ISACA:2023年度隐私实践研究报告_22页_1mb
报告摘要
Privacy in Practice 2023 Summary
Core Content
This report summarizes the findings of the ISACA® global State of Privacy Survey, conducted in the fourth quarter of 2022. It explores the current state of privacy practices in enterprises, focusing on staffing, budgets, program trends, awareness training, breaches, and the concept of Privacy by Design.
Main Points
-
Privacy Staffing:
The average number of full-time-equivalent privacy staff per enterprise is 26, slightly higher than last year. Both legal/compliance and technical privacy roles are understaffed, with technical roles more so (53% vs. 44%). However, there has been some improvement compared to last year.- 27% of respondents report open legal/compliance privacy positions.
- 34% report open technical privacy roles.
- Filling these roles is often time-consuming, with 19% of legal/compliance roles and 23% of technical roles experiencing significant or somewhat increased time to fill.
- Experience is the most important factor in determining candidate qualifications, with 76% of respondents identifying expert-level roles as the hardest to fill.
-
Skill Gaps:
The biggest skill gap among privacy professionals is a lack of experience with technologies and applications (63% of respondents). Other common gaps include:- Experience with frameworks and controls (54%)
- Understanding of laws and regulations (46%)
- Lack of technical expertise (45%)
- Business insight (39%)
- IT operations knowledge (38%)
- Soft skills (34%)
- Networking/infrastructure knowledge (33%)
- Business ethics (18%)
-
Privacy Budgets:
42% of respondents indicate that their enterprise privacy budget is somewhat or significantly underfunded, a slight improvement from 45% last year.- 36% say the budget is appropriately funded.
- 12% expect a decrease in their privacy budget in the next 12 months.
- 34% expect an increase in their privacy budget.
-
Privacy Program Trends:
The role accountable for privacy varies, with the chief privacy officer (21%), chief information officer (16%), and executive-level security officer (14%) being the most common.- 39% of respondents cite lack of executive or business support as an obstacle to forming a privacy program.
- 38% report lack of visibility and influence in the organization as an obstacle.
-
Team Interaction:
Privacy teams frequently interact with:- Information security (32%)
- Legal/compliance (29%)
- Risk management (22%)
- IT operations and development
- Procurement
- Internal audit
- HR
- Sales/marketing/customer relations
- Finance
- Product/business development
- Public/media relations
-
Board Involvement:
55% of respondents believe their board adequately prioritizes privacy, while 22% do not believe it does. A lack of communication from the board may explain the uncertainty.- Boards may view privacy programs as either compliance-driven or ethically driven, or a combination of both.
-
Monitoring Privacy Programs:
Enterprises use various methods to monitor their privacy programs, including:- Evaluating the number of privacy incidents (30%)
- Using pre- and post-training assessments
- Tracking completion rates
- Reviewing compliance with legal and regulatory requirements
- Conducting audits and assessments
-
Privacy Awareness Training:
85% of enterprises provide privacy training to employees. Training is typically reviewed annually (59%), with some organizations revising it as new laws are implemented.- 57% of enterprises separate privacy training from security training.
- 47% of respondents believe privacy training has some positive impact, while 26% say it has a strong positive impact.
-
Privacy Frameworks, Laws, and Regulations:
82% of respondents use a framework or law to manage privacy, with the most common being:- GDPR (50%)
- NIST Privacy Framework (46%)
- ISO/IEC 27002:2013 (36%)
Regional differences exist, with 79% of European respondents using GDPR, and 61% of U.S. respondents using the NIST Privacy Framework.
-
Privacy Breaches and Failures:
- 11% of respondents experienced a material privacy breach in the past 12 months (up from 10% last year).
- 23% find it difficult or very difficult to identify and understand their privacy obligations.
- Common privacy failures include inadequate data protection measures, lack of documentation, and insufficient training.
-
Privacy by Design:
- 30% of respondents indicate their enterprises always practice privacy by design.
- 30% say they frequently practice it.
- Enterprises that always practice privacy by design are more likely to:
- Separate privacy training from security training
- Be confident in their ability to protect sensitive data
- Use AI or automation
Key Information
- Understaffing: Both technical and legal/compliance roles are understaffed, but technical roles are more affected. This trend has improved slightly from last year.
- Training and Awareness: Privacy awareness training is crucial and is often provided regularly. However, it is often reactive and needs to be evaluated for effectiveness.
- Budgets: Privacy budgets are still a concern for many enterprises, but there has been a slight improvement in funding compared to previous years.
- Regulatory Landscape: The global privacy regulatory landscape is evolving rapidly, requiring close collaboration between legal and technical privacy teams.
- Privacy by Design: Practicing privacy by design is associated with better privacy outcomes, including increased confidence and the use of advanced technologies.
Conclusion
The report highlights the ongoing challenges in privacy management, including staffing shortages, budget constraints, and skill gaps. However, there is a positive trend in improved awareness and understanding of privacy issues, as well as a growing emphasis on Privacy by Design. Enterprises that prioritize privacy and invest in adequate staffing and training are better positioned to meet evolving regulatory requirements and protect data subjects effectively.
试读结束,高清完整版pdf/doc/ppt,请点下载