Cyber Voices
In this episode of Cyber Voices, the official podcast of AISA, recorded live on the floor at BrisSEC in Brisbane, host David Savva-Willett sits down with Nicole Stephensen, a strategic risk and privacy professional recognised for her local and international expertise in privacy program management and her work as an expert witness on the reasonable steps needed to secure personal information across its lifecycle. Nicole is a Fellow of the Australian Information Security Association (FAISA) and a leading member of the International Association of Privacy Professionals (IAPP). Fresh from a panel alongside Queensland Privacy Commissioner Alexander White and IDCARE interim Group CEO Charlotte Davidson, Nicole unpacks what a privacy impact assessment really is, why it belongs in every cyber security toolkit, and what happens when organisations skip it. She also shares a memorable reframe from the panel: think of a privacy impact assessment less like a yes or no gate and more like a navigation system. The question stops being can we do this and becomes how do we get there safely, steering around the potholes, roadblocks and unnecessary costs along the way. The conversation explores where privacy and security overlap and where they differ, the reasonable steps expected under Australian privacy law, the recent alignment of Queensland privacy law with the federal approach, and the most common mistake of all, which is simply not doing a privacy impact assessment when you could. As Nicole explains, a good PIA does not have to be onerous or expensive, with free toolkits and templates available from both the federal and state privacy regulators. Links to resources mentioned in this episode: Federal resources, from the Office of the Australian Information Commissioner (OAIC): Guide to undertaking privacy impact assessments https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/guide-to-undertaking-privacy-impact-assessments [https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/guide-to-undertaking-privacy-impact-assessments] Privacy impact assessment tool (the free, adaptable template) https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/privacy-impact-assessment-tool [https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/privacy-impact-assessment-tool] 10 steps to undertaking a privacy impact assessment https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/10-steps-to-undertaking-a-privacy-impact-assessment [https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/privacy-impact-assessments/10-steps-to-undertaking-a-privacy-impact-assessment] Queensland resources, from the Office of the Information Commissioner (OIC): Privacy impact assessments (step by step guide) https://www.oic.qld.gov.au/guidelines/for-government/guidelines-privacy-principles/privacy-impact-assessments [https://www.oic.qld.gov.au/guidelines/for-government/guidelines-privacy-principles/privacy-impact-assessments] Undertaking a Privacy Impact Assessment (the full guideline) https://www.oic.qld.gov.au/guidelines/for-government/guidelines-privacy-principles/privacy-impact-assessments/undertaking-a-privacy-impact-assessment [https://www.oic.qld.gov.au/guidelines/for-government/guidelines-privacy-principles/privacy-impact-assessments/undertaking-a-privacy-impact-assessment] PIA templates, including the threshold privacy assessment and the PIA report templates https://www.oic.qld.gov.au/information-for/information-privacy-officers [https://www.oic.qld.gov.au/information-for/information-privacy-officers]
71 afleveringen
Reacties
0Wees de eerste die een reactie plaatst
Meld je nu aan en word lid van de Cyber Voices community!