Security Governance, Risk & Privacy Topics
Governance, compliance frameworks, regulatory requirements, compliance implementation, and compliance-driven risk management. Covers compliance frameworks (SOX, GDPR, HIPAA, FCPA, etc.), regulatory interpretation, compliance control design, audit and control effectiveness evaluation, and compliance process management. For operational security implementation and technical threat mitigation, see Security Engineering & Operations.
Health Data Privacy and HIPAA
Protecting health and medical data under HIPAA and equivalent sector rules: PHI, the Privacy and Security Rules, covered entities and business associates, and permitted uses and disclosures. Covers de-identification standards and safeguards specific to healthcare data. Includes how health-data constraints shape system and product design.
Data Breach and Privacy Incident Response
Responding to privacy incidents and breaches: detection, containment, investigation, severity and breach classification, and regulator and individual notification within statutory deadlines. Covers complaint intake and resolution, escalation, and balancing transparency against risk during an incident. Includes coordinating the cross-functional response and post-incident remediation.
Data Subject Rights and Request Handling
Operationalizing individual rights: access, rectification, erasure, portability, restriction, and objection requests. Covers identity verification, response timelines, locating data across systems to fulfill a request, and handling edge cases and exemptions. Includes designing systems that can execute deletion and export reliably at scale.
Cross-Border Data Transfers and Multi-Jurisdictional Compliance
Handling personal-data flows and compliance obligations that span multiple jurisdictions with conflicting or overlapping requirements. Covers adequacy decisions, standard contractual clauses, transfer impact assessments, data residency and localization constraints, and reconciling regional regulations into a control set that satisfies the strictest applicable rule while remaining operable globally. Includes emerging and regional privacy laws beyond the major frameworks and the complexity of operating under many regimes at once.
GDPR Principles and Compliance
The General Data Protection Regulation in depth: the six lawful bases, data subject rights, accountability and records obligations, DPO requirements, and enforcement and fines. Covers how GDPR principles translate into concrete engineering and product controls. Includes controller and processor obligations and demonstrating compliance.
Privacy by Design and Default
Embedding privacy into architecture and the development lifecycle: the privacy-by-design principles, privacy-protective defaults, and on-device or edge processing to minimize data exposure. Covers integrating privacy controls into product and program design and into engineering workflows rather than bolting them on. Includes designing privacy-first solutions and reference architectures.
Security Ethics and Responsible Disclosure
Ethical and legal boundaries in security work and the norms of responsible vulnerability disclosure. Covers coordinated disclosure and bug-bounty conduct, staying within legal and ethical limits during testing, handling conflicts of interest, and ethical decision making under pressure. Especially relevant where offensive testing meets legal and ethical constraints.
Compliance Automation and Tooling
Using technology to scale and continuously enforce compliance and privacy. Covers GRC platforms, compliance-as-code, continuous control monitoring, automated evidence collection, and integrating compliance and privacy checks into engineering pipelines. Focuses on how tooling reduces manual effort and enables continuous rather than point-in-time assurance.
Data Minimization and Retention
Collecting and keeping only what is necessary: data minimization at collection, purpose limitation, and retention scheduling with automated deletion. Covers defining retention periods, enforcing them technically, and defensibly disposing of data. Includes balancing operational or analytics needs against minimization obligations.