2 cissp ® Official Study Guide Eighth Edition


Privacy Responsibilities and Legal Requirements



Download 19,3 Mb.
Pdf ko'rish
bet406/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   402   403   404   405   406   407   408   409   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Privacy Responsibilities and Legal Requirements
The safety of personal information also needs to be addressed in any organization’s secu-
rity policy. In addition, the security policy must conform to the regulatory requirements of 
the industry and jurisdictions in which it is active.
Privacy
means protecting personal information from disclosure to any unauthorized 
individual or entity. In today’s online world, the line between public and private informa-
tion is often blurry. For example, is information about your web-surfing habits private or 
public? Can that information be gathered legally without your consent? And can the gath-
ering organization sell that information for a profit that you don’t share in? In addition, 
your personal information includes more than information about your online habits; it also 
includes who you are (name, address, phone, race, religion, age, and so on), your health and 
medical records, your financial records, and even your criminal or legal records. In general 
such information falls under the heading of personally identifiable information (PII), as 
described in the National Institute of Standards and Technology (NIST) publication 
Guide 
to Protecting the Confidentiality of Personally Identifiable Information (PII)
, available 
online at 
https://csrc.nist.gov/publications/detail/sp/800-122/final
.
Dealing with privacy is a requirement for any organization that has employees. Thus, 
privacy is a central issue for all organizations. Protection of privacy should be a core mis-
sion or goal set forth in the security policy for any organization.
The General Data Protection Regulation (GDPR) Regulation (EU) 2016/679 is an EU 
regulation focused on the protection of citizens and their rights and control over their per-
sonal data. While the United States does not have an equivalent set of laws protecting U.S. 
citizens, many U.S. companies adopt some of the GDPR elements in order to attract and 
maintain employees and customers as well as gain the ability to operate in EU countries.
The GDPR and many other personnel privacy issues are discussed at greater length in 
Chapter 4, “Laws, Regulations, and Compliance.”


Summary 

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   402   403   404   405   406   407   408   409   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish