privacy and Data protection(cloud privacy and security)

profileSangeeth08
ITC568_201860_Wk6_DataAndPrivacy_1.pptx

ITC568 Cloud Privacy and Security

Privacy, Data and Jurisdiction

Week 6

Dr Peter White

© Peter White, 2017

1

Evaluate the privacy requirements for digital identities

Evaluate the privacy requirements for data

Evaluate data for sensitivity, location and jurisdictional issues

Agenda

© Peter White, 2017

2

What is PII data:

“any information about an individual maintained by an agency, including any information that can be used to distinguish or trace an individual‘s identity, such as name, social security number, date and place of birth, mother‘s maiden name, or biometric records; and any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information”

PII data

McCalister, E., Grance, T., & Scarfone, K. (2010). Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) Gaithersburg, MD: National Institute of Standards and Technology Retrieved from: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-122.pdf

© Peter White, 2017

3

What is PII data:

Name, such as full name, maiden name, mother‘s maiden name, or alias

Personal identification number, such as tax file number (TFN) , passport number, driver‘s license number, or financial account or credit card number

Address information, such as street address or email address

Personal characteristics, including:

photographic image (especially of face or other identifying characteristic),

fingerprints, handwriting, or other biometric data (e.g., retina scan, voice signature, facial geometry)

Information about an individual that is linked or linkable to one of the above:

date of birth, place of birth,

race,

religion,

activities, geographical indicators,

Information about employment, medical condition, & treatments, weight, education and financial affairs

PII Data

© Peter White, 2017

4

Steps to protect PII data;

Identify all PII data held in the organisation

Minimise the collection, use and retention of PII to what is strictly necessary to accomplish the business aim

Categorise all PII data by their confidentiality impact level

Apply appropriate safeguards for PII based on confidentiality impact levels

Develop an incident response plan for PII data breaches

PII Data

© Peter White, 2017

5

PII:

any information about an individual that can be used to distinguish or trace an individual‘s identity,

any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.

To distinguish an individual is to identify an individual.

Examples of information that could identify an individual include, but are not limited to, name, passport number, tax file number, or biometric data.

But, a list containing only credit scores without any additional information concerning the individuals to whom they relate does not provide sufficient information to distinguish a specific individual.

To trace an individual is to process sufficient information to make a determination about a specific aspect of an individual‘s activities or status.

For example, an audit log containing records of user actions could be used to trace an individual‘s activities.

Linked information is information about or related to an individual that is logically associated with other information about the individual.

Linkable information is information about or related to an individual for which there is a possibility of logical association with other information about the individual.

For example, if two databases contain different PII elements, then someone with access to both databases may be able to link the information from the two databases and identify individuals, as well as access additional information about or relating to the individuals

© Peter White, 2017

6

PII data

What PII data is being held in the organisation:

Systems:

LoB systems?

CRM systems?

Corporate systems and databases?

Partners & contractors?

Locations?

Internal data centre

Remote data centres (DR & BCP sites)

Cloud

Partner/contractor data centres

© Peter White, 2017

7

Identify all PII data

Collection limits

Collect only appropriate data with lawful consent

Data quality

Relevant to the purpose, accurate, complete & up to date

Purpose

The purpose for the use of PII data should be specified at the time of collection and only used for those purposes

Use limitation

Personal data should not be disclosed, made available or otherwise used for purposes other than those specified, except with the consent of the data subject or by the authority of law

Security safeguards

Personal data should be protected against such risks as loss or unauthorised access, destruction, use, modification or disclosure of data.

© Peter White, 2017

8

Minimise the collection, use and retention of PII

Openness

Means should be readily available of establishing the existence and nature of personal data, and the main purposes of their use, as well as the identity of the data controller

Individual Participation

An individual should have the right:

To obtain from a data controller, or otherwise, confirmation of whether or not the data controller has data relating to him;

To be able to access data relating to him within a reasonable time;

at a charge, if any, that is not excessive;

in a reasonable manner; and

in a form that is readily intelligible to him;

To be given reasons if a request for data access is denied, and to be able to challenge such denial; and

To challenge data relating to him and, if the challenge is successful, to have the data erased, rectified, completed, or amended.

Accountability

A data controller should be accountable for complying with measures which give effect to the principles stated above.

© Peter White, 2017

9

Minimise the collection, use and retention of PII

Low Medium High
Loss of confidentiality, integrity, or availability expected to have a LIMITED ADVERSE EFFECT on organizational operations, assets, or individuals. Loss of confidentiality, integrity, or availability expected to have a SERIOUS ADVERSE EFFECT on organizational operations, assets, or individuals. Loss of confidentiality, integrity, or availability expected to have a SEVERE OR CATASTROPHIC ADVERSE EFFECT on organizational operations, assets, or individuals.

© Peter White, 2017

10

Confidentiality Impact Levels

Identifiability

Can the PII data directly identify individuals, or does it only provide indirect identification?

PII that is uniquely & directly identifiable may require a higher impact level

Quantity of PII data

How many individuals are identified in the data?

Do you set a high impact level for a large data set?

Do you set a low impact for a small data set?

Also consider cost of addressing a breach and reputational damage

Data field sensitivity

Each PII data field may have a different sensitivity

Are medical fields more sensitive than a postcode?

Certain combinations of PII data may be more sensitive, e.g. name, address, credit card number

Data fields may be more sensitive when used in a different context, e.g. parents middle name may be used as an authentication factor

© Peter White, 2017

11

Confidentiality Impact Level Factors

Context of use

E.g. statistical analysis, eligibility claims, benefits administration, law enforcement, financial transactions, subscriptions, etc.

The same types of PII may have different confidentiality levels depending on context

List of subscribers to a newsletter

List of people eligible for a government benefit

List of people who work undercover in law enforcement

Obligation to protect confidentiality

Legislation and regulations

Access to and location of PII

Where is the data stored?

What access to PII data is available?

Is access available to remote devices, web sites, other systems, or systems outside direct organisational control (partners & contractors?)

Is PII data stored on backups and in archives?

© Peter White, 2017

12

Confidentiality Impact Level Factors

Operational safeguards

Policy & Procedures

Access rules for PII

PII retention schedules & procedures

PII Incident response & data breach notification

Privacy in the systems development lifecycle

Use of Interconnection Security Arrangements

Ensure partners abide by rules for handling, disclosing, sharing, transmitting, retaining and use of the PII held

Consequences for failure to follow privacy rules

Awareness, Training and Education

What is PII

Applicable privacy laws, regulations, and policies

Restrictions on data collection, storage, and use of PII

Roles and responsibilities for using and protecting PII

Appropriate disposal of PII

Sanctions for misuse of PII

Recognition of a security or privacy incident involving PII

Retention schedules for PII

Roles and responsibilities in responding to PII related incidents and reporting.

© Peter White, 2017

13

PII Safeguards

Privacy specific safeguards:

Minimise the use, collection and retention of PII

Conduct regular privacy impact assessments

What information is to be collected

Why the information is being collected

The intended use of the information

With whom the information will be shared

How the information will be secured

De-identify information

Records that have had identifying information removed or obscured so that it can’t identify an individual

De-identified information is often used in research and statistical analysis to determine trends or patterns

De-identified information can be re-identified through the use of a code, algorithm or pseudonym that is assigned to an individual record

The re-identification algorithm, code, or pseudonym is maintained in a separate system, with appropriate controls in place to prevent unauthorized access to the re-identification information.

The data elements are not linkable, via public records or other reasonably available external records, in order to re-identify the data

© Peter White, 2017

14

PII Safeguards

Privacy specific safeguards:

Anonymising information

Anonymised information is previously identifiable information that has been de-identified and for which a code or other association for re-identification no longer exists

Anonymising techniques include:

Generalizing the Data — Making information less precise, such as grouping continuous values

Suppressing the Data — Deleting an entire record or certain parts of records

Introducing Noise into the Data — Adding small amounts of variation into selected data

Swapping the Data — Exchanging certain data fields of one record with the same data fields of another similar record (e.g., swapping the postcodes of two records)

Replacing Data with the Average Value — Replacing a selected value of data with the average value for the entire group of data.

© Peter White, 2017

15

PII Safeguards

Security controls

Access Enforcement

Separation of Duties

Least Privilege

Remote Access

User-Based Collaboration and Information Sharing

Access Control for Mobile Devices

Auditable Events

Audit Review, Analysis, and Reporting

Identification and Authentication (Organisational Users, partners, etc.)

Media Access

Media Marking

Media Storage

Media Transport

Media Sanitization

Transmission Confidentiality

Protection of Information at Rest

Information System Monitoring

© Peter White, 2017

16

PII Safeguards

Handling incidents and breaches involving PII is different from regular incident handling and may require additional actions by an organisation

Breaches involving PII can receive considerable media attention, which can greatly harm an organisation‘s reputation and reduce the public‘s trust in the organisation.

Moreover, affected individuals can be subject to embarrassment, identity theft, or blackmail as the result of a breach involving PII

Preparation

The development of response plans for breaches involving PII requires organisations to make many decisions about how to handle breaches involving PII

These decisions should be used to develop policies and procedures.

The policies and procedures should be communicated to the organisation‘s entire staff through training and awareness programs.

Training may include tabletop exercises to simulate an incident and test whether the response plan is effective and whether the staff members understand and are able to perform their roles effectively

Training programs should also inform employees of the consequences of their actions for inappropriate use and handling of PII

© Peter White, 2017

17

PII Incident Response Plan

Information needed:

Person reporting the incident

Person who discovered the incident

Date and time the incident was discovered

Nature of the incident

Name of system and possible interconnectivity with other systems

Description of the information lost or compromised

Storage medium from which information was lost or compromised

Controls in place to prevent unauthorised use of the lost or compromised information

Number of individuals potentially affected

Whether law enforcement was contacted

The plan may also need:

Whether breach notification to affected individuals is required

Timeliness of the notification

Source of the notification

Contents of the notification

© Peter White, 2017

18

PII Incident Response Plan

Incident procedure:

Detection and analysis

Normal incident procedures may require amendment including:

Evaluation of PII data involvement

PII data breach reporting requirements

Containment, eradication and recovery

Normal incident procedures may require amendment including:

Determine size of PII breach (how many records involved?)

Additional forensic techniques

Additional media sanitisation

Post-incident activity

Update incident response plan

Update additional security controls, procedures, policies, procedures and training

© Peter White, 2017

19

PII Incident Response Plan

Read:

McCalister, E., Grance, T., & Scarfone, K. (2010). Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) Gaithersburg, MD: National Institute of Standards and Technology Retrieved from: http:// nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-122.pdf

Then read:

King, N., & Raja, V. (2012). Protecting the privacy and security of sensitive customer data in the cloud. Computer Law and Security Review, 28(2012), 308-319. https ://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2012.03.003

Svantesson, D., & Clarke, R. (2010). Privacy and consumer risks in cloud computing. Computer Law and Security Review, 26(2010), 391-397.  https://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2010.05.005

Adrian, A. (2013). How much privacy do clouds provide? An Australian perspective. Computer Law and Security Review, 29(2013), 48-57. https://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2012.11.010

Also, see the Editor-in-Chief's note about this article at https://ezproxy.csu.edu.au/login?url=http:// dx.doi.org/10.1016/j.clsr.2014.05.002

Watch:

Start watching the Bruce Schneier videos. They are about an hour long, but definitely worth watching

© Peter White, 2017

20

Tasks