Karl Kopper Caltrans Privacy and Chief Information Security Officer - - PowerPoint PPT Presentation

karl kopper
SMART_READER_LITE
LIVE PREVIEW

Karl Kopper Caltrans Privacy and Chief Information Security Officer - - PowerPoint PPT Presentation

Karl Kopper Caltrans Privacy and Chief Information Security Officer Four Questions Every Auditor Should Know the Answer To What is What is PII? De- Identification? What is Re-Identification? Privacy Internal Controls & Behavioral


slide-1
SLIDE 1

Karl Kopper

Caltrans Privacy and Chief Information Security Officer

slide-2
SLIDE 2

Four Questions

Every Auditor Should Know the Answer To

slide-3
SLIDE 3

What is PII? What is Re-Identification? What is De- Identification?

slide-4
SLIDE 4

Privacy

Internal Controls & Behavioral Analytics

slide-5
SLIDE 5

First VoIP Call First Touch Screen First Computer Monitor First Ethernet Network First UPC Barcode System First Cell Phone Call

1973 1973

slide-6
SLIDE 6

First VoIP Call Touch Screen Developed First Computer Monitor Ethernet Created First UPC Barcode System

First Cell Phone Call

1973 1973 Martin Cooper Martin Cooper

slide-7
SLIDE 7
slide-8
SLIDE 8

U.S. Department of Health, Education, and Welfare “HEW Report” of 1973 U.S. Department of Health, Education, and Welfare “HEW Report” of 1973

Personally Identifiable Information

  • No secret record-keeping systems
  • Individuals must know what and how
  • Individuals must be able to correct
  • Data about individuals must not be reused
slide-9
SLIDE 9

Privacy act of 1974 Privacy act of 1974

Personally Identifiable Information

The increasing use of computers and sophisticated information technology, while essential to the efficient

  • perations of the Government, has

greatly magnified the harm to individual privacy that can occur from any collection, maintenance, use, or dissemination of personal information.

slide-10
SLIDE 10
slide-11
SLIDE 11

Personally Identifiable Information

Financial

Payment Card Industry – Data Security Standards

Cardholder Data Sensitive Authentication Data

slide-12
SLIDE 12

Personally Identifiable Information

Health Insurance Portability and Accountability Act of 1996

 Individually Identifiable Health Information (IIHI)

Health

slide-13
SLIDE 13

To determine whether information is PII, the agency shall perform an assessment of the specific risk that an individual can be identified using the information with other information that is linked or linkable to the individual.

Office of Management and Budget M-17-12 2017 Office of Management and Budget M-17-12 2017

Personally Identifiable Information

slide-14
SLIDE 14

Personally Identifiable Information

California Consumer Privacy Act

“You should have the right to know what personal information businesses collect about you and your children and what they do with it, including to whom they sell it.”

California

slide-15
SLIDE 15

Personally Identifiable Information

California Consumer Privacy Act

“It is almost impossible to apply for a job, raise a child, drive a car, or make an appointment without sharing your personal information..”

California

slide-16
SLIDE 16

Personally Identifiable Information

California Consumer Privacy Act  Consuming History or Tendency  Browsing History  Geolocation Data  Audio, Electronic, Visual, Thermal, Olfactory or Similar Information

California

slide-17
SLIDE 17

Personally Identifiable Information

California Consumer Privacy Act  Consuming History or Tendency  Browsing History  Geolocation Data  Audio, Electronic, Visual, Thermal, Olfactory or Similar Information “Inferences drawn from any of the information identified above”

California

slide-18
SLIDE 18

State HIPAA

Gramm-Leach-Bliley

PCI Federa l GDPR

slide-19
SLIDE 19

Privacy

slide-20
SLIDE 20

“The State of California is committed to unlocking the value of government data to propel innovation, improve the delivery of public services and empower the people of California while protecting privacy.”

State of California Administrative Manual Section 5160

slide-21
SLIDE 21

Privacy

Innovation

slide-22
SLIDE 22

Innovation

31% of fatal accidents involved alcohol 3,382 fatalities involving a distracted driver Men were drivers in 65% of accidents (2015-2017) 2,790 Lives were saved through the use of Airbags

slide-23
SLIDE 23

Innovation

De-Identification

slide-24
SLIDE 24

Privacy

slide-25
SLIDE 25

Governor William Weld Keynote Graduation Address Bentley College 1996

slide-26
SLIDE 26

Visit Date Diagnostics Procedures Zip Birth Date Gender Name Address Party Voted Health Data Voter List

Latanya Sweeney MIT Graduate Student

slide-27
SLIDE 27

Re-Identification

slide-28
SLIDE 28
slide-29
SLIDE 29
slide-30
SLIDE 30
slide-31
SLIDE 31

Skiing in Salt Lake

slide-32
SLIDE 32

Kiteboarding in La Ventana, Baja, Mexico

slide-33
SLIDE 33

Burning Man

slide-34
SLIDE 34

Burning Man

700 million activities 1.4 trillion latitude/longitude points 7.7 trillion pixels 5 terabytes data Activity duration = 100 thousand years

slide-35
SLIDE 35

Burning Man

“Our global heatmap is the largest, richest, and most beautiful dataset

  • f its kind.”
slide-36
SLIDE 36
slide-37
SLIDE 37
slide-38
SLIDE 38
slide-39
SLIDE 39

Soldiers, remember, rotate from one assignment to the next…

slide-40
SLIDE 40

Traffic Counter Loop Detector Automated Toll System Carpool Lane Infrared Scanner Connected Vehicle

Privacy Concerns

ITS and Locational Privacy: Suggestions for Peaceful Coexistence

Hubert H. Humphrey School of Public Affairs University of Minnesota Frank Douma & Sarah Aue 2011

Speed/Red Light Camera

slide-41
SLIDE 41

What is PII? What is Re-Identification? What is De- Identification? What does your

  • rganization do

to protect PII?

slide-42
SLIDE 42

Security Information & Event Management

slide-43
SLIDE 43

UEBA

slide-44
SLIDE 44

User & Entity Behavior

al

Analytics

Executive Assets Accessed Insider Threat Compromised Credentials

slide-45
SLIDE 45

What is PII? What is Re-Identification? What is De- Identification? What does your

  • rganization do

to protect PII?