Добавил:
Я за два дня прошел весь курс ТВиМС Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
!ОСНОВНАЯ КНИГА КУРСА! Chapple M. (ISC)2 CISSP Certified IS...Study Guide 9ed 2021.pdf
Скачиваний:
1
Добавлен:
20.06.2025
Размер:
15.75 Mб
Скачать

Secure Design Principles

319

Zero trust has been formalized in NIST SP 800-207, “Zero Trust Architecture.” Please consult this document to learn more about this revolution in security design.

Privacy by Design

Privacy by Design (PbD) is a guideline to integrate privacy protections into products during the early design phase rather than attempting to tack it on at the end of development. It is effectively the same overall concept as “security by design” or “integrated security,” where security is to be an element of design and architecture of a product starting at initiation and being maintained throughout the software development lifecycle (SDLC).

As described in Ann Cavoukian’s paper “Privacy by Design – The 7 Foundational Principles: Implementation and Mapping of Fair Information Practices” (collections.ola. org/mon/24005/301946.pdf), the PbD framework is based on seven foundational principles:

■■

■■

■■

■■

■■

■■

■■

Proactive not reactive; preventive not remedial Privacy as the default

Privacy embedded into design

Full functionality – positive-sum, not zero-sum End-to-end security – full lifecycle protection Visibility and transparency

Respect for user privacy

The goal of PbD is to have developers integrate privacy protections into their solutions in order to avoid privacy violations in the first place. The overall concept focuses on preventions rather than remedies for violations.

PbD is also the driving factor behind an initiative to have privacy protections integrated throughout an organization, not just by developers. That business operations and systems design can also integrate privacy protections into their core functions. This in turn has led to the Global Privacy Standard (GPS), which was crafted to create a single set of universal and harmonized privacy principles. GPS is to be adopted by countries to use as a guide in developing privacy legislation, used by organizations to integrate privacy protection into their operations, and used by developers to integrate privacy into the products they produce. There is some integration of a few of the principles of PbD in the EU’s GDPR (see gdpr-info.eu/ issues/privacy-by-design and Chapter 4, “Laws, Regulations, and Compliance”).

For more on PbD and GPS, please visit gpsbydesign.org, review the Cavoukian paper mentioned earlier, and read an additional paper, “Privacy by Design in Law, Policy and Practice,” at collections.ola.org/mon/25008/312239.pdf. Learn more about privacy in Chapter 4 and about software development security in Chapter 20.

Trust but Verify

The phrase “trust, but verify” (which is a quote from a Russian proverb) was made famous by former president Ronald Reagan when discussing U.S. relations with the Soviet Union.

Соседние файлы в предмете Информационная безопасность автоматизированных систем