<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Privacy in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Data-Privacy/m-p/42684#M3118</link>
    <description>&lt;P&gt;Don't expose data to a partner unless absolutely necessary.&amp;nbsp;One of the downfalls of this new &lt;A href="https://searchapparchitecture.techtarget.com/definition/API-economy#:~:text=The%20API%20economy%20refers%20to,APIs)%20in%20a%20controlled%20way." target="_blank" rel="noopener"&gt;&lt;STRONG&gt;API Economy&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;is that many developers are not following "best practices" for protecting a data subjects privacy. Enforce the principle of least privilege by ensuring any third-party that has access to the endpoints is authorized and access is provisioned accordingly. I love the &lt;A href="https://owasp.org/www-project-api-security/" target="_blank" rel="noopener"&gt;OWASP API Security Top 10&lt;/A&gt;. Check it out.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2021 20:24:02 GMT</pubDate>
    <dc:creator>AppDefects</dc:creator>
    <dc:date>2021-01-20T20:24:02Z</dc:date>
    <item>
      <title>Data Privacy</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Data-Privacy/m-p/42680#M3117</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we expose APIS which return email address plain format&lt;/P&gt;&lt;P&gt;Can we expose APIS which ask email address as input plain format&lt;/P&gt;&lt;P&gt;Can we expose APIS which return user address plain format&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;GDPR Article 5 mandates that personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PCIDSS also allows to use PCI data if proper security measures are in place.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any suggestions??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 19:47:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Data-Privacy/m-p/42680#M3117</guid>
      <dc:creator>iluom</dc:creator>
      <dc:date>2021-01-20T19:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Data Privacy</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Data-Privacy/m-p/42684#M3118</link>
      <description>&lt;P&gt;Don't expose data to a partner unless absolutely necessary.&amp;nbsp;One of the downfalls of this new &lt;A href="https://searchapparchitecture.techtarget.com/definition/API-economy#:~:text=The%20API%20economy%20refers%20to,APIs)%20in%20a%20controlled%20way." target="_blank" rel="noopener"&gt;&lt;STRONG&gt;API Economy&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;is that many developers are not following "best practices" for protecting a data subjects privacy. Enforce the principle of least privilege by ensuring any third-party that has access to the endpoints is authorized and access is provisioned accordingly. I love the &lt;A href="https://owasp.org/www-project-api-security/" target="_blank" rel="noopener"&gt;OWASP API Security Top 10&lt;/A&gt;. Check it out.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 20:24:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Data-Privacy/m-p/42684#M3118</guid>
      <dc:creator>AppDefects</dc:creator>
      <dc:date>2021-01-20T20:24:02Z</dc:date>
    </item>
  </channel>
</rss>

