TL,DR: Privacy compliance is adherence to data protection laws governing collection, processing, and management of sensitive data. Yakima Valley Memorial Hospital paid $240,000 in HIPAA settlement for unauthorized PHI access Building a program follows 6 steps: identify applicable laws, conduct risk assessments, implement controls, enforce policies, train employees, and monitor systems continuously Applicability depends on…
TL,DR: GDPR Article 30 requires a Record of Processing Activities for personal data processing. RoPA documents what data you collect, where it sits, how it’s used, and who accesses it. The article explains record-keeping challenges across departments and how to maintain accurate processing documentation. Why is record keeping such a fundamental part of GDPR compliance? …
TL,DR: Security models define how systems protect confidentiality, integrity, and availability through access rules. The article explains Bell-LaPadula, Biba, Clark-Wilson, and other formal security models. Use it to understand access control theory behind secure systems and data protection decisions. Security models offer a blueprint for how security should be applied within organizations to ensure data…
TL,DR: An access control list (ACL) is a register defining user permissions that grant or deny access to critical systems and networks. Insiders caused 20% of data breaches in 2022 due to privilege creep (Verizon) Two types exist: standard ACLs (filter by source IP only, applied near destination) and extended ACLs (filter by source IP,…
TL,DR: Data loss prevention helps stop sensitive information from being leaked, misused, or exposed. DLP controls monitor data across endpoints, email, cloud apps, and networks. Strong DLP programs use classification, policies, encryption, access control, and alerts. In 2017, Equifax, one of the largest credit reporting agencies in the US, reported a Data breach. The breach…
TL,DR: ORM helps you identify, assess, and control risks from processes, systems, people, and external events. The article breaks ORM into scope setting, risk identification, assessment, control selection, monitoring, and reporting. Use it to connect risk appetite, operational resilience, compliance obligations, and incident learning. Be it the Stone Age or the Digital Age, the stakes…