-
Explain the history and evolution of data privacy
Assessment Strategies
Essay
Reflection
Quiz
Criteria
Essay is written in clear, academic writing style
Essay differentiates between privacy and information security
Reflection includes specific ways privacy has evolved over time including historical and modern perspectives of privacy
Essay cites actions/events that have prompted industry changes and/or regulations/laws
-
Demonstrate data steward practices
Assessment Strategies
Project
Quiz
Criteria
Project includes the purpose and scope of the different types of information security governance documents
Project includes the guiding principles and goals for an information security governance program
Project identifies key roles and responsibilities in a RACI (Responsible, Accountable, Consulted, and Informed) matrix
Project describes how decisions are made and escalated
Project explains how the information security governance program supports regulatory compliance
Project outlines how governance effectiveness will be measured and reported
Project states the review frequency for the charter
-
Interpret privacy laws and landscape
Assessment Strategies
Case Study
Project
Quiz
Criteria
Project is written in clear, academic writing style
Project describes a real-world compliance failure or violation and what went wrong
Project summarizes how the compliance failure or violation has shaped the privacy landscape
Project selects a privacy law to develop a privacy audit checklist
Project identifies key requirements of the selected law and maps them to controls from privacy and security frameworks
Draft an audit question
Explain what to look for in evidence
Project includes translation of legal requirements into audit question and checklist items
Project explains the steps of a privacy audit
-
Apply breach response and notification processes
Assessment Strategies
Scenario Response
Written Product
Quiz
Criteria
Written product includes classification of the event, investigation, risk assessment, and notification requirements
Written product follows breach response process for given scenario, and details each step
Written product contains a draft breach notification letter compliant with selected requirements
Written product explains the breach response process, including incident response and breach notification
-
Employ privacy risk management processes
Assessment Strategies
Scenario Response
Project
Quiz
Criteria
Project includes documenting the risk assessment process steps
Project includes asset identification, threat identification, determining risk level/rating, and recommended mitigating controls
Project includes a completed risk register for given scenario
-
Apply privacy supporting technologies
Assessment Strategies
Scenario Response
Project
Written Product
Quiz
Criteria
Project follows each step of the risk assessment process
Project includes classifying data by identifier types
Project includes demonstration of evaluating re-dentification risk using privacy enhancing methods
Project includes implementing and testing the recommended privacy enhancing technologies
Written product includes rationale for recommendations
Project includes completed privacy risk assessments pre- and post-implementation
Product includes the dataset that was modified with privacy enhancing technologies
Product includes executive briefing draft on scenario, risk assessments, privacy enhancing technologies utilized, and recommendations
-
Evaluate privacy concerns in emerging technology
Assessment Strategies
Scenario Response
Project
Quiz
Criteria
Project follows process for privacy impact assessment (PIA) of a new technology
Project describes the technology, data, and purpose of the scenario new technology
Project identifies potential impacts and privacy risks
Project assesses the risk levels using a risk matrix
Project includes recommended mitigation strategies for identified risks
Project assesses transparency and user controls of the scenario
Project includes approval recommendation with rationale
Scenario response includes key elements as specified by the instructor
Scenario response is effective
-
Explain ethical implications in data privacy
Assessment Strategies
Scenario Response
Report
Quiz
Criteria
Report includes a completed ethical impact assessment (EIA)
Report includes a completed ethical matrix with selected privacy principles
Project identifies stakeholders and ethical impacts
-
Analyze Third-Party Risks
Assessment Strategies
Scenario Response
Report
Essay
Quiz
Criteria
Report includes a third-party risk assessment
Report identifies and classifies the data involved
Report identifies third-party risks
Report includes recommended risk-mitigating controls
Report includes risk ratings using a risk matrix
Essay summarizes the monitoring and reporting step
Essay summarizes the remediation and response step
Essay summarizes the termination and exit procedures step
-
Apply Privacy by Design principles
Assessment Strategies
Project
Written Product
Quiz
Criteria
Project includes a completed privacy impact assessment (PIA)
Project includes identifying and rating privacy risks
Project includes recommended Privacy Enhancing Technologies (PETs)
Project identifies multiple training topics for given scenario
Project includes third-party evaluations
Written product describes how recommendations support each of the seven foundational principles