Lenny Zeltser 09月29日 10:49
网络安全与数据隐私的协同与冲突
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

本文探讨了网络安全与数据隐私领导者在组织中扮演的不同角色及其目标。虽然两者都致力于保护数据,但侧重点和方法有所不同:网络安全关注系统的机密性、完整性和可用性,语言常涉及威胁和漏洞;数据隐私则侧重于个人身份信息(PII)的保护,强调合法性、公平性和透明度。文章通过安全监控、数据收集与保留、事件响应和AI采购等具体场景,阐述了两者可能存在的协同与冲突,并提出通过沟通、协商和建立框架来化解分歧,实现有效合作,共同加强组织的安全与隐私保护。

🛡️ **目标一致,视角各异**:网络安全和数据隐私的领导者虽然在保护数据这一核心目标上一致,但关注点和工作视角存在差异。网络安全侧重于系统和数据的机密性、完整性和可用性,常以威胁和漏洞为语言;数据隐私则聚焦于个人数据的保护,强调合法性、公平性、透明度和数据主体的控制权。

🤝 **协同与冲突并存的场景**:在安全监控中,安全团队倾向于广泛的可见性和长期数据保留,而隐私团队则希望限制PII访问和最小化保留期;数据收集与保留方面,双方均倾向于最小化数据,但业务需求可能带来复杂性;事件响应时,安全负责调查,隐私负责通知和法律义务;AI采购中,双方在数据泄露和隐私方面有共同担忧,隐私还需考虑AI治理和训练数据溯源。

⚖️ **建立信任与协商分歧**:有效的网络安全与数据隐私领导者应认识到彼此专业知识的价值。在目标一致时建立信任,在利益不一致时进行协商。必要时,应拥抱健康的争论,因为这往往是最佳解决方案的诞生地。通过建立清晰的合作框架和沟通机制,可以有效化解分歧,共同提升组织的整体安全与隐私防护能力。

While cybersecurity and data privacy leaders have distinct expertise, our fundamental goals are aligned. By understanding each other’s perspectives and priorities, we can support each other to strengthen the organization’s cybersecurity and privacy programs. This was the focus of the presentation that Edy Glozman and I delivered at the RSA Conference. Edy and I collaborate at Axonius, where he is the VP of Legal and I am the CISO.

The overlap in cybersecurity and data privacy is significant, creating the potential for collaboration. However, since each role focuses on a different aspect of the organization, there’s also the potential for disagreements and conflict:

Both functions clearly involve protecting data, though they’re driven by different priorities and expertise. In our presentation, we shared several scenarios where the interests of cybersecurity and privacy professionals diverge or align:

We shared a practical framework to help cybersecurity and data privacy leaders, whether we’re pursuing similar objectives or whether our interests are misaligned. We also shared advice on making the most of either of these scenarios.

Effective security and privacy leaders recognize the value in each other’s expertise. We work to build trust when interests align, and we negotiate when they don’t. When necessary, we lean into healthy disagreements—that’s often where the best solutions emerge. To explore this topic further, watch our presentation and download our slides.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

网络安全 数据隐私 协同 冲突 RSA Conference Axonius CISO 法律 Cybersecurity Data Privacy Collaboration Conflict PII
相关文章