<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>information Archives -</title>
	<atom:link href="https://zymitry.com/tag/information/feed/" rel="self" type="application/rss+xml" />
	<link>https://zymitry.com/tag/information/</link>
	<description>Tech &#38; Other Stuff</description>
	<lastBuildDate>Sun, 22 Mar 2026 00:20:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://i0.wp.com/zymitry.com/wp-content/uploads/2016/11/favicon.png?fit=32%2C32&#038;ssl=1</url>
	<title>information Archives -</title>
	<link>https://zymitry.com/tag/information/</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">120106411</site>	<item>
		<title>Security Policy Example &#8211; IRT Access &#038; Authorization Policy</title>
		<link>https://zymitry.com/policy-irt-access-authorization/</link>
					<comments>https://zymitry.com/policy-irt-access-authorization/#comments</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 27 Jan 2018 23:41:36 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[example]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=953</guid>

					<description><![CDATA[<p>Policy Example &#160; SunSpot Credit Union Computer Incident Response Team—Access &#38; Authorization Policy   1.0       Policy Statement This policy applies to SunSpot Credit Union employees, temporary workers, contractors, and consultants who use or access SunSpot Credit Union information systems and computers.   2.0       Purpose/Objectives Definitions for this policy are as follows: SunSpot Credit Union: (SCU).… <span class="read-more"><a href="https://zymitry.com/policy-irt-access-authorization/">Read More: Security Policy Example &#8211; IRT Access &#038; Authorization Policy &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/policy-irt-access-authorization/">Security Policy Example &#8211; IRT Access &#038; Authorization Policy</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Policy Example</strong></p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>SunSpot Credit Union</strong></p>
<p style="text-align: center;"><strong>Computer Incident Response Team—Access &amp; Authorization Policy</strong></p>
<p><strong> </strong></p>
<p><strong>1.0       Policy Statement</strong></p>
<p>This <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener noreferrer">policy</a> applies to SunSpot Credit Union employees, temporary workers, contractors, and consultants who use or access SunSpot Credit Union information systems and computers.</p>
<p><strong> </strong></p>
<p><strong>2.0       Purpose/Objectives</strong></p>
<p>Definitions for this <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener noreferrer">policy</a> are as follows:</p>
<ul>
<li>SunSpot Credit Union: (SCU).</li>
<li>Incident Response Team: (<a href="https://web.archive.org/web/20230322085647/https://zymitry.com/information-incident-response/" target="_blank" rel="noopener noreferrer">IRT</a>). Personnel designated to respond to security incidents.</li>
<li>Incident Response Policy: (<a href="https://zymitry.com/computer-incident-response-teams/" target="_blank" rel="noopener noreferrer">IRP</a>). Establishes Incident Response (IR) procedures for dealing with incidents related to technology and information risk.</li>
<li>Graham-Leach-Bliley Act: (<a href="https://www.ftc.gov/tips-advice/business-center/privacy-and-security/gramm-leach-bliley-act" target="_blank" rel="noopener noreferrer">GLBA</a>).</li>
<li>Chief Information Office: (<a href="https://zymitry.com/leaderships-role-information-security/" target="_blank" rel="noopener noreferrer">CIO</a>).</li>
<li>Information Security Officer: (<a href="https://zymitry.com/leaderships-role-information-security/" target="_blank" rel="noopener noreferrer">ISO</a>).</li>
</ul>
<p>This document establishes IRT membership, roles, responsibilities, and authority. IRT members and their authority are as follows:</p>
<ul>
<li>Information Security Officer (ISO): IRT team leader with authority over all SCU information systems in the event of a security incident. The ISO has the authority to perform any legal action necessary to protect SCU resources and private information, and customer personal and financial information.</li>
<li>Senior System Administrator: overall responsible for monitoring internal systems and configurations. Designated by the ISO authority to change configurations and take actions as required to protect SCU information resources and customer private and financial information in the event of a security incident. Has the authority to represent and communicate with law enforcement.</li>
<li>Network Administrator. Works closely with the Senior Systems Administrator. Granted the authority to take networks and systems offline if required to protect SCU information systems, and customer private and financial information.</li>
<li>Human Resources Director: Granted the authority manage staff regulation and law related matters that may result from a security incident.</li>
<li>Public Relations Director: Granted the authority to communicate with news and other public entities, stockholders, and other non-legal entities as dictated by the ISO.</li>
<li>Law Firm: The authority to conduct legal matters related to security incidents per direction of the ISO. Has the authority to represent and communicate with law enforcement.</li>
</ul>
<p><strong> </strong></p>
<p><strong>3.0       Scope</strong></p>
<p>This policy applies to all SCU security domain areas to include computers and devices, SCU system users, security detection systems, firewalls, remote access <a href="https://zymitry.com/vpn-security-monitoring-controls/" target="_blank" rel="noopener noreferrer">VPN</a> software and hardware, and applications, that are controlled and operated by SCU staff or its designated IT Infrastructure Implementation Agents, contractors, and vendors, throughout at all branches of SCU, SCU Enterprise Cloud, Web, and Data Center providers, and other offsite facilities.</p>
<p><strong> </strong></p>
<p><strong>4.0       Standards</strong></p>
<p>Require compliance with section 501(b) of the <a href="https://www.ftc.gov/tips-advice/business-center/privacy-and-security/gramm-leach-bliley-act" target="_blank" rel="noopener noreferrer">Gramm-Leach-Bliley Act (GLB Act</a>).4 and section 216 of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act).5 The Security Guidelines establish standards relating to administrative, technical, and physical safeguards to ensure the security, confidentiality, integrity and the proper disposal of customer information. Specific standards are as follows:</p>
<ul>
<li>Develop and maintain an effective information security program.</li>
<li>Ensure the security of customer information at all times.</li>
<li>Procedures for notifying customers of confirmed or suspected private information exposure.</li>
</ul>
<p><strong> </strong></p>
<p><strong>5.0       Procedures</strong></p>
<p>Responsible IRT members must consider <a href="https://www.ftc.gov/tips-advice/business-center/privacy-and-security/gramm-leach-bliley-act" target="_blank" rel="noopener noreferrer">GLBA</a> standards when responding to incidents. The ISO is responsible for overseeing the development, implementation, and maintenance of this policy. The CIO is responsible for enforcing this policy. The SCU incident response model is as follows:</p>
<ol>
<li>Incident detection. The Senior System Administrator and Network Administrator are responsible for monitoring Intrusion Detection and Prevention Systems (<a href="https://zymitry.com/ids-idps-detection-methods/" target="_blank" rel="noopener noreferrer">IDS/IDPS</a>), system logs, and maintain communications with the help desk in order to detect possible security incidents. If a possible incident is detected, they will notify the ISO who will determine if the IRT needs to be activated.</li>
<li>The ISO will direct team members to implement additional control configurations to stop an attack, secure systems, and begin collecting evidence. Per SCU IRP, the ISO will issue evidence bags, make available electronic collection media, and chain of custody forms. All evidence will be collected and chain of custody maintained per the SCU IRP standards. The ISO and CSU law firm will monitor evidence collection procedures.</li>
<li>After evidence collection is complete or to a point where normal operations will not interfere with collection, the ISO will direct team member to recover systems per SCU IRP, Business Continuity Plans (BIA)’s, and other applicable SCU technical and administrative publications and policies.</li>
<li>Conduct analysis and debrief. At the ISO direction, the IRT will meet to discuss, evaluate, and make recommendations to prevent future incidents.</li>
<li>The ISO will be responsible for constructing and disseminating an incident report based on the IRT analysis of the incident. The report is to be used by HR, the Public Relations Director, and retained law firm for communicating details of the incident and make decisions on possible disciplinary or legal action.</li>
<li>Process improvement. Policy updates and additional training as required are to be implemented per the SCU IRP and training policy.</li>
</ol>
<p>&nbsp;</p>
<p><strong>6.0       Guidelines</strong></p>
<p>In the course of business it is inevitable that situations will arise that policy does not specifically address. Guidelines for these issues are as follows:</p>
<ul>
<li>Unforeseen security events or conflicts in procedures are to be referred to the ISO for guidance. In the event that the ISO is unavailable, the Senior System Administrator or CIO, dependent on the most senior present, will fulfill the ISO duties.</li>
</ul>
<p>&nbsp;</p>
<p><strong>7.0       Policy Enforcement and Violations</strong></p>
<p>Violations of this policy will be addressed in accordance relevant SCU information security and human resource policies. The appropriate level of disciplinary action will be determined on an individual case basis by the appropriate executive or designee, with sanctions up to or including termination depending upon the severity of the offense. The ISO is responsible for official interpretation of this policy. Questions regarding the application of this policy should be directed to the SCU Information Technology department.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="https://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></p>
<p>The post <a href="https://zymitry.com/policy-irt-access-authorization/">Security Policy Example &#8211; IRT Access &#038; Authorization Policy</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/policy-irt-access-authorization/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">953</post-id>	</item>
		<item>
		<title>IT &#038; Security Framework and Policy Development Team</title>
		<link>https://zymitry.com/framework-policy-development-team/</link>
					<comments>https://zymitry.com/framework-policy-development-team/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Tue, 23 Jan 2018 01:05:31 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[development]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[roles]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[team]]></category>
		<category><![CDATA[technology]]></category>
		<guid isPermaLink="false">https://zymitry.com/?p=890</guid>

					<description><![CDATA[<p>The IT security policy framework is the foundation of an organizations information security program. The framework consists of a library of documents, but is just not a collection of documents. The framework and its documents are used to build an organizations processes, determine appropriate technologies to use, and lay the foundation for policy enforcement. The… <span class="read-more"><a href="https://zymitry.com/framework-policy-development-team/">Read More: IT &#038; Security Framework and Policy Development Team &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/framework-policy-development-team/">IT &#038; Security Framework and Policy Development Team</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The IT security <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> framework is the foundation of an organizations information security program. The framework consists of a library of documents, but is just not a collection of documents. The framework and its documents are used to build an organizations processes, determine appropriate technologies to use, and lay the foundation for policy enforcement. The framework is a way for management to communicate the importance of information security to the rest of the organization.</p>
<p>Typical business areas commonly involved with <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> framework include; development, maintenance, and compliance. Some of the common roles associated with <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> framework include; Chief Information Security Officer (<a href="https://zymitry.com/leaderships-role-information-security/" target="_blank" rel="noopener">CISO</a>), Information Resources Manager, and Security Manager.</p>
<p>The SANS Reading Room publication; Information Security Policy &#8211; A Development Guide for Large and Small Companies, describes a guideline rather than specific roles.  The guideline describes a two-part structure consisting of primary involvement members, and secondary involvement members.</p>
<p>Primary Involvement:</p>
<ul>
<li>Information Security Team. The team or parts of the team should be assigned overall responsibility for developing framework, and policies. Overall control is normally given to a designated member with others in supporting roles as needed. The primary team guides <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> framework and <a href="https://zymitry.com/security-policies-standards-procedures/" target="_blank" rel="noopener">policy</a> from development through to revision as the cycle dictates.</li>
<li>Technical Writers(s). Many companies have technical writers on staff. Even though they probably will not take an active role in development, they can be an invaluable resource when it comes to planning and structure of the project.</li>
</ul>
<p>Secondary Involvement:</p>
<ul>
<li><a href="https://zymitry.com/computer-incident-response-teams/" target="_blank" rel="noopener">Technical Staff</a>: In addition to <a href="https://zymitry.com/developing-effective-red-team/" target="_blank" rel="noopener">security staff</a>, it is probable that expertise from other areas will be needed. Staff from these areas will have in-depth knowledge of day-to-day operations, and knowledgeable of technical issues in their areas.</li>
<li>Legal Counsel should review policy documents when complete. They can also provide guidance on industry <a href="https://zymitry.com/online-terms-service-contract-law/" target="_blank" rel="noopener">regulations</a> such as the Health Information Portability and Accountability Act (<a href="https://zymitry.com/health-information-privacy-complaint/" target="_blank" rel="noopener">HIPAA</a>), and Sarbanes Oxley (<a href="https://zymitry.com/section-409-sarbanes-oxley-act-sox/" target="_blank" rel="noopener">SOX</a>).</li>
<li>Human Resources (HR) should also review all policies to ensure they comply with company HR policies.</li>
<li>Audit and Compliance. Departments responsible for internal audits will likely be involved in monitoring policies. They should be involved in the development of frameworks and policies to ensure that they are enforceable.</li>
<li>User Groups. During revision stages users can provide a good indication on how successful a policy has been, and what parts might need revision. They often notice where improvements can be made in style, layout, and wording.</li>
</ul>
<p>References</p>
<p>Diver, S. (06, July 12).<em> Information Security Policy &#8211; A Development Guide for Large and Small Companies. </em>Retrieved September 7, 2017, from <a href="https://www.sans.org/reading-room/whitepapers/policyissues/information-security-policy-development-guide-large-small-companies-1331" target="_blank" rel="noopener">https://www.sans.org/reading-room/whitepapers/policyissues/information-security-policy-development-guide-large-small-companies-1331</a>.</p>
<p>The post <a href="https://zymitry.com/framework-policy-development-team/">IT &#038; Security Framework and Policy Development Team</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/framework-policy-development-team/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">890</post-id>	</item>
		<item>
		<title>Security+ SY0-401 General Information &#038; Characteristics</title>
		<link>https://zymitry.com/security-plus-general-information/</link>
					<comments>https://zymitry.com/security-plus-general-information/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Mon, 12 Dec 2016 18:17:10 +0000</pubDate>
				<category><![CDATA[Security+ SY0-401]]></category>
		<category><![CDATA[about]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[objectives]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=393</guid>

					<description><![CDATA[<p>Security+ General Information The CompTIA Security+ Certification is often a first step towards more advanced security certifications. &#160; About The CompTIA Security+ certification is a vendor-neutral, internationally recognized credential used by organizations and security professionals around the globe to validate foundation level security skills and knowledge. Candidates are encouraged to use this document to help prepare… <span class="read-more"><a href="https://zymitry.com/security-plus-general-information/">Read More: Security+ SY0-401 General Information &#038; Characteristics &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/security-plus-general-information/">Security+ SY0-401 General Information &#038; Characteristics</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2>Security+ General Information</h2>
<p>The CompTIA Security+ Certification is often a first step towards more advanced security certifications.</p>
<p>&nbsp;</p>
<h3>About</h3>
<p>The CompTIA Security+ certification is a vendor-neutral, internationally recognized credential used by organizations and security professionals around the globe to validate foundation level security skills and knowledge. Candidates are encouraged to use this document to help prepare for CompTIA  security+ SY0-401, which measures necessary skills for IT security professionals. These content examples are meant to clarify the test objectives and should not be construed as a comprehensive listing of all content in this examination. Successful candidates will have the knowledge required to:</p>
<p style="padding-left: 30px;">• Identify risk<br />
• Participate in risk mitigation activities<br />
• Provide infrastructure, application, information and operational security<br />
• Apply security controls to maintain confidentiality, integrity and availability<br />
• Identify appropriate technologies and products<br />
• Troubleshoot security events and incidents<br />
• Operate with an awareness of applicable policies, laws and regulations</p>
<p>EXAM ACCREDITATION: CompTIA Security+ is accredited by ANSI to show compliance with the ISO 17024 Standard and, as such, the exam objectives undergo regular reviews and updates.<br />
EXAM DEVELOPMENT: CompTIA exams result from subject matter expert workshops and industry-wide survey results regarding the skills and knowledge required of an IT professional.</p>
<p>&nbsp;</p>
<h3>What this information is not</h3>
<p>There are no test questions to be found here. All information contained on this site is readily available through various print and internet sources. The information published on this site is provided strictly for the purpose of assisting in preparing for the Security + Certification exam. The information provided is accurate and up-to-date to the best of my knowledge at the date it was published. Zymitry does not offer any guarantee or warranty to its accuracy. Use this information at your own risk. See full <a href="https://zymitry.com/zymitry-disclaimer/" target="_blank" rel="noopener">Disclaimer</a>.</p>
<p>&nbsp;</p>
<h3>Current Version</h3>
<p>As of December, 2016, the current Security+ version is Security+ SY0-401. There is speculation that version <a href="https://web.archive.org/web/20210621001736/https://www.certblaster.com/difference-comptia-security-plus-sy0-401-sy0-501/" target="_blank" rel="noopener">Security+ SY0-501</a> should be released December, 2017.</p>
<p>&nbsp;</p>
<h3>General Characteristics</h3>

<table id="tablepress-1" class="tablepress tablepress-id-1">
<tbody class="row-hover">
<tr class="row-1">
	<td class="column-1">Exam Description</td><td class="column-2">CompTIA Security+ certification covers network security, compliance and operation security, threats and vulnerabilities as well as application, data and host security. Also included are access control, identity management, and cryptography.</td>
</tr>
<tr class="row-2">
	<td class="column-1">Type of Questions</td><td class="column-2">Multiple choice and <a href="https://certification.comptia.org/testing/about-testing/performance-based-questions-explained" target="_blank">performance-based</a></td>
</tr>
<tr class="row-3">
	<td class="column-1">Recommended Experience</td><td class="column-2">CompTIA Network+ and two years of experience in IT administration with a security focus</td>
</tr>
<tr class="row-4">
	<td class="column-1">Passing Score</td><td class="column-2">750 (on a scale of 100-900)</td>
</tr>
<tr class="row-5">
	<td class="column-1">Number of Questions</td><td class="column-2">Maximum of 90 questions</td>
</tr>
<tr class="row-6">
	<td class="column-1">Length of Test</td><td class="column-2">90 Minutes</td>
</tr>
<tr class="row-7">
	<td class="column-1">Languages</td><td class="column-2">English, Japanese and Portuguese</td>
</tr>
</tbody>
</table>

<p>&nbsp;</p>
<h3>Hierarchy and Presentation</h3>
<p>The provided information is broken out into domains defined by CompTIA. Each domain is then broken down further into detailed categories and sub-categories covering all areas specified by CompTIA.</p>
<p>CompTIA Security+ Certification Domains:</p>
<ul>
<li>Network Security</li>
<li>Compliance and Operational Security</li>
<li>Threats and Vulnerabilities</li>
<li>Application, Data and Host Security</li>
<li>Access Control and Identity Management</li>
<li>Cryptography</li>
</ul>
<p>&nbsp;</p>
<h3>Acronyms</h3>
<p>Acronyms used in this material can be found <a href="https://zymitry.com/security-terms-acronyms/" target="_blank" rel="noopener">here</a>.</p>
<p>&nbsp;</p>
<p>References</p>
<p>CompTIA Security+ <a href="https://web.archive.org/web/20191001010520/https://certification.comptia.org/certifications/security" target="_blank" rel="noopener">General Information</a></p>
<p>CompTIA Security+ <a href="http://www.comptia.jp/pdf/comptia-security-sy0-401.pdf" target="_blank" rel="noopener">Certification Exam Objectives</a></p>
<p>&nbsp;</p>
<p>The post <a href="https://zymitry.com/security-plus-general-information/">Security+ SY0-401 General Information &#038; Characteristics</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/security-plus-general-information/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">393</post-id>	</item>
		<item>
		<title>Ethics Related to the Collection of Information</title>
		<link>https://zymitry.com/ethics-related-collection-information/</link>
					<comments>https://zymitry.com/ethics-related-collection-information/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 26 Nov 2016 23:37:34 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[accessibility]]></category>
		<category><![CDATA[accuracy]]></category>
		<category><![CDATA[availability]]></category>
		<category><![CDATA[categorization]]></category>
		<category><![CDATA[CIA security concept]]></category>
		<category><![CDATA[CIA triad]]></category>
		<category><![CDATA[collection]]></category>
		<category><![CDATA[confidentiality]]></category>
		<category><![CDATA[data amendment]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[information systems]]></category>
		<category><![CDATA[information usage]]></category>
		<category><![CDATA[integrity]]></category>
		<category><![CDATA[ownership]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[system availability]]></category>
		<guid isPermaLink="false">http://zymitry.com/?p=301</guid>

					<description><![CDATA[<p>Ethical considerations play a vital role in the design of information systems, particularly in relation to the Confidentiality, Integrity, Availability (CIA) security concept. This article explores various ethical issues that must be addressed in information system design and their relevance to the CIA security triad. It delves into concerns such as the beneficiaries of collected information, privacy and confidentiality of user data, accuracy of information, property and ownership rights, accessibility controls, the purpose of information usage, system availability, and categorization for maintaining integrity. Understanding and addressing these ethical aspects is crucial for ensuring the responsible and secure handling of information within organizations.</p>
<p>The post <a href="https://zymitry.com/ethics-related-collection-information/">Ethics Related to the Collection of Information</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h1>Ethics Related to the Collection of Information</h1>
<p>&nbsp;</p>
<p><strong>Ethics Related to the Collection of Information</strong></p>
<p><em>Revised July 01, 2023</em></p>
<p>When designing information systems, it is crucial to address various ethical considerations that relate to the Confidentiality, Integrity, Availability (CIA) security concept. The following points provide an overview of these ethical concerns and their relevance to the CIA security triad:</p>
<ol>
<li>
<h4>Benefit of Information Collection:</h4>
<ul>
<li>Confidentiality: Determine who benefits from the information collected and ensure appropriate confidentiality measures are in place.</li>
<li>Policies and Restrictions: Implement policies and restrictions that control how the collected information will be used and ensure compliance.</li>
</ul>
</li>
<li>
<h4>Privacy and Confidentiality:</h4>
<ul>
<li>Confidentiality: Protect users&#8217; personal information and maintain its confidentiality.</li>
<li>User Consent: Inform users about how their information will be used and obtain explicit consent.</li>
<li>Transparency: Provide clear and accurate explanations of how collected information will be utilized to avoid misleading users.</li>
</ul>
</li>
<li>
<h4>Accuracy of Information:</h4>
<ul>
<li>Integrity: Ensure the accuracy and integrity of information by implementing data validation and verification mechanisms.</li>
<li>User Responsibility: While users may input information, organizations still hold responsibility for maintaining accurate data, especially in critical domains like healthcare.</li>
</ul>
</li>
<li>
<h4>Property and Ownership:</h4>
<ul>
<li>Confidentiality and Integrity: Respect copyright and ownership rights associated with information.</li>
<li>Permission and Use: Determine if alteration or use of copyrighted material is allowed and abide by the associated restrictions.</li>
</ul>
</li>
<li>
<h4>Accessibility:</h4>
<ul>
<li>Confidentiality, Integrity, and Availability: Implement controls to restrict access to authorized users only.</li>
<li>Data Amendments: Establish mechanisms to control data amendments and ensure data integrity.</li>
<li>Availability: Ensure consistent and reliable access to information for authorized users.</li>
</ul>
</li>
<li>
<h4>Purpose and Extensiveness of Information Use:</h4>
<ul>
<li>Confidentiality: Define the intended purpose of information use and establish boundaries to prevent unauthorized utilization.</li>
<li>Limitations: Avoid using information beyond its intended purpose without proper consent or legal authorization.</li>
</ul>
</li>
<li>
<h4>System Availability:</h4>
<ul>
<li>Availability: Ensure that information systems are consistently available, reliable, and accessible to authorized users.</li>
</ul>
</li>
<li>
<h4>Categorization:</h4>
<ul>
<li>Integrity: Categorize information to minimize variations within and between categories.</li>
<li>Data Consistency: Establish consistent categorization standards to maintain data integrity.</li>
</ul>
</li>
</ol>
<p>By addressing these ethical considerations during information systems design, organizations can uphold ethical principles, protect user privacy, maintain data accuracy and integrity, and ensure the availability of information in a responsible and ethical manner.</p>
<p>&nbsp;</p>
<h4>References and Related Articles</h4>
<p>Capozzoli, E. A., Windsor, R. D., &amp; True, S. L. (2006). Reading 7: <em>Integration and Ethical Perspectives for Information Systems Management.</em> In M. Whitman &amp; H. Mattford (Authors), Readings and Cases in the Management of Information Security. Mason, OH: Course Technology.</p>
<p><a href="https://www.promptcloud.com/blog/importance-of-ethical-data-collection/" target="_blank" rel="noopener">https://www.promptcloud.com/blog/importance-of-ethical-data-collection/</a></p>
<p><a href="https://www.oreilly.com/library/view/accounting-information-systems/9781118162309/c13-26.html" target="_blank" rel="noopener">https://www.oreilly.com/library/view/accounting-information-systems/9781118162309/c13-26.html</a></p>
<p>https://www.forbes.com/sites/forbestechcouncil/2020/03/31/the-ethical-data-dilemma-why-ethics-will-separate-data-privacy-leaders-from-followers/?sh=272064a14c6a</p>
<h4>Additional Articles</h4>
<p><a href="https://zymitry.com/demystifying-pci-dss-safeguarding-cardholder-data-transactions/" target="_blank" rel="noopener">Demystifying the Payment Card Industry Data Security Standard (PCI DSS): Safeguarding Cardholder Data in Transactions</a></p>
<p><a href="https://zymitry.com/security-policy-hand-held-devices/" target="_blank" rel="noopener">Security Policy Template for Hand-Held Devices</a></p>
<p><a href="https://zymitry.com/process-migrating-application-cloud/" target="_blank" rel="noopener">The Process of Migrating an Application to the Cloud</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-implications-exploration/" target="_blank" rel="noopener">Exploring the Implications of Artificial Intelligence</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-texas-higher-ed/" target="_blank" rel="noopener">Artificial Intelligence in Texas Higher Education: Ethical Considerations, Privacy, and Security</a></p>
<p>&nbsp;</p>
<p><span style="font-size: 10pt;"><strong>Note:</strong> <em>This article has been drafted and improved with the assistance of AI, incorporating ChatGPT suggestions and revisions to enhance clarity and coherence. The original research, decision-making, and final content selection were performed by a human author.</em></span></p>
<p><a href="http://zymitry.com/zymitry-disclaimer/">Disclaimer</a></p>
<p><a href="https://zymitry.com/terms-conditions-use/" target="_blank" rel="noopener">Terms and Conditions of Use</a></p>
<p>The post <a href="https://zymitry.com/ethics-related-collection-information/">Ethics Related to the Collection of Information</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/ethics-related-collection-information/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">301</post-id>	</item>
		<item>
		<title>Consumer Privacy Bill of Rights</title>
		<link>https://zymitry.com/consumer-privacy-bill-rights/</link>
					<comments>https://zymitry.com/consumer-privacy-bill-rights/#respond</comments>
		
		<dc:creator><![CDATA[Greg Palmer]]></dc:creator>
		<pubDate>Sat, 19 Nov 2016 05:46:11 +0000</pubDate>
				<category><![CDATA[Information Security Compliance]]></category>
		<category><![CDATA[Bill]]></category>
		<category><![CDATA[Consumer]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Rights]]></category>
		<guid isPermaLink="false">http://zymitry.com/blog/?p=163</guid>

					<description><![CDATA[<p>Consumer Privacy Bill of Rights &#160; Consumer Privacy Bill of Rights &#160; Introduction The Consumer Privacy Bill of Rights (CPBR) was proposed as a draft bill by President Obama on 27 February 2015. The CPBR is intended as a law that will govern the collection and dissemination of consumer data. The Obama administration re-introduced the… <span class="read-more"><a href="https://zymitry.com/consumer-privacy-bill-rights/">Read More: Consumer Privacy Bill of Rights &#187;</a></span></p>
<p>The post <a href="https://zymitry.com/consumer-privacy-bill-rights/">Consumer Privacy Bill of Rights</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="flex flex-grow flex-col gap-3">
<div class="min-h-[20px] flex items-start overflow-x-auto whitespace-pre-wrap break-words flex-col gap-4">
<div class="markdown prose w-full break-words dark:prose-invert light">
<h1><strong>Consumer Privacy Bill of Rights</strong></h1>
</div>
</div>
</div>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Consumer Privacy Bill of Rights</strong></p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Introduction</strong></p>
<p>The Consumer Privacy Bill of Rights (CPBR) was proposed as a draft bill by President Obama on 27 February 2015. The CPBR is intended as a law that will govern the collection and dissemination of consumer data. The Obama administration re-introduced the CPBR as an enhancement to the Data Security and Breach Notification Act of 2015 which requires organizations to disclose data breaches in a timely manner to mitigate the risk of identity theft (Chernichaw &amp; Freeman, 2015). This paper will explore the key provisions of the CPBR, related legal cases where the CPBR could have applied, explore how the CPBR could affect consumers and business, and discuss safeguards that would be used by organizations upon implementation of the CPBR.</p>
<p>&nbsp;</p>
<p><strong>Consumer Privacy Bill of Rights Background</strong></p>
<p>Lustigman &amp; Solomon (2015) state that the reintroduction of the CPBR should come as no surprise to anyone involved in data collection due to a number of data gathering organizations that have come under FTC scrutiny for lax or ineffective privacy practices. For example; in 2011, Google was subjected to a Federal Trade Commission (FTC) investigation and penalties for misrepresenting a new social network. The privacy policy for this network provided misleading information on privacy controls. Another example incident occurred in 2012 when the FTC settled with the popular social networking site Facebook over its lack of transparency in its privacy policies, and deceiving its users about information that their users thought was private, when in fact this information was made public (Lustigman, &amp; Solomon, 2015).</p>
<p><a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer">Kerry (2015) </a>states that the Edward Snowden leaks have brought about concerns among the public regarding government surveillance, and has also brought attention to how much electronic data can be collected and how much it can reveal about a person. Additionally, a rash of highly publicized cyber-attacks and data breaches that have affected organizations such as Target, Sony Pictures, and Anthem, has created anxiety among consumers about the vulnerability of personal information. As a result, it has brought to light an acute need to renew global trust in the United States government protection of privacy and in the companies that operate under U.S. privacy law. Currently, forty seven states have breach notification laws in addition to other federal laws that govern the protection of private information, but it has been noted that there are gaps in these laws due to the increasing proportion of electronic data collection that falls outside currently existing privacy laws. The CPBR is intended to fill in these gaps and provide a federal government established baseline standard for the protection of private information <a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer">(Kerry, 2015)</a>.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Consumer Privacy Bill of Rights Key Provisions</strong></p>
<p>The current discussion draft of the CPBR was submitted to the U.S. Senate with the last formal action on the bill performed in April of 2015 (Congress.gov Bill 1158, 2015). The following are the major key provisions of the current discussion draft:</p>
<ul>
<li>Transparency: Covered entities are required to provide individuals with concise, conspicuous, and easily understandable notices that provide accurate, clear, and timely information about the entities’ privacy and security practices. This provision specifies requirements for notices to include; information about retention practices, disclosures, and mechanisms for obtaining access to personal data (Whitehouse.gov CPBR Act, 2015, pg.6-7).</li>
<li>Individual Control: Covered entities are required to provide individuals with reasonable means to control the processing of their personal data that are proportionate to the privacy risks. The provision defines privacy risk as &#8220;the potential for personal data, on its own or when linked to other information about an individual, to cause emotional distress or physical, financial, professional or other harm to an individual.” The provision requires that covered entities provide individuals with the means to withdraw consent to the processing of personal data (Whitehouse.gov CPBR Act, 2015, pg.7-8).</li>
<li>Respect for Context: A covered entity is required to processes personal data in a manner that is reasonable compared to its context. Context would be determined by evaluating the interactions between an entity and individuals and what reasonable individuals would understand about the covered entity’s practices. The provision states that &#8220;covered entities shall provide individuals with notice regarding personal data practices that are not reasonable in light of context at times and in a manner reasonably designed to enable individuals to decide whether to reduce their exposure to the associated privacy risk, as well as a mechanism for control that is reasonably designed to permit individuals to exercise choice to reduce such privacy risk&#8221;. A privacy risk analysis would include; reviews of data sources, systems, information flows, partnering entities, and data and analysis uses. Exceptions for certain data analysis is governed by FTC-approved industry Privacy Review Boards that can exempt covered entities from providing heightened notice and individual control where the Privacy Review Boards supervise data processing that is otherwise not reasonable in terms of context (Whitehouse.gov CPBR Act, 2015, pg.8-10).</li>
<li>Focused Collection and Responsible Use: Covered entities are permitted to collect, retain and use personal data only as is reasonable in the context that it will be used. Entities are required to delete, destroy, or de-identify personal data within a reasonable time after collected data has served the purpose for which it was collected (Whitehouse.gov CPBR Act, 2015, pg.10-11).</li>
<li>Security: Covered entities are required to secure personal data against loss, compromise, alteration, and unauthorized use, or disclosure. Furthermore, entities are required to conduct security risk assessments and implement reasonable security safeguards (Whitehouse.gov CPBR Act, 2015, pg.11).</li>
<li>Access and Accuracy: Covered entities would generally be required to provide individuals, upon request and proper identity verification, with reasonable access to the personal data about them that entities have collected and control. Entities are required to take reasonable and appropriate steps to mitigate related associated privacy risks and ensure that personal data held by entities is accurate (Whitehouse.gov CPBR Act, 2015, pg.12-13).</li>
<li>Accountability: Covered entities would be required to provide training to employees, conduct privacy assessments, adopt privacy policies and procedures, require those working with personal data to use the data consistently with the entities goals and policies, and take reasonable steps to ensure compliance with the all provisions of the CPBR (Whitehouse.gov CPBR Act, 2015, pg.13-14).</li>
<li>Enforcement and Civil Penalties: The FTC is responsible for enforcing the CPBR on a federal level. The bill makes provisions for State Attorney General&#8217;s to also enforce the bill with notification provided to the FTC. Civil penalties for violation of the bill are calculated by multiplying the number of days that the covered entity violates the Act by an amount not to exceed $35,000. The total civil penalty determined by the court shall not exceed $25,000,000 (Whitehouse.gov CPBR Act, 2015, pg.14-16).</li>
<li>Safe Harbor: The Secretary of Commerce may convene interested stakeholders, such as members of industry, civil society, the public safety community, and academia, to develop codes of conduct. Covered entities that adhere to this code of conduct can apply to the commission for Safe Harbor. Covered entities that can demonstrate that they have maintained a commitment to adhere to the Commission-approved code of conduct shall have a complete defense (Whitehouse.gov CPBR Act, 2015, pg.17-20).</li>
</ul>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Related Legal Proceedings Discussion</strong></p>
<p> Currently the United States does not have a single comprehensive federal law that covers consumer information privacy and security. Instead it has enacted several industry specific laws, for example; the GLBA and HIPAA that cover personal information privacy for financial information and health information. For this reason most states have enacted their own data privacy and security laws that cover gaps on how to handle private information and its security. The issue is that the provisions and penalties of these laws can vary from state to state (Grama, 2015, pg. 248). The CPBR is intended to fill in the potential gaps not covered by existing federal and state laws, and establish a single baseline standard for the protection of private information<a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer"> (Kerry, 2015)</a>.  Since the CPBR has not been implemented as law yet, there are no historical cases or case studies directly related to the bill. The following case studies examine a few privacy related incidents where provisions of the CPBR would have been beneficial to the protection and securing of consumer private information.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Related Legal Proceedings Case Study (1), Sony Pictures.</strong></p>
<p>On 21 Nov, 2014, Sony Pictures Entertainment executives received extortion emails from a cyber criminal group warning of an attack. On 24 Nov, 2014 Sony discovered internal documents, emails and movies had been leaked and that it had lost control of its IT network <a href="https://securityintelligence.com/who-hacked-sony-new-report-raises-more-questions-about-scandalous-breach/" target="_blank" rel="noopener noreferrer">(Tamir, 2015)</a>. Apparently hackers targeted Sony employees in Russia, India and other parts of Asia with spear-phishing e-mails to which a malicious PDF document was attached, which included a remote-access Trojan. After some Sony employees opened the PDF file, their PCs became infected with the malware, and the hackers used this to gain access to the Sony Pictures network. The hackers provided Sony with samples of stolen documents, emails, and other data that proved to be authentic. The hacking group claimed to have initiated the attack because of a movie titled “The Interview” which portrayed the country of North Korea in an unflattering light. The attackers sent the warning message demanding that Sony pull the movie from release. When Sony failed to pull the movie release by the allotted time specified by the attackers, the hacking group proceeded with the attack <a href="https://www.bankinfosecurity.com/report-claims-russians-hacked-sony-a-7873?rf=2015-02-04-eb&amp;utm_source=SilverpopMailing&amp;utm_medium=email&amp;utm_campaign=enews-bis-20150204%20%281%29&amp;utm_content=&amp;spMailingID=7476382&amp;spUserID=NTQ5MzMyMzQ1ODIS1&amp;spJobID=620402043&amp;spReportId=NjIwNDAyMDQzS0" target="_blank" rel="noopener noreferrer">(Schwartz, 2015)</a>.</p>
<p>In this case most of the publicity and target of investigation was related to intellectual property and company business data that was exposed. It was noted that since Sony was not a health care organization or a type of financial institution, there wasn’t a requirement for Sony to meet a specific and detailed regulatory requirements for data security involving personal data even though a very large quantity of the data exposed was personal in nature. This included documents, correspondence, and salaries of employees, as well as other private information about staff and actors. While Sony faces regulatory action and lawsuits from former employees, most of the attention and negative business implications have nothing to do with personal data (Nahra, 2015).</p>
<p>In Corona v. Sony Pictures Entertainment, Inc., No. 14-CV-09600 (RGK), U.S. District Judge R. Gary Klausner approved a settlement between Sony and 15,000 current and former employees for an undisclosed amount of money. Sony still faces potential liability for negligence based on its three-week delay in notifying its employees of the data breach, as well as statutory claims under the California Confidentiality of Medical Information Act and the Unfair Competition Law <a href="https://web.archive.org/web/20240414201142/https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/" target="_blank" rel="noopener noreferrer">(Hunton Privacy Blog Sony, 2016)</a>.</p>
<p>There are still many questions that remain unanswered about this case today to include questions about Sony’s information system security at the time of the breach. The most important item of note though is that most federal and state investigations into the incident are not related to the personal information that was exposed. It is also of note that any future potential liability is only partially being pursued using the California Confidentiality of Medical Information Act and the Unfair Competition Law. There is no other legal mechanism in place that applies specifically to information privacy on its own that can be used in the Sony case <a href="https://web.archive.org/web/20240414201142/https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/" target="_blank" rel="noopener noreferrer">(Hunton Privacy Blog Sony, 2016)</a>. Since the Sony breach did not fall under specific existing industry laws such as HIPAA or GLBA, the possibility of any legal penalties being leveled against Sony for the exposure of staff personal private information is still unclear and being explored (Nahra, 2015). The information privacy loopholes revealed in this case are an example of where a law like the proposed CPBR would cover the exposure of the staff’s private information related to this breach. The employees would still have the option of pursuing civil suits, but Sony would also still be liable for penalties under the CPBR. Furthermore, if a law like the CPBR was implemented, it specifies that Sony would have a legal obligation to protect this private information and compel them to implement security safeguards to protect private information, even the private information of its employees.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Related Legal Proceedings Case Study (2), Uber</strong></p>
<p>The popular ride-sharing service Uber has been the target of several complaints alleging the exposure of the private data of its customers and drivers the past few years, and is currently involved with many lawsuits. Currently, Uber uses a technology that is referred to as “God Mode” which Uber claims is an application that allows them to track all Uber customers in real time. However, it has been reported that Uber often used this function as entertainment for parties, showing the Ubers in a city and the silhouettes of waiting Uber users who had flagged cars. One party attendee reported that real-time information was used and as a result individuals were identifiable. It has also been reported that it is not just employees who have too much access. A reporter for the Washington Post interviewed for a job at Uber in 2013 and was given unrestricted access to customer data for an entire day, just as if he were an employee. The data collected by Uber during the normal course of business to include; name and credit card information are private information protected by many existing privacy laws. The issue in these cases is that other private information is routinely being misused, and this misuse is not covered by many state information privacy laws. Additionally, since Uber is not a health related organization or a financial organization, federal laws such as HIPAA and GLBA do not apply <a href="http://www.financierworldwide.com/ubers-privacy-violations-a-cautionary-tale-for-others/#.V2G3xbsrKHs" target="_blank" rel="noopener noreferrer">(Mueffelmann, 2015)</a>.</p>
<p>On 22 June, 2015, the FTC filed a “Complaint, Request for Investigation, Injunction, and Other Relief” against Uber related to the privacy infractions described above. The filing states that Uber has ignored the FTC’s prior decisions, and their current actions threaten the privacy rights and personal safety of American consumers. The filing further states that Uber continues to ignore past bad practices of the company involving the misuse of location data, an action that poses a direct risk of consumer harm (Epic Uber Injunction, 2015).</p>
<p>The Uber case is a good example of why laws such as the proposed CPBR need to be implemented. The CPBR contains provisions that specifically address much of the misuse described in this case, specifically, the provisions for Transparency, Individual Control, Focused Collection and Responsible Use, and Security.</p>
<p>The Transparency provision requires organizations to provide individuals with concise, conspicuous, and easily understandable notices that provide accurate, clear, and timely information about the entities’ privacy and security practices. Something Uber currently does not do.</p>
<p>The Individual Control provision requires organizations to provide individuals with reasonable means to control the processing of their personal data that are proportionate to the privacy risks. The provision defines privacy risk as &#8220;the potential for personal data, on its own or when linked to other information about an individual, to cause emotional distress or physical, financial, professional or other harm to an individual.” The provision requires that covered entities provide individuals with the means to withdraw consent to the processing of personal data. The “God Mode” application can be used to provide accurate location information on Uber users. As such this information is private. Uber sharing this information with other customers exposes this private information. Additionally, Uber does not provide customers a method to “opt-out” of being tracked by the application.</p>
<p>The Focused Collection and Responsible Use provision states that entities are permitted to collect, retain and use personal data only as is reasonable in the context that it will be used. Uber using data collected by the “God Mode” application for entertainment purposes would violate this provision.</p>
<p>The Security provision would specifically cover incidents such as allowing prospective employees to have unrestricted access to private information of its customers. This provision would also provide instruction for safeguarding private information (Whitehouse.gov CPBR Act, 2015, pg.6-11).</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Impact of the CPBR on Information Security Safeguards – Security Provisions</strong></p>
<p>The CPBR Security provision (Whitehouse.gov CPBR Act, 2015, pg.11), states that safeguards must adhere to several sub-provisions that are as follows:</p>
<ul>
<li>“Identify reasonably foreseeable internal and external risks to the privacy and security of personal data that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information”.</li>
<li>&#8220;Establish, implement, and maintain safeguards reasonably designed to ensure the security of such personal data&#8221;.</li>
<li>Regularly assess the sufficiency of any safeguards in place to control reasonably foreseeable internal and external risks. Evaluate and adjust safeguards as required. Make any material changes to operations or business arrangements as required to ensure compliance.</li>
</ul>
<p>The provision further states that the reasonableness of the safeguards that a covered entity adopts must account for: the degree of the privacy risk associated with the personal data under the covered entity’s control, the foreseeability of threats to the security of such data, widely accepted practices in administrative, technical, and physical safeguards for protecting personal data, and the cost of implementing and regularly reviewing such safeguards (Whitehouse.gov CPBR Act, 2015, pg.11)</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Impact of the CPBR on Information Security Safeguards – Discussion</strong></p>
<p>The first item noticed about the Security provision of the CPBR bill in its current form is that it does not reference any specific standard or law. It simply states that safeguards must meet “widely accepted practices in administrative, technical, and physical safeguards for protecting personal data”. The Safe Harbor provision states that there is to be the creation of codes of conduct that would be overseen and approved by the FTC, but this code of conduct has not been created yet (Whitehouse.gov CPBR Act, 2015, pg.17-20).</p>
<p>Lustigman &amp; Solomon (2015) state that the largest impact of the CPBR if implemented would be on organizations such as online marketers, retailers, service, and sales oriented businesses, since they often do not fall under many of the existing privacy laws such as HIPAA and GLBA. Organizations that currently fall under existing laws usually already meet compliance standards of the CPBR. The implementation of the CPBR would force the sales and retail organizations mentioned above to change their privacy policies and how they currently handle and secure private information.</p>
<p>A safeguard baseline standard could reasonably be derived from the health and financial industries governed by laws such as HIPAA and the GLBA, or, generated using guidelines provided by the National Institute of Standards and Technology (NIST), and The International Organization for Standardization (ISO). NIST computer security publications for example are a widely-recognized as a standard for  information security guidelines that identify key security web resources to support users in industry, government, and academia (NIST Computer Security, n.d.).</p>
<p>Since most organizations that are subject to existing federal and state information privacy laws use publications from organizations such as NIST, these publications would be a good source to use in the implementation of security safeguards required by the CPBR.</p>
<p><strong> </strong></p>
<p style="text-align: center;"><strong>Impact of the CPBR on Information Security Safeguards – Safeguards</strong></p>
<p>The following are security safeguards that can be implemented to meet CPBR Security provisions using NIST publications as guidelines:</p>
<ul>
<li>The Transparency provision requires organizations to provide individuals with concise, conspicuous, and easily understandable notices that provide accurate, clear, and timely information about the entities’ privacy and security practices (Whitehouse.gov CPBR Act, 2015, pg.6-7). Technical safeguards are not well suited to enforce this provision, an administrative safeguard such as a policy would work best. The NIST 800-14 provides guidelines that can be used to generate policies and procedures (Swanson &amp; Guttman, 1996, pg.11-15).</li>
<li>The Individual Control provision states that entities are required to provide individuals with reasonable means to control the processing of their personal data that are proportionate to the privacy risks. In the case of this provision, a means would have to exist that allowed users to access private information held by the entity. One privacy concern would be authentication. An example technical safeguard could entail an online authentication where a user would need to provide two-part authentication.</li>
<li>The Respect for Context, Focused Collection and Responsible Use, and Access and Accuracy provisions, would be best addressed with policies and procedures as outlined by NIST (Swanson &amp; Guttman, 1996, pg.11-15).</li>
</ul>
<p>The overall objective of security safeguards is to protect private information. This process requires a method for determining risk and exactly how an entity handles privacy, determine which safeguards are in place and how effective they are, and what additional safeguards need to be put into place. The CPBR Security provision instructs that entities must conduct risk assessments which would satisfy the need to  identify risks and implement security safeguards against these risks. NIST Publication 800-30 provides guidance on how to organize and conduct risk assessments, as well as guidance on implementing controls <a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">(Gallagher. NIST 800-30, 2012, pg.4-38)</a>.</p>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>Conclusions</strong></p>
<p>Upon research and examination of the proposed Consumer Privacy Bill of Rights bill it appears that the provisions proposed do in fact fill in many gaps and loopholes in privacy laws. In the cases of Sony and Uber, it clearly shows that much of the private information exposed in these incidents did not fall directly under existing federal and state laws. The CPBR would provide a baseline standard that would fill in the gaps not already covered. The law is proposed as one that sets a standard, but it is important to note that it will preempt current and future state privacy and security laws <a href="https://web.archive.org/web/20190918122414/https://cdt.org/insight/analysis-of-the-consumer-privacy-bill-of-rights-act/" target="_blank" rel="noopener noreferrer">(CDT, CPBR, 2015).</a></p>
<p>The CPBR initially appears to be an excellent proposal, but it does have a few areas of concern in its current form. Sullivan (2015) discusses the political environment that surrounds the law and also discusses the alternative Consumer Privacy Bill proposed after the CPBR by Senators Leahy and Franken. This particular proposal goes a few steps further than the CPBR in regards to not requiring demonstration of harm before notice (Sullivan, 2015). This lack of vision and direction appears to be slowing down the passing of either bill while legislators work them out.</p>
<p>Another primary concern of the CPBR includes penalties for violation. Penalties in the bills current form are for amounts not to exceed $35,000 per incident (Whitehouse.gov CPBR Act, 2015, pg.14-16). If these penalties were to be applied to very large organizations, the $35,000 per incident for a violation is not much of a deterrent.</p>
<p>Overall the proposed CPBR appears to have the potential to be a valuable law that fills in private information protection gaps, however, in its current form, it still has a few issues that need to be resolved or it will be in danger of becoming an ineffective law.</p>
<p>&nbsp;</p>
<p>More privacy and censorship news can be found at Online Censorship News</p>
<p><strong> </strong></p>
<p style="text-align: center;"><strong>References</strong></p>
<p>CDT, CPBR. (2015, March 02). <em>Analysis of the Consumer Privacy Bill of Rights Act.</em> Retrieved June 16, 2016, from <a href="https://web.archive.org/web/20190918122414/https://cdt.org/insight/analysis-of-the-consumer-privacy-bill-of-rights-act/" target="_blank" rel="noopener noreferrer">https://cdt.org/insight/analysis-of-the-consumer-privacy-bill-of-rights-act/</a>.</p>
<p>Chernichaw, A., &amp; Freeman, B. (2015, April 08). <em>White House Re-Introduces Consumer Privacy Bill of Rights Act. </em>Retrieved May 05, 23, from http://www.whitecase.com/publications/article/white-house-re-introduces-consumer-privacy-bill-rights-act.</p>
<p>Congress.gov Bill 1158. (2015, April 30). <em>S.1158 &#8211; Consumer Privacy Protection Act of 2015</em>. Retrieved June 13, 2016, from https://www.congress.gov/bill/114th-congress/senate-bill/1158/action.</p>
<p>Epic Uber Injunction. (2015, June 22).<em> Complaint, Request for Investigation, Injunction, and Other Relief. </em>Retrieved June 15, 2016, from https://epic.org/privacy/internet/ftc/uber/Complaint.pdf</p>
<p>Gallagher. P. NIST 800-30. (2012, September). Guide for Conducting Risk Assessments. Retrieved June 16, 2016, from <a href="https://web.archive.org/web/20250525195835/https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank" rel="noopener noreferrer">http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf</a></p>
<p><em>G</em>rama, J. L. (2015). <em>Legal issues in information security</em> (2nd ed.). Boston, MA: Jones &amp; Bartlett Learning.</p>
<p>Hunton Privacy Blog Sony. (2016, April 18). <em>Federal Court: Sony Pictures Data Breach Class Action Settlement Approved. </em>Retrieved June 15, 2016, from<a href="https://web.archive.org/web/20240414201142/https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/" target="_blank" rel="noopener noreferrer"> https://www.huntonprivacyblog.com/2016/04/18/federal-court-sony-pictures-data-breach-class-action-settlement-approved/</a>.</p>
<p>Kerry, C. (2015, March 06). <em>We need a Privacy Bill of Rights.</em> Retrieved May 27, 2016, from <a href="https://web.archive.org/web/20230609192438/https://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights/" target="_blank" rel="noopener noreferrer">http://thehill.com/blogs/congress-blog/civil-rights/234741-we-need-a-privacy-bill-of-rights</a>.</p>
<p>Lustigman, A., &amp; Solomon, A. (2015, March 12). <em>An overview and the impact of the Consumer Privacy Bill of Rights. </em>Retrieved May 27, 2016, from http://www.insidecounsel.com/2015/03/12/an-overview-and-the-impact-of-the-consumer-privacy.</p>
<p>Mueffelmann, K. (2015, February). <em>Uber’s privacy violations a cautionary tale for others.</em> Retrieved June 14, 2016, from <a href="http://www.financierworldwide.com/ubers-privacy-violations-a-cautionary-tale-for-others/#.V2G3xbsrKHs" target="_blank" rel="noopener noreferrer">http://www.financierworldwide.com/ubers-privacy-violations-a-cautionary-tale-for-others/#.V2G3xbsrKHs</a>.</p>
<p>Nahra, K. J. (2015, March). <em>Lessons to Be Learned from the Sony Breach</em>. Retrieved June 13, 2016, from http://apps.americanbar.org/buslaw/committees/CL925000pub/newsletter/201503/fa_2.pdf</p>
<p>NIST Computer Security. (n.d.). Computer Security Resource Center (CSRC. Retrieved June 16, 2016, from http://csrc.nist.gov/.</p>
<p>Schwartz, M. J. (2015, February 04). <em>Report Claims Russians Hacked Sony.</em> Retrieved June 13, 2016, from <a href="https://www.bankinfosecurity.com/report-claims-russians-hacked-sony-a-7873?rf=2015-02-04-eb&amp;utm_source=SilverpopMailing&amp;utm_medium=email&amp;utm_campaign=enews-bis-20150204%20%281%29&amp;utm_content=&amp;spMailingID=7476382&amp;spUserID=NTQ5MzMyMzQ1ODIS1&amp;spJobID=620402043&amp;spReportId=NjIwNDAyMDQzS0" target="_blank" rel="noopener noreferrer">http://www.bankinfosecurity.com/report-claims-russians-hacked-sony-a-7873?rf=2015-02-04-eb&amp;utm_source=SilverpopMailing&amp;utm_medium=email&amp;utm_campaign=enews-bis-20150204%20%281%29&amp;utm_content=&amp;spMailingID=7476382&amp;spUserID=NTQ5MzMyMzQ1ODIS1&amp;spJobID=620402043&amp;spReportId=NjIwNDAyMDQzS0</a>.</p>
<p>Sullivan, B. (2015, April 30). <em>Will the New Consumer Privacy Bill Protect You?</em> Retrieved June 16, 2016, from http://blog.credit.com/2015/04/new-consumer-privacy-bill-protect-115438/</p>
<p>Swanson, M., &amp; Guttman, B. (1996, September).<em> Generally Accepted Principles and Practices for Securing Information Technology Systems. </em>Retrieved June 16, 2016, from http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf</p>
<p>Tamir, D. (2015, February 05). <em>Who Hacked Sony? New Report Raises More Questions About Scandalous Breach. </em>Retrieved June 13, 2016, from <a href="https://securityintelligence.com/who-hacked-sony-new-report-raises-more-questions-about-scandalous-breach/" target="_blank" rel="noopener noreferrer">https://securityintelligence.com/who-hacked-sony-new-report-raises-more-questions-about-scandalous-breach/</a>.</p>
<p>Whitehouse.gov CPBR Act. (2015). <em>Administration Discussion Draft: Consumer Privacy Bill of Rights Act of 2015. </em>Retrieved May 23, 2016, from https://www.whitehouse.gov/sites/default/files/omb/legislative/letters/cpbr-act-of-2015-discussion-draft.pdf</p>
<h4>Additional Articles</h4>
<p><a href="https://zymitry.com/artificial-intelligence-implications-exploration/" target="_blank" rel="noopener">Exploring the Implications of Artificial Intelligence</a></p>
<p><a href="https://zymitry.com/artificial-intelligence-texas-higher-ed/" target="_blank" rel="noopener">Artificial Intelligence in Texas Higher Education: Ethical Considerations, Privacy, and Security</a></p>
<p><a href="https://zymitry.com/demystifying-pci-dss-safeguarding-cardholder-data-transactions/" target="_blank" rel="noopener">Demystifying the Payment Card Industry Data Security Standard (PCI DSS): Safeguarding Cardholder Data in Transactions</a></p>
<p><a href="https://zymitry.com/sarbanes-oxley-act-sox-finanical-reporting/" target="_blank" rel="noopener">Sarbanes-Oxley Act (SOX): Strengthening Financial Reporting and Accountability</a></p>
<h4><a href="http://zymitry.com/blog/zymitry-disclaimer/" target="_blank" rel="noopener noreferrer">Disclaimer</a></h4>
<p><a href="https://zymitry.com/terms-conditions-use/" target="_blank" rel="noopener">Terms and Conditions of Use</a></p>
<p>The post <a href="https://zymitry.com/consumer-privacy-bill-rights/">Consumer Privacy Bill of Rights</a> appeared first on <a href="https://zymitry.com"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://zymitry.com/consumer-privacy-bill-rights/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">163</post-id>	</item>
	</channel>
</rss>
