Thu, April 4 @ 3:15 p.m. – 4:30 p.m.
Room 147B, Convention Center
Cara Bloom, Privacy Engineer, Netflix
Serge Egelman, Research Director, Usable Security and Privacy, International Computer Science Institute; Founder and Chief Scientist, AppCensus
Vaibhav Garg, CIPT, Cybersecurity & Privacy Research and Public Policy Research, Executive Director, Comcast Cable
Nandita Rao Narla, CIPP/US, CIPM, CIPT, FIP, Head of Technical Privacy and Governance, DoorDash
Privacy by design requires us to embed privacy as a principle from the start of the product development process. However, this shift requires privacy engineering at every subsequent stage. Every organization thus faces the challenge of scaling this process without adding significant cost. Furthermore, these processes must align with developer workflow and not require developers themselves to be experts in privacy. This panel provides a roadmap of how to achieve this difficult task. The panel will present this in four stages. The first is how product teams can determine, document, and communicate privacy requirements? The second is how controls correspond to these requirements reviewed at design stage. The third is how the implementation of these controls is validated in build stage. The fourth is how teams pen-test applications to find any gaps in these implementations pre-production.
What you will learn:
• What are the key elements of a privacy engineering program?
• Potential tools and techniques to scale a program without extensive investment.
• How to drive privacy with developers without requiring deep subject matter expertise.