<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Derived PII in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38531#M1152</link>
    <description>&lt;P&gt;The term you are looking for is aggregate or combinal data.&amp;nbsp; At what point to you continue adding data where the entire set is now PII.&amp;nbsp; In education, FERPA has a rule that you don't take data sets with a group of less than 10.&amp;nbsp; It prevents derived PII instances.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Aug 2020 21:59:15 GMT</pubDate>
    <dc:creator>PuettK</dc:creator>
    <dc:date>2020-08-27T21:59:15Z</dc:date>
    <item>
      <title>Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38464#M1142</link>
      <description>&lt;P&gt;OK, so having an episode of old-timers today. What is the proper term for a set of data that collectively constitutes PII? For example, the individual data points alone are not PII, but collectively, provide a picture that is "linkable" to an individual? PII that is derived from the sum of non-PII data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 15:50:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38464#M1142</guid>
      <dc:creator>CV_SEC</dc:creator>
      <dc:date>2020-08-26T15:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38467#M1143</link>
      <description>&amp;gt; CV_SEC (Newcomer I) posted a new topic in Privacy on 08-26-2020 11:50 AM in the&lt;BR /&gt;&lt;BR /&gt;&amp;gt; OK, so having an episode of old-timers today. What is the proper term for a set&lt;BR /&gt;&amp;gt; of data that collectively constitutes PII? For example, the individual data&lt;BR /&gt;&amp;gt; points alone are not PII, but collectively, provide a picture that is "linkable"&lt;BR /&gt;&amp;gt; to an individual? PII that is derived from the sum of non-PII data.&lt;BR /&gt;&lt;BR /&gt;Other than just PII or de-anonimized I can't think of any particular term.&lt;BR /&gt;Inference and amalgamation attacks are pretty much as old as databases&lt;BR /&gt;themselves ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;I used to worry about robots becoming self-aware &amp;amp; taking over&lt;BR /&gt;the world. Then I tried to use a motion sensor faucet.&lt;BR /&gt;- &lt;A href="https://twitter.com/philipnation/status/564496243762937856" target="_blank"&gt;https://twitter.com/philipnation/status/564496243762937856&lt;/A&gt;&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Wed, 26 Aug 2020 17:39:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38467#M1143</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-08-26T17:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38468#M1144</link>
      <description>&lt;P&gt;Thanks for the quick reply. I've discussed the topic many times but never had anyone ask me for the exact term.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 17:51:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38468#M1144</guid>
      <dc:creator>CV_SEC</dc:creator>
      <dc:date>2020-08-26T17:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38470#M1145</link>
      <description>&lt;P&gt;I found this in NIST SP 800-122&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"PII data composed of individuals‘ names, fingerprints, or SSNs uniquely and &lt;STRONG&gt;directly&lt;/STRONG&gt; identify individuals,&lt;BR /&gt;whereas PII data composed of individuals‘ ZIP codes and dates of birth can &lt;STRONG&gt;indirectly&lt;/STRONG&gt; identify individuals&lt;BR /&gt;or can significantly narrow large datasets"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't find anything specifically to what you're after but somebody else might find it.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 18:00:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38470#M1145</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2020-08-26T18:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38488#M1146</link>
      <description>&lt;P&gt;Aggregated&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2020 19:47:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38488#M1146</guid>
      <dc:creator>MikeinGlennDale</dc:creator>
      <dc:date>2020-08-26T19:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38498#M1147</link>
      <description>&amp;gt; MikeinGlennDale (Viewer) posted a new reply in Privacy on 08-26-2020 03:47 PM in&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Aggregated&lt;BR /&gt;&lt;BR /&gt;That's the one. Sorry.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;Freedom isn't worth having if it doesn't include the freedom to&lt;BR /&gt;make mistakes. - Mahatma Gandhi&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Wed, 26 Aug 2020 21:52:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38498#M1147</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-08-26T21:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38499#M1148</link>
      <description>Do we have a source or security framework that specifically references PII and aggregate being connected as such? I only ask because aggregate can be applied to all types of data or information when collecting it in one spot.</description>
      <pubDate>Wed, 26 Aug 2020 22:16:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38499#M1148</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2020-08-26T22:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38508#M1149</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;&amp;nbsp; the answer I gave about data aggregation and derived PII is based on personal experience.&amp;nbsp; I'm pretty sure that was the term my new friends&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1063244743"&gt;@CV_SEC&lt;/a&gt;&amp;nbsp; were looking for.&amp;nbsp; I was just trying to update my CPE's and then I saw the message board and was like oh he's trying to think of Aggregate LOL.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best relatable I can think of is the Cambridge Analytica data analytics.&amp;nbsp; They took individual data points for use with influencing outcomes specified by the Cambridge Analytica customers.&amp;nbsp; Recommend the Netflix documentary The Great Hack for the details about methods, and techniques.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a case to be made that data in aggregate has a higher "value" than independent data points.&amp;nbsp; Is there a correlation in value / sensitivity?&amp;nbsp; In the late 1990's Netscape (the web browser company) was among the first to monetize data about a customer.&amp;nbsp; They could charge something like $50 for a collection of data points aggregated with a high degree of confidence that those individual data points when taken in aggregate form a whole person.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The invented term PII is arguable treated as more sensitive data than traditional sensitive data types.&amp;nbsp; So...back to the original question about Derived PII.&amp;nbsp; While not an answer to a test question exactly I would like to hear other thoughts about the subject matter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;&amp;nbsp;you made reference to inference attacks in databases and I think that hits the mark accurately.&amp;nbsp; I'm not sure if this message board is designed to help people study and pass exams or if it's intended to share real world experience and examples.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 10:47:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38508#M1149</guid>
      <dc:creator>MikeinGlennDale</dc:creator>
      <dc:date>2020-08-27T10:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38512#M1150</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/545208923"&gt;@MikeinGlennDale&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp; I'm not sure if this message board is designed to help people study and pass exams or if it's intended to share real world experience and examples.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I like to think of this place as a way to 'aggregate' theory with real world experience and examples. Also, Welcome! Stick around and share occasionally.&amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 13:20:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38512#M1150</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2020-08-27T13:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38526#M1151</link>
      <description>Appreciate the welcome &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/690706113"&gt;@tmekelburg1&lt;/a&gt;. Sure, I'll give it a shot.</description>
      <pubDate>Thu, 27 Aug 2020 20:10:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38526#M1151</guid>
      <dc:creator>MikeinGlennDale</dc:creator>
      <dc:date>2020-08-27T20:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Derived PII</title>
      <link>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38531#M1152</link>
      <description>&lt;P&gt;The term you are looking for is aggregate or combinal data.&amp;nbsp; At what point to you continue adding data where the entire set is now PII.&amp;nbsp; In education, FERPA has a rule that you don't take data sets with a group of less than 10.&amp;nbsp; It prevents derived PII instances.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 21:59:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/Derived-PII/m-p/38531#M1152</guid>
      <dc:creator>PuettK</dc:creator>
      <dc:date>2020-08-27T21:59:15Z</dc:date>
    </item>
  </channel>
</rss>

