12
How Non-Profits can Assess and Evaluate Privacy Risks Christopher Parsons University of Victoria

How non profits can assess and evaluate privacy risks (net2vic october 2013)

Embed Size (px)

DESCRIPTION

How Non-Profits can Assess and Evaluate Privacy Risks Everyone is worried about privacy but what exactly should we actually be worried about? What are some of the daily ‘risks’ and the broader considerations for non-profits, today? In this presentation, Christopher will identify some practices that non-profits can adopt to both secure their clients’ personal information and to make better decisions about what information to collect or not. He’ll identify how non-profits can develop transparent and effective policies concerning the collection of personal information, basic and intermediate levels of securing some of that data (and what not to do with it, once you’ve collected it!), as well as some common ‘threats’ that such organizations might experience. These threats will identify different parties that could intentionally or accidently compromise non-profits’ computers, some of tactics third-parties might adopt to compromise data stores, and ways to potentially manage such threats.

Citation preview

Page 1: How non profits can assess and evaluate privacy risks (net2vic october 2013)

How Non-Profits can Assess and Evaluate

Privacy Risks

Christopher ParsonsUniversity of Victoria

Page 2: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Talk outline•Nailing down ‘privacy’

•‘Risk talk’

•Setting your own expectations

•Securing your data...from who?

•Considering your policies

•Basic tips

•Intermediate tips

Page 3: How non profits can assess and evaluate privacy risks (net2vic october 2013)

<Caveat>

Page 4: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Nailing down privacy

By Sang Valte

Page 5: How non profits can assess and evaluate privacy risks (net2vic october 2013)

‘Risk talk’By flosofl

Page 6: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Setting your own expectations

internally•Assess: Data collection, use,

management, disposal

•Understand: How and why you collect data

•Explain: Data processes clearly!

Page 7: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Effective collection

•Clear

•Purpose driven (and limited)

•Secured for clear duration

•Minimum needed for service offering

Page 8: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Securing your data

•‘Where’ is data, and who can access, and when/why?

•Are you geographically limited in where you can store?

•Who are securing it from?

•If you don’t have it, you don’t need to secure it!

Page 9: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Considering your policies

•Secure email? Data retention? Share PII?

•What if LEAs arrive? Where is the data?

•Who to contact?

•Do you update? How?

•Not just legalese!

Page 10: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Basic tips

•Role based access

•‘Good’ hygiene

•Secure mobile devices

•Outsource to reliable partners

Page 11: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Intermediate tips

•Encrypt OS and thumbdrives

•Activate remote wipe capabilities

•Lunchtime briefs

•Privacy ‘point’

•Plan for FUBAR, and beyond!

Page 12: How non profits can assess and evaluate privacy risks (net2vic october 2013)

Contact information

• Email: [email protected]

•Homepage: http://www.christopher-parsons.com

• Twitter: @caparsons