* Everyone in the company is accountable if a security breach occurs
Michelle Dennedy is Sun’s chief privacy officer. She’s also a lawyer and a smart lady (provided the two aren’t mutually exclusive). She also, like many folks at Sun, maintains a blog with her thoughts on things both within and without her purview at that leading identity management facility in Silicon Valley.
Recently she blogged about her recent trip to Toronto for the International Association of Privacy Professionals (IAPP) meeting, which she attended with Sun Chief Information Security Officer, Mark Connelly. She relates their discussions about security in a privacy context.
Their conversation revolved around personally identifiable information and its security. Dennedy is struck by how often an organization’s CPO will simply ask “is the data secure?” without inquiring too deeply into how that security is accomplished. More importantly, she claims, those responsible for privacy should be asking their technical brethren not only how the data is secured but what steps they take to prove or test that system’s security.
Too often, it seems, we rely on someone else’s yes or no answer to a very complex question.
It’s easy to say that we are all overburdened these days, and that the pace of technological advance means that only specialists can understand what’s happening within their narrow range of interest. But should an information breach occur it will be more than the technical people whose job will be on the line – everyone involved with both security and privacy will be held accountable. And when your future relies on a task that someone else has to accomplish, accepting either a yes or no answer may give you an unwarranted sense of wellbeing. I’m not saying that everyone needs to work 30-hour days so that they have a deep understanding of both the technology and the business needs – just that they understand enough to make informed decisions.
As Dennedy puts it: “I am not suggesting that we, the non-techs, all march back to school in one en masse engineering do over. I am, however, suggesting that we make certain that certain features are on the list of requirements before any IT is purchased, any vendor is selected or any system goes live. We need to ask more and better questions before we are forced to live with bad answers.” Wise words no matter which side of the aisle you’re sitting on.
The more the technical side of the house gets to know the business side, the better off everyone will be. Dennedy advises her pencil-pushing buddies to “Get to know a little bit about pocket protectors and maybe Star Trek,” and I’m advising you get to know a little bit about eyeshades and whatever it is that privacy wonks do for amusement (please, someone let me know what that is!). The more we know about each other the easier it will be to work together.




