privacy and Data protection(cloud privacy and security)
ITC568 Cloud Privacy and Security
Privacy, Data and Jurisdiction
Week 6
Dr Peter White
© Peter White, 2017
1
Evaluate the privacy requirements for digital identities
Evaluate the privacy requirements for data
Evaluate data for sensitivity, location and jurisdictional issues
Agenda
© Peter White, 2017
2
What is PII data:
“any information about an individual maintained by an agency, including any information that can be used to distinguish or trace an individual‘s identity, such as name, social security number, date and place of birth, mother‘s maiden name, or biometric records; and any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information”
PII data
McCalister, E., Grance, T., & Scarfone, K. (2010). Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) Gaithersburg, MD: National Institute of Standards and Technology Retrieved from: http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-122.pdf
© Peter White, 2017
3
What is PII data:
Name, such as full name, maiden name, mother‘s maiden name, or alias
Personal identification number, such as tax file number (TFN) , passport number, driver‘s license number, or financial account or credit card number
Address information, such as street address or email address
Personal characteristics, including:
photographic image (especially of face or other identifying characteristic),
fingerprints, handwriting, or other biometric data (e.g., retina scan, voice signature, facial geometry)
Information about an individual that is linked or linkable to one of the above:
date of birth, place of birth,
race,
religion,
activities, geographical indicators,
Information about employment, medical condition, & treatments, weight, education and financial affairs
PII Data
© Peter White, 2017
4
Steps to protect PII data;
Identify all PII data held in the organisation
Minimise the collection, use and retention of PII to what is strictly necessary to accomplish the business aim
Categorise all PII data by their confidentiality impact level
Apply appropriate safeguards for PII based on confidentiality impact levels
Develop an incident response plan for PII data breaches
PII Data
© Peter White, 2017
5
PII:
any information about an individual that can be used to distinguish or trace an individual‘s identity,
any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.
To distinguish an individual is to identify an individual.
Examples of information that could identify an individual include, but are not limited to, name, passport number, tax file number, or biometric data.
But, a list containing only credit scores without any additional information concerning the individuals to whom they relate does not provide sufficient information to distinguish a specific individual.
To trace an individual is to process sufficient information to make a determination about a specific aspect of an individual‘s activities or status.
For example, an audit log containing records of user actions could be used to trace an individual‘s activities.
Linked information is information about or related to an individual that is logically associated with other information about the individual.
Linkable information is information about or related to an individual for which there is a possibility of logical association with other information about the individual.
For example, if two databases contain different PII elements, then someone with access to both databases may be able to link the information from the two databases and identify individuals, as well as access additional information about or relating to the individuals
© Peter White, 2017
6
PII data
What PII data is being held in the organisation:
Systems:
LoB systems?
CRM systems?
Corporate systems and databases?
Partners & contractors?
Locations?
Internal data centre
Remote data centres (DR & BCP sites)
Cloud
Partner/contractor data centres
© Peter White, 2017
7
Identify all PII data
Collection limits
Collect only appropriate data with lawful consent
Data quality
Relevant to the purpose, accurate, complete & up to date
Purpose
The purpose for the use of PII data should be specified at the time of collection and only used for those purposes
Use limitation
Personal data should not be disclosed, made available or otherwise used for purposes other than those specified, except with the consent of the data subject or by the authority of law
Security safeguards
Personal data should be protected against such risks as loss or unauthorised access, destruction, use, modification or disclosure of data.
© Peter White, 2017
8
Minimise the collection, use and retention of PII
Openness
Means should be readily available of establishing the existence and nature of personal data, and the main purposes of their use, as well as the identity of the data controller
Individual Participation
An individual should have the right:
To obtain from a data controller, or otherwise, confirmation of whether or not the data controller has data relating to him;
To be able to access data relating to him within a reasonable time;
at a charge, if any, that is not excessive;
in a reasonable manner; and
in a form that is readily intelligible to him;
To be given reasons if a request for data access is denied, and to be able to challenge such denial; and
To challenge data relating to him and, if the challenge is successful, to have the data erased, rectified, completed, or amended.
Accountability
A data controller should be accountable for complying with measures which give effect to the principles stated above.
© Peter White, 2017
9
Minimise the collection, use and retention of PII
| Low | Medium | High |
| Loss of confidentiality, integrity, or availability expected to have a LIMITED ADVERSE EFFECT on organizational operations, assets, or individuals. | Loss of confidentiality, integrity, or availability expected to have a SERIOUS ADVERSE EFFECT on organizational operations, assets, or individuals. | Loss of confidentiality, integrity, or availability expected to have a SEVERE OR CATASTROPHIC ADVERSE EFFECT on organizational operations, assets, or individuals. |
© Peter White, 2017
10
Confidentiality Impact Levels
Identifiability
Can the PII data directly identify individuals, or does it only provide indirect identification?
PII that is uniquely & directly identifiable may require a higher impact level
Quantity of PII data
How many individuals are identified in the data?
Do you set a high impact level for a large data set?
Do you set a low impact for a small data set?
Also consider cost of addressing a breach and reputational damage
Data field sensitivity
Each PII data field may have a different sensitivity
Are medical fields more sensitive than a postcode?
Certain combinations of PII data may be more sensitive, e.g. name, address, credit card number
Data fields may be more sensitive when used in a different context, e.g. parents middle name may be used as an authentication factor
© Peter White, 2017
11
Confidentiality Impact Level Factors
Context of use
E.g. statistical analysis, eligibility claims, benefits administration, law enforcement, financial transactions, subscriptions, etc.
The same types of PII may have different confidentiality levels depending on context
List of subscribers to a newsletter
List of people eligible for a government benefit
List of people who work undercover in law enforcement
Obligation to protect confidentiality
Legislation and regulations
Access to and location of PII
Where is the data stored?
What access to PII data is available?
Is access available to remote devices, web sites, other systems, or systems outside direct organisational control (partners & contractors?)
Is PII data stored on backups and in archives?
© Peter White, 2017
12
Confidentiality Impact Level Factors
Operational safeguards
Policy & Procedures
Access rules for PII
PII retention schedules & procedures
PII Incident response & data breach notification
Privacy in the systems development lifecycle
Use of Interconnection Security Arrangements
Ensure partners abide by rules for handling, disclosing, sharing, transmitting, retaining and use of the PII held
Consequences for failure to follow privacy rules
Awareness, Training and Education
What is PII
Applicable privacy laws, regulations, and policies
Restrictions on data collection, storage, and use of PII
Roles and responsibilities for using and protecting PII
Appropriate disposal of PII
Sanctions for misuse of PII
Recognition of a security or privacy incident involving PII
Retention schedules for PII
Roles and responsibilities in responding to PII related incidents and reporting.
© Peter White, 2017
13
PII Safeguards
Privacy specific safeguards:
Minimise the use, collection and retention of PII
Conduct regular privacy impact assessments
What information is to be collected
Why the information is being collected
The intended use of the information
With whom the information will be shared
How the information will be secured
De-identify information
Records that have had identifying information removed or obscured so that it can’t identify an individual
De-identified information is often used in research and statistical analysis to determine trends or patterns
De-identified information can be re-identified through the use of a code, algorithm or pseudonym that is assigned to an individual record
The re-identification algorithm, code, or pseudonym is maintained in a separate system, with appropriate controls in place to prevent unauthorized access to the re-identification information.
The data elements are not linkable, via public records or other reasonably available external records, in order to re-identify the data
© Peter White, 2017
14
PII Safeguards
Privacy specific safeguards:
Anonymising information
Anonymised information is previously identifiable information that has been de-identified and for which a code or other association for re-identification no longer exists
Anonymising techniques include:
Generalizing the Data — Making information less precise, such as grouping continuous values
Suppressing the Data — Deleting an entire record or certain parts of records
Introducing Noise into the Data — Adding small amounts of variation into selected data
Swapping the Data — Exchanging certain data fields of one record with the same data fields of another similar record (e.g., swapping the postcodes of two records)
Replacing Data with the Average Value — Replacing a selected value of data with the average value for the entire group of data.
© Peter White, 2017
15
PII Safeguards
Security controls
Access Enforcement
Separation of Duties
Least Privilege
Remote Access
User-Based Collaboration and Information Sharing
Access Control for Mobile Devices
Auditable Events
Audit Review, Analysis, and Reporting
Identification and Authentication (Organisational Users, partners, etc.)
Media Access
Media Marking
Media Storage
Media Transport
Media Sanitization
Transmission Confidentiality
Protection of Information at Rest
Information System Monitoring
© Peter White, 2017
16
PII Safeguards
Handling incidents and breaches involving PII is different from regular incident handling and may require additional actions by an organisation
Breaches involving PII can receive considerable media attention, which can greatly harm an organisation‘s reputation and reduce the public‘s trust in the organisation.
Moreover, affected individuals can be subject to embarrassment, identity theft, or blackmail as the result of a breach involving PII
Preparation
The development of response plans for breaches involving PII requires organisations to make many decisions about how to handle breaches involving PII
These decisions should be used to develop policies and procedures.
The policies and procedures should be communicated to the organisation‘s entire staff through training and awareness programs.
Training may include tabletop exercises to simulate an incident and test whether the response plan is effective and whether the staff members understand and are able to perform their roles effectively
Training programs should also inform employees of the consequences of their actions for inappropriate use and handling of PII
© Peter White, 2017
17
PII Incident Response Plan
Information needed:
Person reporting the incident
Person who discovered the incident
Date and time the incident was discovered
Nature of the incident
Name of system and possible interconnectivity with other systems
Description of the information lost or compromised
Storage medium from which information was lost or compromised
Controls in place to prevent unauthorised use of the lost or compromised information
Number of individuals potentially affected
Whether law enforcement was contacted
The plan may also need:
Whether breach notification to affected individuals is required
Timeliness of the notification
Source of the notification
Contents of the notification
© Peter White, 2017
18
PII Incident Response Plan
Incident procedure:
Detection and analysis
Normal incident procedures may require amendment including:
Evaluation of PII data involvement
PII data breach reporting requirements
Containment, eradication and recovery
Normal incident procedures may require amendment including:
Determine size of PII breach (how many records involved?)
Additional forensic techniques
Additional media sanitisation
Post-incident activity
Update incident response plan
Update additional security controls, procedures, policies, procedures and training
© Peter White, 2017
19
PII Incident Response Plan
Read:
McCalister, E., Grance, T., & Scarfone, K. (2010). Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) Gaithersburg, MD: National Institute of Standards and Technology Retrieved from: http:// nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-122.pdf
Then read:
King, N., & Raja, V. (2012). Protecting the privacy and security of sensitive customer data in the cloud. Computer Law and Security Review, 28(2012), 308-319. https ://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2012.03.003
Svantesson, D., & Clarke, R. (2010). Privacy and consumer risks in cloud computing. Computer Law and Security Review, 26(2010), 391-397. https://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2010.05.005
Adrian, A. (2013). How much privacy do clouds provide? An Australian perspective. Computer Law and Security Review, 29(2013), 48-57. https://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2012.11.010
Also, see the Editor-in-Chief's note about this article at https://ezproxy.csu.edu.au/login?url=http:// dx.doi.org/10.1016/j.clsr.2014.05.002
Watch:
Start watching the Bruce Schneier videos. They are about an hour long, but definitely worth watching
© Peter White, 2017
20
Tasks