The intersection of privacy and security
Organizations’ data owners often face conflicting mandates and data requests when privacy and security teams work independently. A single information risk governance team may save money and create a more efficient process. As a result, it is easier for the company’s data owners to fulfill their responsibilities of interpreting and enforcing the law.
Separate programs for privacy and security put stakeholders in danger of being misled, and resources are at risk of being wasted because of the separate, sometimes duplicate, plans and implementation efforts. Integrating both programs allows for much more effective work.
In the context of privacy and security, this usually means developing risk assessment procedures that stakeholders must complete before implementing their projects (sometimes known as “security reviews” or “privacy impact assessments”). With a single risk assessment team, both programs...