Saturday, March 24, 2018

GDPR: Everybody panic and run around screaming "Consent & Fines"

As the May 25th deadline approaches, many companies approach to this looks more and more like a dumpster fire, with project managers, lawyers, and vendors becoming increasingly hysterical.




What could have been a boon to privacy and security seems to have turned into something of an exercise in pointlessness and hiding skeletons in the closet by implementing technology quick-fixes flogged by vendors touting silver bullets.

I hate saying this, but start getting the basics right. If you don't understand what you have you can't ensure privacy or security - Implementing even  the best controls on shaky ground is just going to add complexity, and potentially decrease the protection of your information (whether PII or just your own Intellectual Property). Encrypting databases when everyone is local admin on the database servers, everyone has access to all key material, and SQLi is the best documented means to access the data anyway isn't really helping, but just playing pretend and that is going to make us all look bad in the end.

[/RANT]

Recommended reading:
https://www.cnil.fr/en/pia-software-updates-beta-version
https://www.peerlyst.com/posts/gdpr-compliance-step-by-step-part-1-the-prerequisites-david-froud
http://www.davidfroud.com/free-resource-the-gdpr-in-plain-english/
https://www.peerlyst.com/posts/the-gdpr-wiki-nicole-lamoureux
https://www.cisecurity.org/cybersecurity-best-practices/
https://www.sans.org/
http://www.pragmaticcso.com/
https://www.itculate.io/2017/06/p2-mapping-microservice-relationships/




No comments: