Integrity
Data Governance participants will practice integrity with their dealings with each other; they will be truthful and forthcoming when discussing drivers, constraints, options, and impacts for data-related decisions.
Transparency
Data Governance and Stewardship processes will exhibit transparency; it should be clear to all participants and auditors how and when data-related decisions and controls were introduced into the processes.
Auditability
Data-related decisions, processes, and controls subject to Data Governance will be auditable; they will be accompanied by documentation to support compliance-based and operational auditing requirements.
© Peter White, 2017
11
Data Governance Principles
Accountability
Data Governance will define accountabilities for cross-functional data-related decisions, processes, and controls.
Stewardship
Data Governance will define accountabilities for stewardship activities that are the responsibilities of individual contributors, as well as accountabilities for groups of Data Stewards.
Checks-and-Balances
Data Governance will define accountabilities in a manner that introduces checks-and-balances between business and technology teams as well as between those who create/collect information, those who manage it, those who use it, and those who introduce standards and compliance requirements.
© Peter White, 2017
12
Data Governance Principles
Standardisation
Data Governance will introduce and support standardization of enterprise data.
Change Management
Data Governance will support proactive and reactive Change Management activities for reference data values and the structure/use of master data and metadata.
© Peter White, 2017
13
Data Governance Principles
What data NEEDS to be there?
What data has to be collected and stored?
Where will it be stored:
Database or file storage?
Location?
What protection does it need?
Encryption?
Private subnet?
What access control is in place?
© Peter White, 2017
14
Data protection in the Cloud
What can your Cloud provider offer?
https://aws.amazon.com/compliance/data-privacy-faq /
https://aws.amazon.com/security/security-resources /
Amazon Web Services. (2014). Using AWS in the context of Australian Privacy Considerations.
Amazon Web Services. (2014). Amazon Web Services: Overview of Security Processes.
Amazon Web Services. (2014). Amazon Web Services: Risk and Compliance.
Microsoft Corp. (2015). Microsoft Azure Network Security (3 ed.). Redmond, WA: Microsoft Corp.
© Peter White, 2017
15
CSP resources
Read:
The Data Governance institute, (n.d.), The Basic Information, Retrieved from http://www.datagovernance.com/the-basic-information /
The resource list on the next page
Watch the videos on data protection and data governance
Consider the free AWS course – AWS Security Fundamentals- https://aws.amazon.com/training/course-descriptions/security-fundamentals /
© Peter White, 2017
16
Tasks
Amazon Web Services. (2014, 27 November 2014). Using AWS in the context of Australian Privacy Considerations. Retrieved from http:// d0.awsstatic.com/whitepapers/compliance/Using_AWS_in_the_context_of_Australian_Privacy_Considerations.pdf
Amazon Web Services. (2014). Amazon Web Services: Overview of Security Processes. Retrieved from https:// media.amazonwebservices.com/pdf/AWS_Security_Whitepaper.pdf
Amazon Web Services. (2014). Amazon Web Services: Risk and Compliance. Retrieved from http:// d0.awsstatic.com/whitepapers/compliance/AWS_Risk_and_Compliance_Whitepaper.pdf
Office of the Australian Information Commissioner. (2017). Privacy Management Framework: enabling compliance and encouraging good practice. Sydney Retrieved from https://www.oaic.gov.au/agencies-and-organisations/guides/privacy-management-framework.
Office of the Australian Information Commissioner. (2015). Guide to securing personal information. Sydney Retrieved from https://www.oaic.gov.au/agencies-and-organisations/guides/guide-to-securing-personal-information.
© Peter White, 2017
17
Resources