๐ CISSP Study Note: Privacy
๐ CISSP Study Note: Privacy
๐ Definition
Privacy is the right of an individual human being to control the collection, use, disclosure, and distribution of information about themselves. It represents a fundamental human right—recognized in law, ethics, and security governance—and is central to modern data protection frameworks.
๐ง Why It Matters in Cybersecurity
Privacy is not just a policy issue—it’s a trust issue.
In cybersecurity, ensuring privacy means designing and enforcing systems that respect user autonomy, minimize data exposure, and ensure compliance with privacy laws.
Failing to protect privacy can result in:
-
Legal and regulatory penalties
-
Loss of public trust
-
Reputational damage
-
Civil lawsuits or criminal charges
๐ค Privacy vs. Security
| Concept | Focus |
|---|---|
| Security | Protecting data and systems from threats (confidentiality, integrity, availability) |
| Privacy | Protecting people by giving them control over how their personal data is collected, used, and shared |
✅ Security is a tool used to help achieve privacy, but the two are not the same.
๐ Key Privacy Principles
| Principle | Description |
|---|---|
| Consent | Individuals must be informed and must agree to data collection. |
| Data Minimization | Only collect the minimum amount of personal data necessary. |
| Purpose Limitation | Use data only for the stated, agreed-upon purposes. |
| Right to Access | Individuals can view what data is collected about them. |
| Right to Erasure | Also known as “the right to be forgotten.” |
| Accountability | Organizations are responsible for protecting the privacy rights of data subjects. |
๐ก️ Laws That Protect Privacy
| Law / Regulation | Region | Key Focus |
|---|---|---|
| GDPR | EU | Broad personal data protections and individual rights |
| CCPA | California | Data transparency, opt-out rights, data sale limits |
| HIPAA | USA (healthcare) | Protects patient health information (PHI) |
| GLBA | USA (finance) | Protects customer financial data |
| PIPEDA | Canada | Fair data handling and access rights |
✅ Example (CISSP-Style)
A mobile fitness app collects user data like age, GPS location, heart rate, and sleep patterns. Before use, it presents a clear privacy policy, asks for explicit consent, and allows users to opt out of data sharing.
✅ This approach demonstrates proper privacy-by-design principles and individual control over personal data.
๐ Found In CISSP Domains
| Domain | Focus |
|---|---|
| ๐ Domain 1: Security and Risk Management | Emphasizes privacy, ethics, data protection laws, and individual rights. |
| ๐ Domain 2: Asset Security | Focuses on data classification, handling, and protecting sensitive personal information (PII/PHI). |
๐ Memory Hook
“Privacy is about people. Security is about protection.”
Privacy ensures individual dignity and control, even in a world driven by data.
Comments
Post a Comment