<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When using RUM, what do you need to take into account? in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47717#M1376</link>
    <description>&lt;P&gt;IMHO this is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is a case of foundational, best or most correct answer versus the simply correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rationale…&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RUM is pretty spooky and to do it in most jurisdictions you’ll need to have consent(specific) for the processing of this personal data. You’ll need to capture everything you do with it to ensure accountability, considering why and how you process the data and why. Moreover, in regards to harm you’d only start to really consider what the false negative/positive metrics meant to the individual in terms of harm, their interests etc. Often a detection will just alert a person that they should take a look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So while I think you totally consider false positives, I think that they are downstream of the privacy considerations and their impact will depend on many factors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless of course the system doing the RUM ‘releases the hounds’ or similar on a false positive with no human in the loop to countermand this.&lt;/P&gt;</description>
    <pubDate>Sun, 03 Oct 2021 06:04:32 GMT</pubDate>
    <dc:creator>Early_Adopter</dc:creator>
    <dc:date>2021-10-03T06:04:32Z</dc:date>
    <item>
      <title>When using RUM, what do you need to take into account?</title>
      <link>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47708#M1375</link>
      <description>&lt;P&gt;The question c05.087 of CCSP Official Practice Tests asks which you need to take into account when using real-user monitoring (RUM). And it says like the followings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;You need to take privacy concerns into account.&lt;/LI&gt;&lt;LI&gt;Though false positives are typical for RUM systems, they are incorrect as the answer.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I think you need to take privacy concerns into account not only when using RUM but also when implementing application logging. So I think privacy concerns are important concerns without RUM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While false positives are typical for RUM but are not relevant to application logging.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I cannot understand clearly why option C, "privacy concerns", is correct and option A, "false positive" is incorrect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:59:42 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47708#M1375</guid>
      <dc:creator>Masahiro</dc:creator>
      <dc:date>2023-10-09T09:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: When using RUM, what do you need to take into account?</title>
      <link>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47717#M1376</link>
      <description>&lt;P&gt;IMHO this is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is a case of foundational, best or most correct answer versus the simply correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rationale…&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RUM is pretty spooky and to do it in most jurisdictions you’ll need to have consent(specific) for the processing of this personal data. You’ll need to capture everything you do with it to ensure accountability, considering why and how you process the data and why. Moreover, in regards to harm you’d only start to really consider what the false negative/positive metrics meant to the individual in terms of harm, their interests etc. Often a detection will just alert a person that they should take a look.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So while I think you totally consider false positives, I think that they are downstream of the privacy considerations and their impact will depend on many factors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unless of course the system doing the RUM ‘releases the hounds’ or similar on a false positive with no human in the loop to countermand this.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 06:04:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47717#M1376</guid>
      <dc:creator>Early_Adopter</dc:creator>
      <dc:date>2021-10-03T06:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: When using RUM, what do you need to take into account?</title>
      <link>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47721#M1377</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/797288093"&gt;@Early_Adopter&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;Your reply has made me clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2021 09:18:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/When-using-RUM-what-do-you-need-to-take-into-account/m-p/47721#M1377</guid>
      <dc:creator>Masahiro</dc:creator>
      <dc:date>2021-10-03T09:18:40Z</dc:date>
    </item>
  </channel>
</rss>

