全网唯一标准王
#BHUSA @BlackHatEvents Better Privacy Through Offense: How To Build a Privacy Red Team Scott Tenaglia Engineering Manager, Privacy Red Team, Meta#BHUSA @BlackHatEvents Information Classification: GeneralAgenda 01 The Case for Offensive Privacy 02 Security and Privacy 03 Meta’s Privacy Red Team 04 Operations Ideas 05 Final Thoughts#BHUSA @BlackHatEvents Information Classification: GeneralThis talk is... ➢The start of a conversation about offensive privacy. ➢Potentially a blueprint for how your company could create a similar team or offering. ➢To help you understand how privacy red teaming fits into a holistic privacy program.This talk is not... ➢A product or service pitch. ➢A conversation about any other aspect of Meta beyond privacy red teaming. ➢About absolutes. ➢The final word on this topic.#BHUSA @BlackHatEvents Information Classification: GeneralAgenda 01 The Case for Offensive Privacy 02 Security and Privacy 03 Meta’s Privacy Red Team 04 Operations Ideas 05 Final Thoughts#BHUSA @BlackHatEvents Information Classification: GeneralHave you ever... ➢Been on an op, come across some PII, but don’t know what to do about it? ➢Been asked to start recording access to user data as a finding? ➢Been asked to perform a more privacy -focused assessment? ➢Had a finding but no one cared because it have enough “security” impact? #BHUSA @BlackHatEvents Information Classification: GeneralSecurity and Privacy programs help mitigate risk. Perceived Risk Mitigations Red Team *Image courtesy of the NIST Privacy Framework https:// www.nist.gov /privacy -framework/privacy -frameworkRed teams identify actual risk by testing mitigations from an adversarial perspective. Mitigations are a combination of people, process, and technology (i.e., a blue team).#BHUSA @BlackHatEvents Information Classification: General Scraping Red TeamScanning Identify the actual risk to systems and networks. *Image courtesy of the NIST Privacy Framework https:// www.nist.gov /privacy -framework/privacy -framework Perceived Risk Mitigations Attack Surface EnumerationLarge Scale Data Access Identify the actual risk to the user’s privacy and their data.#BHUSA @BlackHatEvents Information Classification: GeneralAgenda 01 The Case for Offensive Privacy 02 Security and Privacy 03 Meta’s Privacy Red Team 04 Operations Ideas 05 Final Thoughts

pdf文档 US-22-Tenaglia-Better-Privacy-Through-Offense-How-To-Build-a-Privacy-Red-Team

文档预览
中文文档 27 页 50 下载 1000 浏览 0 评论 0 收藏 3.0分
温馨提示:本文档共27页,可预览 3 页,如浏览全部内容或当前文档出现乱码,可开通会员下载原始文档
US-22-Tenaglia-Better-Privacy-Through-Offense-How-To-Build-a-Privacy-Red-Team 第 1 页 US-22-Tenaglia-Better-Privacy-Through-Offense-How-To-Build-a-Privacy-Red-Team 第 2 页 US-22-Tenaglia-Better-Privacy-Through-Offense-How-To-Build-a-Privacy-Red-Team 第 3 页
下载文档到电脑,方便使用
本文档由 SC 于 2023-05-03 01:08:09上传分享
友情链接
站内资源均来自网友分享或网络收集整理,若无意中侵犯到您的权利,敬请联系我们微信(点击查看客服),我们将及时删除相关资源。