1
00:00:06,570 --> 00:00:09,450
- Welcome to Lesson 26: Deep Dive Quiz.

2
00:00:09,450 --> 00:00:11,850
In 26, we summarize the elements

3
00:00:11,850 --> 00:00:14,070
of effective security compliance.

4
00:00:14,070 --> 00:00:17,160
In lesson 26.1 we talked
about compliance monitoring

5
00:00:17,160 --> 00:00:20,190
and in 26.2, well we spent a lot of time

6
00:00:20,190 --> 00:00:22,143
talking about privacy principles.

7
00:00:23,220 --> 00:00:24,053
So are you ready?

8
00:00:24,053 --> 00:00:26,490
Let's do a five question quiz together.

9
00:00:26,490 --> 00:00:27,780
I know you know how to do this,

10
00:00:27,780 --> 00:00:29,820
but make sure you've got
your pen or your pencil

11
00:00:29,820 --> 00:00:30,990
and your paper ready

12
00:00:30,990 --> 00:00:33,393
and put me on pause as
much as you need to.

13
00:00:35,460 --> 00:00:39,090
Which statement best describes
the concept of privacy?

14
00:00:39,090 --> 00:00:40,500
The right of an individual to control

15
00:00:40,500 --> 00:00:42,090
their personal information;

16
00:00:42,090 --> 00:00:44,070
The right of an individual
to be compensated

17
00:00:44,070 --> 00:00:46,080
for the use of personal information;

18
00:00:46,080 --> 00:00:47,310
The right of an individual to know

19
00:00:47,310 --> 00:00:49,650
how personal information is being secured;

20
00:00:49,650 --> 00:00:53,250
And the right of an individual
to demand disclosure.

21
00:00:53,250 --> 00:00:56,130
These are all pretty
valid statements, right?

22
00:00:56,130 --> 00:01:00,183
But which one of them best
describes the concept of privacy?

23
00:01:01,200 --> 00:01:02,980
Go ahead and put me on pause

24
00:01:04,141 --> 00:01:05,700
if you need to.

25
00:01:05,700 --> 00:01:08,010
All right, I'm gonna choose the first one,

26
00:01:08,010 --> 00:01:10,020
which is "The right of the individual

27
00:01:10,020 --> 00:01:12,390
to control their personal information."

28
00:01:12,390 --> 00:01:15,450
An inherent of that, right, is really

29
00:01:15,450 --> 00:01:17,040
the right to know how
their personal information

30
00:01:17,040 --> 00:01:19,078
might be secured and demand to know

31
00:01:19,078 --> 00:01:21,780
that they have personal information,

32
00:01:21,780 --> 00:01:24,720
but the succinct description of privacy

33
00:01:24,720 --> 00:01:26,700
is the right of an individual to control

34
00:01:26,700 --> 00:01:28,140
their personal information.

35
00:01:28,140 --> 00:01:29,010
Do you agree?

36
00:01:29,010 --> 00:01:29,970
I hope so.

37
00:01:29,970 --> 00:01:31,803
Let's check it out and it's correct.

38
00:01:33,180 --> 00:01:36,660
Okay, which response
is often a consequence

39
00:01:36,660 --> 00:01:38,460
of noncompliance?

40
00:01:38,460 --> 00:01:40,830
Go ahead and choose all that apply.

41
00:01:40,830 --> 00:01:42,030
Fines,

42
00:01:42,030 --> 00:01:43,650
license revocation,

43
00:01:43,650 --> 00:01:44,850
sanctions,

44
00:01:44,850 --> 00:01:46,860
or loss of stakeholder trust.

45
00:01:46,860 --> 00:01:48,243
Choose all that apply.

46
00:01:49,110 --> 00:01:50,116
What do you think?

47
00:01:50,116 --> 00:01:52,116
This is a consequence of non-compliance.

48
00:01:53,250 --> 00:01:55,650
Well, fines I'm gonna choose.

49
00:01:55,650 --> 00:01:58,080
License revocation or charter revocation,

50
00:01:58,080 --> 00:01:59,460
that absolutely could happen.

51
00:01:59,460 --> 00:02:02,010
Sanctions, definitely could happen.

52
00:02:02,010 --> 00:02:05,100
And for sure, loss of stakeholder trust.

53
00:02:05,100 --> 00:02:06,030
So all of these,

54
00:02:06,030 --> 00:02:07,920
fines, license revocation,

55
00:02:07,920 --> 00:02:10,920
sanctions, and loss of stakeholder trust

56
00:02:10,920 --> 00:02:14,580
are all consequences of noncompliance.

57
00:02:14,580 --> 00:02:15,413
Agree?

58
00:02:15,413 --> 00:02:16,830
Well, let's check.

59
00:02:16,830 --> 00:02:18,003
And that is correct.

60
00:02:19,890 --> 00:02:22,860
Number three: This privacy
enhancing technique

61
00:02:22,860 --> 00:02:24,810
can be used to sanitize data

62
00:02:24,810 --> 00:02:27,450
in such a way that it
cannot be related back

63
00:02:27,450 --> 00:02:29,520
to a given individual.

64
00:02:29,520 --> 00:02:30,990
Is it scrubbing,

65
00:02:30,990 --> 00:02:32,580
anonymization,

66
00:02:32,580 --> 00:02:33,720
masking,

67
00:02:33,720 --> 00:02:35,763
Or data minimization?

68
00:02:39,210 --> 00:02:41,040
So we're gonna sanitize data in a way

69
00:02:41,040 --> 00:02:44,250
that it can never be related
back to the given individual.

70
00:02:44,250 --> 00:02:45,100
What do you like?

71
00:02:47,220 --> 00:02:50,430
Well, I'm gonna choose anonymization.

72
00:02:50,430 --> 00:02:53,100
Anonymization, once I've anonymized data

73
00:02:53,100 --> 00:02:55,650
I cannot relate it back to the original,

74
00:02:55,650 --> 00:02:57,870
to the given individual.

75
00:02:57,870 --> 00:02:58,703
Agree?

76
00:02:58,703 --> 00:02:59,536
Let's check.

77
00:03:00,630 --> 00:03:02,310
And that is correct.

78
00:03:02,310 --> 00:03:03,603
All right, number four.

79
00:03:04,590 --> 00:03:07,147
This OECD Privacy Principle states that

80
00:03:07,147 --> 00:03:11,460
"personal data should not be
disclosed, made available,

81
00:03:11,460 --> 00:03:13,530
or otherwise used for purposes

82
00:03:13,530 --> 00:03:15,960
other than those specified."

83
00:03:15,960 --> 00:03:18,090
Is this individual participatioN,

84
00:03:18,090 --> 00:03:19,590
use limitation,

85
00:03:19,590 --> 00:03:21,000
data quality,

86
00:03:21,000 --> 00:03:23,250
or collection limitation?

87
00:03:23,250 --> 00:03:26,220
When we looked at the first five

88
00:03:26,220 --> 00:03:28,320
of the OECD Privacy Principles.

89
00:03:28,320 --> 00:03:30,690
This one says "personal data
should not be disclosed,

90
00:03:30,690 --> 00:03:33,390
made available, or
otherwise used for purposes

91
00:03:33,390 --> 00:03:35,157
other than those specified."

92
00:03:36,540 --> 00:03:38,130
What are you gonna choose?

93
00:03:38,130 --> 00:03:40,430
Put me on pause if you
need to think about it.

94
00:03:41,370 --> 00:03:44,340
This one is gonna be, use limitation.

95
00:03:44,340 --> 00:03:46,320
Use limitation says personal data

96
00:03:46,320 --> 00:03:48,030
should not be disclosed, made available,

97
00:03:48,030 --> 00:03:50,670
or otherwise used for purposes

98
00:03:50,670 --> 00:03:52,230
other than those specified.

99
00:03:52,230 --> 00:03:53,970
Let's double check.

100
00:03:53,970 --> 00:03:56,040
And that is correct.

101
00:03:56,040 --> 00:03:58,770
All right, our last
question, question five.

102
00:03:58,770 --> 00:04:02,910
Per GDPR, this role is
responsible for determining

103
00:04:02,910 --> 00:04:06,090
the purposes for which,
and the means by which,

104
00:04:06,090 --> 00:04:08,310
personal data is processed.

105
00:04:08,310 --> 00:04:10,170
Is this the data processor,

106
00:04:10,170 --> 00:04:11,790
the data controller,

107
00:04:11,790 --> 00:04:13,650
the data protection officer,

108
00:04:13,650 --> 00:04:15,960
or the data security officer?

109
00:04:15,960 --> 00:04:18,150
This is a coordinated GDPR, right?

110
00:04:18,150 --> 00:04:20,460
This is the role that's
responsible for determining

111
00:04:20,460 --> 00:04:23,670
the purposes for which,
and the means by which,

112
00:04:23,670 --> 00:04:25,743
personal data is gonna be processed.

113
00:04:26,610 --> 00:04:27,750
Is this our data processor,

114
00:04:27,750 --> 00:04:28,770
our data controller,

115
00:04:28,770 --> 00:04:32,130
our data protection
officer, known as a DPO,

116
00:04:32,130 --> 00:04:34,023
or our data security officer?

117
00:04:35,610 --> 00:04:38,040
What do you think it's gonna be?

118
00:04:38,040 --> 00:04:40,770
It's gonna be the one that's
in control of the data.

119
00:04:40,770 --> 00:04:43,020
That is going to be our data controller.

120
00:04:43,020 --> 00:04:45,060
Our data controller is
responsible for determining

121
00:04:45,060 --> 00:04:47,610
the purposes for which,
and the means by which,

122
00:04:47,610 --> 00:04:49,860
personal data is processed.

123
00:04:49,860 --> 00:04:51,540
Who actually processes the data?

124
00:04:51,540 --> 00:04:53,220
Well, that's our data processor.

125
00:04:53,220 --> 00:04:54,900
And who oversees all of this?

126
00:04:54,900 --> 00:04:58,140
That's our DPO, our
data protection officer.

127
00:04:58,140 --> 00:04:58,980
Agree?

128
00:04:58,980 --> 00:04:59,913
Let's check.

129
00:05:00,870 --> 00:05:02,103
And that's correct.

130
00:05:03,060 --> 00:05:05,220
So congratulations, great job.

131
00:05:05,220 --> 00:05:07,260
Five questions, I bet you nailed them all.

132
00:05:07,260 --> 00:05:08,130
Awesome!

133
00:05:08,130 --> 00:05:09,720
All right, so what's up next?

134
00:05:09,720 --> 00:05:13,560
Lesson 27, we're gonna
explain types and purposes

135
00:05:13,560 --> 00:05:15,840
of audits and assessments.

136
00:05:15,840 --> 00:05:16,790
I'll see you there.
