Endpoint

2/18/2019
10:30 AM
Amit Ashbel
Amit Ashbel
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

Privacy Ops: The New Nexus for CISOs & DPOs

No longer can privacy be an isolated function managed by legal or compliance departments with little or no connection to the organization's underlying security technology.

Recent advancements in machine learning and big data analytics have made data more important today than ever before. Companies are now investing heavily in protecting their customers' data; for instance, Facebook has pledged to double its safety and security team to 20,000 people.

Since the introduction of Europe's General Data Protection Regulation (GDPR) in 2018, data protection officers (DPOs) have become the subject of the latest hiring frenzy. Large organizations that are mandated to hire a DPO based on the GDPR's criteria are struggling to find the right person for the job. But how does a DPO fit into the typical security organization?

At the end of the day, a DPO should report directly to top management on all regulation and privacy topics. As such, the perfect candidate must have in-depth knowledge of GDPR and other regulations. Your DPO should also view the responsibilities of GDPR compliance as an opportunity to drive your business forward.

Here is where things become challenging.

Security is led by the chief information security officer (CISO), who oversees regulation and all other security matters. The privacy side is led by the DPO, but this department is traditionally made up of lawyers and legal practitioners who have little knowledge of technology and security. The DPO doesn't have a real connection to the company's technology, and certainly does not have the buying power behind it.

This is true historically as well; the privacy side of operations within an enterprise comes from a legal background, which has been conservative and resistant to change. However, the emergence of regulations such as GDPR has caused a rise of influence in privacy roles, which have started to see growth and an increase in purchasing power. Organizations have also realized the critical need for cross-departmental collaboration and communication.

Today, we have entered a new era of global privacy management. No longer will privacy be an isolated function that can be housed by just legal or compliance. There needs to be a connector somewhere — Privacy Operations — a new and separate group that will serve as the technical connector between the security and privacy teams.

Privacy Ops is much like DevSecOps, wherein security processes take place along with development sprints. And just as security practitioners had to become involved and affect the software life cycle, privacy practitioners today must understand the data life cycle and enforce protection controls throughout the data processing pipelines. In Privacy Ops, we will see a merging of the security and privacy teams, in which the DPOs will leverage the security team's expertise to implement and manage technology in order to simplify regulation adherence.

This change and adaptation to new privacy standards has the potential to positively affect multiple aspects of privacy, business, and security. Privacy or DPO teams can now enhance their in-house impact on the organization and help protect user privacy by adopting technical solutions to be maintained by the privacy operations teams. This allows business digitalization teams to leverage data that is now maintained and governed. Security teams can leverage the power of the new privacy operations teams to enforce privacy regulations, thus allowing security to focus on risk management and prevention.

The impact of hiring data protection professionals and implementing privacy-driven technology is yet to be seen, but it is a necessary step toward minimizing data breaches and keeping our data from falling into the wrong hands.

Related Content:

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Amit Ashbel, security evangelist at Cognigo, has been with the security industry for two decades and has taken on multiple tasks and responsibilities, including technical positions and senior product lead positions. Amit has experience with a wide range of security ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Vincent Bureau
50%
50%
Vincent Bureau,
User Rank: Apprentice
2/19/2019 | 4:57:03 PM
Privacy Ops & DPO role
Good understanding of the culture and privacy operations. Agree with the Privacy ops approach. Beware of the conflict of interest as the DPO for the GDPR is an independent advisor. 
Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-6149
PUBLISHED: 2019-03-18
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
CVE-2018-15509
PUBLISHED: 2019-03-18
Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
CVE-2018-20806
PUBLISHED: 2019-03-17
Phamm (aka PHP LDAP Virtual Hosting Manager) 0.6.8 allows XSS via the login page (the /public/main.php action parameter).
CVE-2019-5616
PUBLISHED: 2019-03-15
CircuitWerkes Sicon-8, a hardware device used for managing electrical devices, ships with a web-based front-end controller and implements an authentication mechanism in JavaScript that is run in the context of a user's web browser.
CVE-2018-17882
PUBLISHED: 2019-03-15
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.