2023-02-02-ISACA-2023年度隐私实践研究报告_22页_1mb
报告摘要
Summary of Privacy in Practice 2023
Core Content
Privacy in Practice 2023 is a report based on the results of the ISACA® global State of Privacy Survey conducted in the fourth quarter of 2022. It provides an in-depth analysis of current trends in privacy practices across enterprises, including staffing, budgets, program development, training, legal and regulatory compliance, and the implementation of privacy by design.
Main Findings
Privacy Staffing
- The average number of full-time-equivalent (FTE) employees with privacy-related responsibilities is 26, slightly up from 25 in 2022.
- Legal/compliance and technical privacy roles are both understaffed, with 44% and 53% of respondents reporting this, respectively.
- The time to fill privacy positions has generally increased or remained the same, with 19% and 23% of respondents indicating significant or somewhat increased time for legal/compliance and technical roles, respectively.
- Experience is the most important factor in determining a candidate’s qualifications for privacy roles.
- Technical privacy roles are more likely to experience increased demand than legal/compliance roles.
- Expert-level roles are the most difficult to fill, with 76% of respondents identifying this as the biggest challenge.
Skill Gaps
- The biggest skill gap is a lack of experience with different technologies and applications (63%).
- Other significant gaps include:
- Experience with frameworks and controls (54%)
- Understanding of laws and regulations (46%)
- Lack of technical expertise (45%)
- Business insight (39%)
- IT operations knowledge (38%)
- Soft skills (34%)
- Networking/infrastructure knowledge (33%)
- Business ethics (18%)
Privacy Budgets
- 42% of respondents indicate their enterprise privacy budget is somewhat or significantly underfunded.
- 36% of respondents believe their privacy budget is appropriately funded, an increase from 33% in 2022.
- 12% of respondents expect a significant or somewhat decrease in privacy budgets over the next 12 months.
- There is a slight improvement in budget funding compared to 2022, with 35% of respondents expecting an increase in budgets, down to 34% this year.
Privacy Program Trends
- Chief Privacy Officer (CPO) is the most common role accountable for privacy, with 21% of respondents.
- Chief Information Officer (CIO) and executive-level security officer are also key roles, with 16% and 14% of respondents, respectively.
- Lack of executive support and lack of visibility/influence are the top two obstacles to forming a privacy program (39% and 38%).
- A strong C-level privacy advocate can help mitigate these challenges.
Interaction with Other Areas
- Privacy teams interact most frequently with information security (32%), legal/compliance (29%), and risk management (22%).
- They also engage with IT operations and development, procurement, internal audit, human resources, sales/marketing/customer relations, finance, product/business development, and public/media relations.
Board of Directors' Involvement
- 55% of respondents believe their board adequately prioritizes privacy.
- 22% do not believe the board prioritizes privacy, and 20% are unsure.
- A compliance-driven approach to privacy is common, but it may lead to reactive rather than proactive privacy initiatives.
- Ethically driven or combination of both approaches are also present.
Monitoring Privacy Programs
- 30% of enterprises evaluate the number of privacy incidents as a metric for program effectiveness.
- However, relying solely on this metric is reactive and may not reveal weaknesses until a breach occurs.
- Forward-looking metrics are recommended to avoid high penalties and reputational damage.
Privacy Awareness Training
- 85% of enterprises provide privacy awareness training.
- 59% review and revise training annually, 24% as new laws and regulations go into effect, 9% every two-to-five years, and 4% do not revise it.
- Pre- and post-training assessments are considered a stronger method to evaluate training effectiveness.
- 26% of respondents believe privacy training has a strong positive impact, and 47% believe it has some positive impact.
- 57% of enterprises keep privacy training separate from security training, while 31% combine them.
Privacy Frameworks, Laws, and Regulations
- 82% of respondents use a framework or law to manage privacy.
- 73% consider it mandatory to address privacy with documented policies, standards, and procedures.
- The top three frameworks used are:
- GDPR (50%)
- NIST Privacy Framework (46%)
- ISO/IEC 27002:2013 (36%)
- European respondents are more likely to use GDPR (79%), while U.S. respondents are more likely to use the NIST Privacy Framework (61%).
- 23% of respondents find it difficult or very difficult to identify and understand privacy obligations.
Privacy Breaches and Failures
- 11% of respondents experienced a material privacy breach in the past 12 months, up slightly from 10% in 2022.
- 64% of respondents reported no breaches, 17% were unsure, and 9% preferred not to answer.
- Common privacy failures include:
- Poor data governance
- Inadequate access controls
- Inconsistent data handling
- Lack of encryption
- Inadequate incident response
- Poor third-party management
Privacy by Design
- 30% of enterprises always practice privacy by design, and 30% frequently do so.
- Enterprises that always practice privacy by design are more likely to:
- Separate privacy training from security training (65% vs. 57% total)
- Have higher confidence in their ability to ensure data privacy (65% vs. 40% total)
- Use AI or automation more (25% vs. 20% total)
Conclusion
Privacy is becoming a more critical and strategic function within enterprises. While challenges such as understaffing and budget constraints persist, there is a positive trend in awareness and investment. Experience and technical expertise remain key factors in hiring qualified privacy professionals. The integration of privacy by design and cross-functional collaboration are increasingly seen as essential to successful privacy programs. As privacy regulations continue to evolve, regular communication between legal and technical teams, along with effective training and monitoring, will be vital for maintaining compliance and protecting data subjects.
试读结束,高清完整版pdf/doc/ppt,请点下载