ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy
A small startup company is developing a new mobile application that will collect user location data. The company wants to ensure they minimize the risk of a data breach and comply with future privacy regulations. Which principle should guide their design and development process from the very beginning?
- ADefense in Depth
- BSecurity by Obscurity
- CPrivacy by Design
- DJust-in-Time Provisioning
Show answer & explanationAnswer & explanation
Correct answer: C. Privacy by Design
Privacy by Design is an approach that integrates privacy considerations into the entire engineering process, from the initial design stages through to deployment and operation. This proactively addresses privacy concerns rather than reacting to them after development.
Why the other options are wrong
- A. Defense in Depth is a security strategy, but Privacy by Design specifically focuses on privacy from the outset.
- B. Security by Obscurity relies on hiding information, which is not a robust security principle.
- D. Just-in-Time Provisioning is an access management concept, not a privacy design principle.
Privacy by Design
An approach to systems engineering that incorporates privacy and data protection into the entire design and operation of IT systems, infrastructure, and practices.
- Proactive, not reactive.
- Privacy as a default setting.
- Privacy embedded into design.
Memory trick: Designing secrets from the start keeps data smart.