Data Security Involves Human Behavior and, Therefore, Is More an Art, Than a Science

©2011 Braydon Fuller
©2011 Braydon Fuller

I have recently written of how data breach responses and response plans cannot be one-size-fits-all and must be tailored to the unique needs of the company involved, as well as its culture. That is, they must be tailored to fit a company of humans dealing with humans. This morning I read an article that discusses that human approach to data security — a slight variation on what I was discussing regarding data breach and response — but a very close sibling.

The ultimate premise of the article is that, because data security involves interaction with human beings, it must necessarily be an art, not a science. The same is true for data breach response plans as well as the data breach response process. Here is a little teaser of the thought provoking article:

Because humans play a key role in data security, this makes data security quite complicated. Managing human behavior is immensely challenging. People are hard to control. They need to be educated. They need to care. But people forget. They have lapses in judgment. They don’t learn what they’re supposed to learn and don’t do what they’re supposed to do.

*   *   *

Data security thus involves difficult tradeoffs. It is something that must be delicately balanced with other considerations. Good data security involves forging an appropriate level of risk. How much risk is appropriate? That’s a hard question to answer, because it involves the nature and sensitivity of the data being protected, the amount of data per individual being protected, the number of individuals whose data is being protected, the potential harms from the breach of that data to the individuals involved, the potential harms form the breach to the organization, the nature of the threats, the financial and efficiency costs of various measures to reduce risk, and the standard data security practices in industry.

via Data Security Is an Art, Not Just a Science | LinkedIn.

Published by Shawn E. Tuma

Shawn Tuma is an attorney who is internationally recognized in cybersecurity, computer fraud and data privacy law, areas in which he has practiced for nearly two decades. He is a Partner at Spencer Fane, LLP where he regularly serves as outside cybersecurity and privacy counsel to a wide range of companies from small to midsized businesses to Fortune 100 enterprises. You can reach Shawn by telephone at 972.324.0317 or email him at stuma@spencerfane.com.

Leave a comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Business Cyber Risk

Subscribe now to keep reading and get access to the full archive.

Continue reading