37
The Role of Privacy in the Transportation Sector Elisa May Cuevas Executive Director IV National Privacy Commission

The Role of Privacy in the Transportation Sector

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: The Role of Privacy in the Transportation Sector

The Role of Privacy in the Transportation Sector

Elisa May CuevasExecutive Director IV

National Privacy Commission

Page 2: The Role of Privacy in the Transportation Sector

The Bigger role of Data Privacy in the Transportation industry

https://csrps.com/Media/Default/2017%20Reports/2017-Ponemon-Cost-of-Data-Breach-Study.pdf

…privacy reaches far beyond simple confidentiality – which is crucial in the transportation sector as the data collected may often lead to actual or perceived privacy violations.

Page 3: The Role of Privacy in the Transportation Sector

https://csrps.com/Media/Default/2017%20Reports/2017-Ponemon-Cost-of-Data-Breach-Study.pdf

Malicious Attack

System Glitch

Human Error

Root cause of Data Breach

47 % External

53 % Internal

Page 4: The Role of Privacy in the Transportation Sector

https://blog.varonis.com/the-world-in-data-breaches/

https://www.scmagazine.com/home/news/data-breach/rail-europe-north-america-discloses-breach-of-e-commerce-it-platform/

https://www.zdnet.com/article/130k-users-data-leaked-via-chinas-train-ticketing-site/

https://www.thestar.com/business/2017/12/11/privacy-commissioner-to-investigate-uber-data-breach.html

Page 5: The Role of Privacy in the Transportation Sector

http://pwc.blogs.com/cyber_security_updates/2015/04/transport-logistics-companies-cyber-security-is-relevant-to-you-too.html

“All we do is move stuff around.”

“We don’t make anything so it’s not like we have any designs or plans to steal.”

“We only work with corporates, so we don’t hold credit card information.”

How is Data Privacy Relevant to us?

Page 6: The Role of Privacy in the Transportation Sector

https://blog.varonis.com/the-world-in-data-breaches/

Global Data Breach Statistics

7 MillionData RecordsCompromised

Every day

56records

CompromisedEvery Second

3.26Million dollars

Average cost of data breach

Page 7: The Role of Privacy in the Transportation Sector

https://blog.varonis.com/the-world-in-data-breaches/

Countries with Highest Number of Stolen Identities

Rail Europe North America

Online TrainTicket Service

Page 8: The Role of Privacy in the Transportation Sector

To remain in business and become a trusted delivery partner, organisations need to demonstrate that these risks have been considered and effective controls are in place to address them.

As the latest round of cyber incidents underline, no company (transport and logistics included) can assume they’re outside of the firing-line.

http://pwc.blogs.com/cyber_security_updates/2015/04/transport-logistics-companies-cyber-security-is-relevant-to-you-too.html

Page 9: The Role of Privacy in the Transportation Sector

https://www.forbes.com/sites/leemathews/2017/08/16/notpetya-ransomware-attack-cost-shipping-giant-maersk-over-200-million/#1ad353c64f9ahttps://www.bleepingcomputer.com/news/security/maersk-reinstalled-45-000-pcs-and-4-000-servers-to-recover-from-notpetya-attack/

Page 10: The Role of Privacy in the Transportation Sector

SECURITY

PersonalInformation

A Personal data breach refers to a breach of

security leading to the accidental or unlawful

destruction, loss, alteration, unauthorized disclosure of, or access

to, personal data transmitted, stored, or

otherwise processed

A Breach is the unauthorized acquisition, access, use, or disclosure of protected information, which compromises the security or privacy of such information

PRIVACY

Impact on Data

v Confidentialityv Integrityv Availability

Governance of the unauthorized

Impact on people

v Collectionv Usev Storagev Sharingv Disposal

Governance of the authorized

SensitivePersonal

Information

Page 11: The Role of Privacy in the Transportation Sector

Building Privacy ResilienceIn your workplace

Organizational Measures

Physical Measures

Technical Measures

Page 12: The Role of Privacy in the Transportation Sector

Organizational Measures

Measures to be

implemented across

the organizational

structure.

• Policy, Procedures guidance & Training

Page 13: The Role of Privacy in the Transportation Sector

Organizational Measures

Acceptable Use Policy

Collection Policy

Disposal Policy

Storage Policy

Clear Desk Policy

Page 14: The Role of Privacy in the Transportation Sector

Collection Policy

Page 15: The Role of Privacy in the Transportation Sector

Acceptable Use Policy

Page 16: The Role of Privacy in the Transportation Sector

Disposal Policy

Page 17: The Role of Privacy in the Transportation Sector

Storage Policy

Page 18: The Role of Privacy in the Transportation Sector

Clear Desk Policy

Page 19: The Role of Privacy in the Transportation Sector

Physical Measures

Files Under Lock and Key

Storage of Personal Data

Shred Paper Files

Lock Servers and Networks

ID user Access

Page 20: The Role of Privacy in the Transportation Sector

Storage of Personal Data

Page 21: The Role of Privacy in the Transportation Sector

Files under lock and key or in a secure area.

Page 22: The Role of Privacy in the Transportation Sector

Shred the paper files

Page 23: The Role of Privacy in the Transportation Sector

Keep servers and network switch boards in a locked

room and control access to it.

Page 24: The Role of Privacy in the Transportation Sector

ID as user access

Page 25: The Role of Privacy in the Transportation Sector

Mail marked “private and confidential” if intended for the

eyes of the addressee only.

Page 26: The Role of Privacy in the Transportation Sector

Do not leave computers and cellphones unlocked in the

workspace

Page 27: The Role of Privacy in the Transportation Sector

Label files with personal

information “Confidential”

Page 28: The Role of Privacy in the Transportation Sector

Find the Identity

exposures in the picture.

Page 29: The Role of Privacy in the Transportation Sector
Page 30: The Role of Privacy in the Transportation Sector

Technical Measures

Page 31: The Role of Privacy in the Transportation Sector

Confidential Mail boxes

Page 32: The Role of Privacy in the Transportation Sector

The use of password protected device, e.g. password

protected USB flash drives

Page 33: The Role of Privacy in the Transportation Sector

Each employee should have his own user ID. They should be treated like

office keys and not shared or compromised in any way.

Page 34: The Role of Privacy in the Transportation Sector

A secure network should include an effective firewall and antivirus to keep out unwanted connections.

Page 35: The Role of Privacy in the Transportation Sector

The use of encryption

LOG IN ***********

Page 36: The Role of Privacy in the Transportation Sector

Top Data Protection threats for Transportation and Logistics Sector

• Advanced persistent threats (APTs) and increased use of

mobile devices

• Security talent shortage

• Breaches are frequent; processes are flawed

• Outsourcing is on the rise

https://www.smartcitiesworld.net/special-reports/special-reports/the-cyber-security-threat-to-transportation

Page 37: The Role of Privacy in the Transportation Sector

Thank you!5th Flr., Philippine International

Convention Center, PICC Complex, 1307 Pasay City

[email protected]