Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Audits Show Things At a Moment in Time; Silly To Sue For Breaches That Happen 1 Year After Audit Conclusion? | Main | Healthcare Worker Gets 1 Year In Prison For Posting HIV Victim's Medical Records On Internet »

Privacy Enhancing Technologies (PETs) & Privacy Threatening Technologies

I'm doing research while working on the 2nd edition of my book, "Managing an Information Security and Privacy Awareness and Training Program"...

In one section I provide 60 different topics for which training should be provided for targeted groups. One of these topics is about privacy enhancing technologies (PETs) and privacy threatening technologies. Business leaders and IT folks implementing the technologies must understand the privacy impacts to the organization of using such technologies.

Here are the lists I have for each; I am not going to provide specific vendor products, but categories of technologies:



  • PETs (Privacy Enhancing Technologies)


§ Encryption
§ Steganography
§ P3P (Platform for Privacy Preferences Project)
§ Access control systems
§ Privacy seals for Web sites
§ Blind signatures
§ Digital signatures
§ Biometrics
§ Firewalls
§ Spam filters
§ Cookie cutters and bug zappers
§ HTML filters
§ Pseudonymous and anonymous systems, such as communication anonymizers
§ Trusted sender stamps
§ EPAL (enterprise privacy authorization language)


  • Privacy threatening technologies (generally weren't created to invade privacy, but can be used to do so)


§ Cookies
§ Log files
§ Web bugs/web gifs/web beacons/clear gifs
§ Filtering and monitoring
§ Spyware
§ Spam and phishing
§ "Always online" Web-phones with audio and video capabilities
§ Grid networks and cloud computing
§ Blogs and micro-blogs (such as Twitter)
§ Instant messaging
§ Peer to peer
§ Active content and client-based scripting
§ Photo-enabled smart phones
§ Surveillance technologies
§ Trojans

Am I missing any technology in either of these lists? Let me know!

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/1000

Comments

I'm concerned that you are trying to create a binary, mutually-exclusive list. The same technology can often be used to be protect or threaten one's privacy.

Consider how the Targeted Advertising Cookie Opt-Out (TACO) plugin uses cookies to prevent advertising networks from collecting information about you, thereby protecting one's privacy.

Or, think about how biometics can be used to track people's access and movements, thereby threatening one's privacy.

Thanks for your comments, Michael.

No, I am not at all trying to create such a list. As I indicated in the post, this is an excerpt from the 2nd edition of my book, within which I expand upon the issues. This is simply a listing of training topics for what are commonly considered as PETs and privacy threatening technologies.

An important part of training and awareness is to start with a focus on specific topics, and then within the actual training content, or awareness communication or activity, dig into the facts and issues revolving around the topics. In this case, I'm starting with the list of topics that would be a skeleton around which the content is created. Not apparent when looking just at the list, I realize.

I wholeheartedly agree that almost any type of technology can be used for privacy invasion or privacy protection. You gave a couple of good examples. And there are many more. Indeed, the lists I provided show how historically and commonly people think of, and often use, these technologies. That is why it is so important to provide effective training for these topics to help people understand the many different ways in which they can be used! In fact, a good exercise within such training would be to include discussion of the ways in which each can be used for protecting privacy and also how each can be used to breach privacy. These lists would be fascinating to see from one type of training group to another (e.g., marketing, IT, legal, HR, sales, etc.). The devil's in the details.

Rebecca

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.