privacy and Data protection(cloud privacy and security)

profileSangeeth08
ITC568_201860_Wk5_BusinessRequirements.pptx

ITC568 Cloud Privacy and Security

Business Requirements and Jurisdiction

Week 4

Dr Peter White

Business requirements for data sensitivity

Legal and regulatory issues for data

Agenda

© Peter White, 2017

2

We will concentrate on the data that the enterprise has and collects.

Generally, this data may be categorised as:

Transactional - data that results from a transaction by or with the enterprise.

Financial - data that relates to the finances of the enterprise.

Strategic - data that relates to the strategic plans and decisions of the enterprise.

Personal - data that it holds about persons that it has dealings with. These can be customers, staff, contractors or employees of other enterprises that it deals with.

Confidential - data that it holds that it does not want to be publicly available. This may include such things as contracts, proposals, pricing data, documents under a Non Disclosure Agreement, or similar types of data.

Publicly available - data that the enterprise holds, or manages but makes freely available to members of the public.

Data

© Peter White, 2017

3

Which category of data needs some form of protection and why?

Transactional

Financial

Strategic

Personal

Confidential

Publicly available

Data protection

© Peter White, 2017

4

This will depend on your jurisdiction & the type of data that you hold

What is the jurisdiction of the organisation?

Where is it located?

Has it offices in more than one state?

Does it have offices in other countries?

Does it offer goods for sale in other countries?

What type of data is being held?

PII data?

Then a number of Privacy acts may apply

Which one takes priority?

Personal Financial data, such as credit card information

Payment Card Industry Data Security Standard (PCI DSS) compliance will be required

Corporate data

What protection is required?

Legislation and Regulation

© Peter White, 2017

5

APP 1 — Open and transparent management of personal information

APP 2 — Anonymity and pseudonymity

APP 3 — Collection of solicited personal information

APP 4 — Dealing with unsolicited personal information

APP 5 — Notification of the collection of personal information

APP 6 — Use or disclosure of personal information

APP 7 — Direct marketing

APP 8 — Cross-border disclosure of personal information

APP 9 — Adoption, use or disclosure of government related identifiers

APP 10 — Quality of personal information

APP 11 — Security of personal information

APP 12 — Access to personal information

APP 13 — Correction of personal information

© Peter White, 2017

6

Australian Privacy Principles

From: https://www.oaic.gov.au/agencies-and-organisations/guides/app-quick-reference-tool

Should enterprise data be classified?

Should data have a Dissemination Limiting Marker (DLM) showing the classification of each set of data?

Would that affect how the data is used?

Would it affect who could access the data?

How would it affect data movement within the enterprise?

© Peter White, 2017

7

Classification

© Peter White, 2017

8

Business Impact Guides

From: https://www.finance.nsw.gov.au/ict/sites/default/files/NSW%20Government%20Information%20Classification%20Labelling%20and%20Handling%20Guidelines%20V.2.2_0.pdf

Data Governance is “a system of decision rights and accountabilities for information-related processes, executed according to agreed-upon models which describe who can take what actions with what information, and when, under what circumstances, using what methods.”

Every data governance program will have essentially the same three-part mission :

to make/collect/align rules,

to resolve issues, and

to monitor/enforce compliance while providing ongoing support to Data Stakeholders.

© Peter White, 2017

9

Data Governance

From: http://www.datagovernance.com/the-basic-information/

An enterprise needs to move to formal Data Governance when one of four situations occur:

The enterprise gets so large that traditional management isn’t able to address data-related cross-functional activities.

The enterprise’s data systems get so complicated that traditional management isn’t able to address data-related cross-functional activities.

The enterprise’s Data Architects, SOA teams, or other horizontally-focused groups need the support of a cross-functional program that takes an enterprise (rather than siloed) view of data concerns and choices.

Regulation, compliance, or contractual requirements call for formal Data Governance.

© Peter White, 2017

10

Data Governance

Integrity

Data Governance participants will practice integrity with their dealings with each other; they will be truthful and forthcoming when discussing drivers, constraints, options, and impacts for data-related decisions.

Transparency

Data Governance and Stewardship processes will exhibit transparency; it should be clear to all participants and auditors how and when data-related decisions and controls were introduced into the processes.

Auditability

Data-related decisions, processes, and controls subject to Data Governance will be auditable; they will be accompanied by documentation to support compliance-based and operational auditing requirements.

© Peter White, 2017

11

Data Governance Principles

Accountability

Data Governance will define accountabilities for cross-functional data-related decisions, processes, and controls.

Stewardship

Data Governance will define accountabilities for stewardship activities that are the responsibilities of individual contributors, as well as accountabilities for groups of Data Stewards.

Checks-and-Balances

Data Governance will define accountabilities in a manner that introduces checks-and-balances between business and technology teams as well as between those who create/collect information, those who manage it, those who use it, and those who introduce standards and compliance requirements.

© Peter White, 2017

12

Data Governance Principles

Standardisation

Data Governance will introduce and support standardization of enterprise data.

Change Management

Data Governance will support proactive and reactive Change Management activities for reference data values and the structure/use of master data and metadata.

© Peter White, 2017

13

Data Governance Principles

What data NEEDS to be there?

What data has to be collected and stored?

Where will it be stored:

Database or file storage?

Location?

What protection does it need?

Encryption?

Private subnet?

What access control is in place?

© Peter White, 2017

14

Data protection in the Cloud

What can your Cloud provider offer?

https://aws.amazon.com/compliance/data-privacy-faq /

https://aws.amazon.com/security/security-resources /

Amazon Web Services. (2014). Using AWS in the context of Australian Privacy Considerations.

Amazon Web Services. (2014). Amazon Web Services: Overview of Security Processes.

Amazon Web Services. (2014). Amazon Web Services: Risk and Compliance.

Microsoft Corp. (2015). Microsoft Azure Network Security (3 ed.). Redmond, WA: Microsoft Corp.

© Peter White, 2017

15

CSP resources

Read:

The Data Governance institute, (n.d.), The Basic Information, Retrieved from http://www.datagovernance.com/the-basic-information /

The resource list on the next page

Watch the videos on data protection and data governance

Consider the free AWS course – AWS Security Fundamentals- https://aws.amazon.com/training/course-descriptions/security-fundamentals /

© Peter White, 2017

16

Tasks

Amazon Web Services. (2014, 27 November 2014). Using AWS in the context of Australian Privacy Considerations. Retrieved from http:// d0.awsstatic.com/whitepapers/compliance/Using_AWS_in_the_context_of_Australian_Privacy_Considerations.pdf

Amazon Web Services. (2014). Amazon Web Services: Overview of Security Processes. Retrieved from https:// media.amazonwebservices.com/pdf/AWS_Security_Whitepaper.pdf

Amazon Web Services. (2014). Amazon Web Services: Risk and Compliance. Retrieved from http:// d0.awsstatic.com/whitepapers/compliance/AWS_Risk_and_Compliance_Whitepaper.pdf

Office of the Australian Information Commissioner. (2017). Privacy Management Framework: enabling compliance and encouraging good practice. Sydney Retrieved from https://www.oaic.gov.au/agencies-and-organisations/guides/privacy-management-framework.

Office of the Australian Information Commissioner. (2015). Guide to securing personal information. Sydney Retrieved from https://www.oaic.gov.au/agencies-and-organisations/guides/guide-to-securing-personal-information.

© Peter White, 2017

17

Resources