Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

2/18/2019
10:30 AM
Amit Ashbel
Amit Ashbel
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Privacy Ops: The New Nexus for CISOs & DPOs

No longer can privacy be an isolated function managed by legal or compliance departments with little or no connection to the organization's underlying security technology.

Recent advancements in machine learning and big data analytics have made data more important today than ever before. Companies are now investing heavily in protecting their customers' data; for instance, Facebook has pledged to double its safety and security team to 20,000 people.

Since the introduction of Europe's General Data Protection Regulation (GDPR) in 2018, data protection officers (DPOs) have become the subject of the latest hiring frenzy. Large organizations that are mandated to hire a DPO based on the GDPR's criteria are struggling to find the right person for the job. But how does a DPO fit into the typical security organization?

At the end of the day, a DPO should report directly to top management on all regulation and privacy topics. As such, the perfect candidate must have in-depth knowledge of GDPR and other regulations. Your DPO should also view the responsibilities of GDPR compliance as an opportunity to drive your business forward.

Here is where things become challenging.

Security is led by the chief information security officer (CISO), who oversees regulation and all other security matters. The privacy side is led by the DPO, but this department is traditionally made up of lawyers and legal practitioners who have little knowledge of technology and security. The DPO doesn't have a real connection to the company's technology, and certainly does not have the buying power behind it.

This is true historically as well; the privacy side of operations within an enterprise comes from a legal background, which has been conservative and resistant to change. However, the emergence of regulations such as GDPR has caused a rise of influence in privacy roles, which have started to see growth and an increase in purchasing power. Organizations have also realized the critical need for cross-departmental collaboration and communication.

Today, we have entered a new era of global privacy management. No longer will privacy be an isolated function that can be housed by just legal or compliance. There needs to be a connector somewhere — Privacy Operations — a new and separate group that will serve as the technical connector between the security and privacy teams.

Privacy Ops is much like DevSecOps, wherein security processes take place along with development sprints. And just as security practitioners had to become involved and affect the software life cycle, privacy practitioners today must understand the data life cycle and enforce protection controls throughout the data processing pipelines. In Privacy Ops, we will see a merging of the security and privacy teams, in which the DPOs will leverage the security team's expertise to implement and manage technology in order to simplify regulation adherence.

This change and adaptation to new privacy standards has the potential to positively affect multiple aspects of privacy, business, and security. Privacy or DPO teams can now enhance their in-house impact on the organization and help protect user privacy by adopting technical solutions to be maintained by the privacy operations teams. This allows business digitalization teams to leverage data that is now maintained and governed. Security teams can leverage the power of the new privacy operations teams to enforce privacy regulations, thus allowing security to focus on risk management and prevention.

The impact of hiring data protection professionals and implementing privacy-driven technology is yet to be seen, but it is a necessary step toward minimizing data breaches and keeping our data from falling into the wrong hands.

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Amit Ashbel, security evangelist at Cognigo, has been with the security industry for two decades and has taken on multiple tasks and responsibilities, including technical positions and senior product lead positions. Amit has experience with a wide range of security ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Vincent Bureau
50%
50%
Vincent Bureau,
User Rank: Apprentice
2/19/2019 | 4:57:03 PM
Privacy Ops & DPO role
Good understanding of the culture and privacy operations. Agree with the Privacy ops approach. Beware of the conflict of interest as the DPO for the GDPR is an independent advisor. 
News
A Startup With NSA Roots Wants Silently Disarming Cyberattacks on the Wire to Become the Norm
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/11/2021
Edge-DRsplash-10-edge-articles
Cybersecurity: What Is Truly Essential?
Joshua Goldfarb, Director of Product Management at F5,  5/12/2021
Commentary
3 Cybersecurity Myths to Bust
Etay Maor, Sr. Director Security Strategy at Cato Networks,  5/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google Maps is taking "interactive" to a whole new level!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-21830
PUBLISHED: 2021-05-17
A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213.
CVE-2020-21832
PUBLISHED: 2021-05-17
A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417.
CVE-2020-21833
PUBLISHED: 2021-05-17
A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440.
CVE-2020-21834
PUBLISHED: 2021-05-17
A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164.
CVE-2020-21835
PUBLISHED: 2021-05-17
A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.