How Does the NIST Privacy Framework Work?

5.1K views
•
February 26, 2020
by
RSAC Cybersecurity
YouTube video player
How Does the NIST Privacy Framework Work?

TL;DR

The NIST Privacy Framework helps organizations identify and manage privacy risks arising throughout the data life cycle, while connecting impacts on individuals to enterprise risks such as lost trust, compliance costs, and reputational harm. Organizations can tailor its core, profiles, and implementation tiers to their priorities, resources, maturity, and collaboration between privacy and cybersecurity teams.

Transcript

Okay. Good morning, and welcome to the session, NIST Privacy Framework IRL: Use Cases from the Field. Uh, this session is a panel, so let me introduce you the moderator, who is Naomi Lefkovitz, Senior Privacy Policy Advisor at NIST. Please, the stage is yours. Thank you. Okay. Great. Thank you very much, and, um, thanks for showing up at eight in t... Read More

Key Insights

  • The NIST Privacy Framework is a voluntary, living tool for managing privacy as an enterprise risk. It was developed through an open and collaborative stakeholder process intended to ensure that its structure and guidance address the practical needs of organizations that may choose to adopt it.
  • Privacy risk management is about optimizing beneficial uses of data while minimizing adverse consequences for individuals. This approach supports ethical decision-making and customer trust while making privacy considerations part of the same general risk management practices that organizations use for other business or mission concerns.
  • The Privacy Framework is not a one-to-one compliance tool for any single law or regulation. It is intentionally agnostic to particular laws and jurisdictions, although organizations can use its measures to help demonstrate actions that may support obligations associated with requirements such as CCPA or GDPR.
  • Privacy risks extend beyond losses of confidentiality, integrity, and availability. They can emerge from data processing conducted for business or mission purposes throughout the information life cycle, including collection and disposal, even when that processing does not fit within the traditional boundaries of cybersecurity risk.
  • Individuals can experience privacy problems such as embarrassment, discrimination, and loss of self-determination. Organizations may then experience related enterprise consequences, including customer abandonment, loss of trust in products and services, non-compliance costs, reputational harm, and damage to internal culture.
  • The framework's core provides increasingly granular activities and outcomes for organizational dialogue. Its high-level functions can support discussions with senior management, boards, and the C-suite, while categories and subcategories allow privacy, legal, policy, cybersecurity, and technical teams to work at more detailed levels.
  • Profiles make the framework risk-based rather than a universal checklist. Organizations select and prioritize the activities and outcomes that matter most to their circumstances, then use a target profile to clarify the privacy outcomes they seek and guide decisions about processes, resources, and priorities.
  • Implementation tiers provide generalized benchmarking and a communication aid for privacy risk management. After identifying privacy risks, an organization can use the tiers to consider whether its current processes and resources are sufficient to manage those risks and achieve its selected target profile.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the NIST Privacy Framework used for?

The NIST Privacy Framework is a voluntary enterprise risk management tool for considering how data processing may affect individuals. It helps organizations optimize beneficial uses of data while minimizing adverse consequences, strengthen customer trust, and connect privacy concerns with familiar organizational risks. It can also help demonstrate measures relevant to legal obligations, but it is not designed as a one-to-one compliance checklist.

Q: How does privacy risk differ from cybersecurity risk?

Cybersecurity risk focuses on losses of confidentiality, integrity, and availability, while privacy risk also concerns problems arising from data processing across the full information life cycle. The two fields overlap around the security of personal information, but privacy extends further. Business or mission uses of data can create embarrassment, discrimination, or loss of self-determination for individuals without being limited to a conventional cybersecurity incident.

Q: How can privacy impacts become enterprise risks?

Privacy impacts are experienced directly by individuals, who may face embarrassment, discrimination, or loss of self-determination. Those impacts can produce consequences for an organization, including customer abandonment, reduced trust in products and services, non-compliance costs, reputational harm, and damage to internal culture. Making this connection visible can bring privacy into the broader enterprise risk portfolio and support better allocation of resources and budgets.

Q: What are the main components of the NIST Privacy Framework?

The framework has three main components: the core, profiles, and implementation tiers. The core presents increasingly granular privacy activities and outcomes. Profiles allow an organization to select and prioritize outcomes according to its risks instead of treating the core as a mandatory checklist. Implementation tiers provide generalized benchmarking and help evaluate whether processes and resources are sufficient to manage identified risks and achieve a target profile.

Q: How do profiles make the Privacy Framework risk-based?

Profiles allow each organization to choose and prioritize the core activities and outcomes that matter most for its circumstances. This means the full core is not a checklist that every organization must complete in the same way. A target profile expresses the privacy outcomes an organization wants to achieve and provides a basis for assessing whether existing processes, priorities, and resources can support those outcomes.

Q: How do implementation tiers support privacy programs?

Implementation tiers serve as a communication aid and provide a generalized form of benchmarking. Once an organization identifies its privacy risks, it can use the tiers to ask whether adequate processes and resources are in place to manage those risks. The tiers also help teams discuss what may be needed to progress toward the outcomes selected in the organization's target profile.

Q: How can the Privacy Framework improve communication?

The framework creates a shared structure for discussing privacy risk across different organizational levels and functions. High-level functions can support conversations with senior management, the C-suite, and boards that may not have specialized privacy expertise. More detailed categories and subcategories can support work among engineers, privacy professionals, cybersecurity teams, and legal or policy teams. The framework may also support external communication, potentially including communication with regulators.

Q: How can organizations combine the Privacy and Cybersecurity Frameworks?

The Privacy Framework is structurally aligned with the Cybersecurity Framework and intentionally includes areas of overlap. Privacy-marked functions help users recognize privacy-focused content, while organizations can mix and match elements according to their needs. This flexibility accommodates differences in privacy program maturity and in the strength of collaboration between privacy and cybersecurity teams, while NIST encourages strong cooperation between those teams.

Summary & Key Takeaways

  • The NIST Privacy Framework is a voluntary, living enterprise risk management tool developed through an open, collaborative stakeholder process. It helps organizations consider privacy impacts while developing systems, products, and services. Its goals include supporting ethical decisions, optimizing beneficial data uses, minimizing adverse consequences, building customer trust, and demonstrating measures relevant to legal obligations.

  • Privacy risk extends beyond cybersecurity concerns about confidentiality, integrity, and availability. It can arise from ordinary data processing across the information life cycle, from collection through disposal. Individuals may experience embarrassment, discrimination, or loss of self-determination, while organizations may face customer abandonment, diminished trust, compliance costs, reputational damage, and harm to internal culture.

  • The framework is structurally aligned with the NIST Cybersecurity Framework and contains a core, profiles, and implementation tiers. The core defines increasingly granular activities and outcomes. Profiles select and prioritize relevant outcomes instead of imposing a universal checklist. Implementation tiers help organizations assess whether their processes and resources are sufficient to reach a target profile.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚