๐Ÿ”’ CISSP Study Note: Privacy

๐Ÿ”’ CISSP Study Note: Privacy


๐Ÿ” Definition

Privacy is the right of an individual human being to control the collection, use, disclosure, and distribution of information about themselves. It represents a fundamental human right—recognized in law, ethics, and security governance—and is central to modern data protection frameworks.


๐Ÿง  Why It Matters in Cybersecurity

Privacy is not just a policy issue—it’s a trust issue.
In cybersecurity, ensuring privacy means designing and enforcing systems that respect user autonomy, minimize data exposure, and ensure compliance with privacy laws.

Failing to protect privacy can result in:

  • Legal and regulatory penalties

  • Loss of public trust

  • Reputational damage

  • Civil lawsuits or criminal charges


๐Ÿ‘ค Privacy vs. Security

Concept Focus
Security Protecting data and systems from threats (confidentiality, integrity, availability)
Privacy Protecting people by giving them control over how their personal data is collected, used, and shared

✅ Security is a tool used to help achieve privacy, but the two are not the same.


๐Ÿ“‹ Key Privacy Principles

Principle Description
Consent Individuals must be informed and must agree to data collection.
Data Minimization Only collect the minimum amount of personal data necessary.
Purpose Limitation Use data only for the stated, agreed-upon purposes.
Right to Access Individuals can view what data is collected about them.
Right to Erasure Also known as “the right to be forgotten.”
Accountability Organizations are responsible for protecting the privacy rights of data subjects.

๐Ÿ›ก️ Laws That Protect Privacy

Law / Regulation Region Key Focus
GDPR EU Broad personal data protections and individual rights
CCPA California Data transparency, opt-out rights, data sale limits
HIPAA USA (healthcare) Protects patient health information (PHI)
GLBA USA (finance) Protects customer financial data
PIPEDA Canada Fair data handling and access rights

✅ Example (CISSP-Style)

A mobile fitness app collects user data like age, GPS location, heart rate, and sleep patterns. Before use, it presents a clear privacy policy, asks for explicit consent, and allows users to opt out of data sharing.
✅ This approach demonstrates proper privacy-by-design principles and individual control over personal data.


๐Ÿ“– Found In CISSP Domains

Domain Focus
๐Ÿ“˜ Domain 1: Security and Risk Management Emphasizes privacy, ethics, data protection laws, and individual rights.
๐Ÿ“˜ Domain 2: Asset Security Focuses on data classification, handling, and protecting sensitive personal information (PII/PHI).

๐Ÿ”‘ Memory Hook

“Privacy is about people. Security is about protection.”
Privacy ensures individual dignity and control, even in a world driven by data.


Comments

Popular posts from this blog

๐Ÿงญ CISSP Study Note: Guidelines

๐Ÿ’ธ CISSP Study Note: Risk Transference

๐Ÿ“ CISSP Study Note: Standards