ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A global technology company is developing a new social media platform. They are particularly concerned about adhering to the General Data Protection Regulation (GDPR) and other international privacy laws. To proactively address these concerns, they decide to embed privacy considerations into the platform's architecture and development process from the very beginning. This approach is best described as:
- ASecurity by Design
- BCompliance by Default
- CData Minimization
- DPrivacy by Design
Show answer & explanationAnswer & explanation
Correct answer: D. Privacy by Design
Privacy by Design is an approach that integrates privacy considerations into the design and operation of information systems, networked infrastructure, and business practices, proactively rather than reactively. The scenario explicitly mentions embedding privacy from the beginning to address privacy laws.
Why the other options are wrong
- A. Security by Design is a broader concept focusing on overall security, not specifically privacy.
- B. Compliance by Default relates to systems being compliant without user intervention, but 'Privacy by Design' is the methodology for achieving this.
- C. Data Minimization is a principle of Privacy by Design, but not the overarching approach described.
Privacy by Design (PbD)
An approach to systems engineering that incorporates privacy and data protection into the entire lifecycle of technology, from the initial design phase to deployment and beyond. It emphasizes proactive rather than reactive measures.
- Seven foundational principles
- Proactive, not reactive
- Privacy as the default setting
Memory trick: Design for Privacy, build for Security.