The Three Privacy Engineering Objectives

Security has confidentiality, integrity and availability. Privacy has three objectives of its own. NIST named them predictability, manageability and disassociability. The privacy engineering objectives exist for a plain reason. A system can be entirely secure and still create problems for the people whose information it processes.

They come from NISTIR 8062, An Introduction to Privacy Engineering and Risk Management in Federal Systems, published in January 2017. The CIPT Body of Knowledge is the IAPP document that sets out what the exam covers, and it names all three in Domain V.

One spelling note first. NIST writes disassociability. Some course materials render it dissociability. Both mean the same objective.

Why the security triad runs out

NIST draws a line between two risk models. In the security model, harm follows unauthorised activity. An organisation loses confidentiality, integrity or availability. In the privacy model, the processing is planned and permitted, and consequences for individuals arise anyway.

NIST gives that second case a name. A problematic data action causes an adverse effect, or problem, for individuals.

Smart meters are the worked example. Granular household electricity readings can reveal when a house is occupied and which appliances are running. The concern has little to do with whether the utility can keep those readings secure.

That distinction explains why the privacy engineering objectives exist at all. Confidentiality, integrity and availability describe a system that resists attack. They say nothing about a system that behaves exactly as designed and still exposes people.

The three privacy engineering objectives

NIST defines them in the glossary of the report:

  • Predictability: enabling of reliable assumptions by individuals, owners and operators about personally identifiable information and its processing by a system.
  • Manageability: providing the capability for granular administration of personally identifiable information including alteration, deletion and selective disclosure.
  • Disassociability: enabling the processing of personally identifiable information or events without association to individuals or devices beyond the operational requirements of the system.

Predictability

Predictability sits underneath the transparency and accountability principles. Framing it as reliable assumptions changes what an assessment asks. A weak assessment records that a notice went up. A better one asks whether people read it, understood it and behaved as anticipated.

Predictability also supports purpose specification without freezing a system. It asks operators to assess the effect of a change in processing. It does not ask them to avoid change.

Manageability

Manageability underpins access and amendment, minimisation, quality and integrity. Without granular administration, an organisation cannot correct inaccurate information with any confidence. Nor can it dispose of obsolete records or honour stated preferences.

NIST makes no claim about who should hold that control. Letting individuals edit their own records would defeat a fraud detection system. Manageability still holds where an appropriately privileged actor can make the change.

Disassociability

Candidates blur this one of the privacy engineering objectives into confidentiality. Confidentiality prevents unauthorised access. Disassociability addresses exposure inside an authorised perimeter. It actively blinds identity or activity wherever the system does not need the link.

Identity proofing and direct health care both require association. NIST adds a caution worth remembering. Difficulty or expense does not turn an association into an operational requirement. That is accepted risk, described honestly.

Putting the objectives to work on a scenario

The privacy engineering objectives work best as a diagnostic. A scenario describes a system behaving badly. The question is which capability is missing.

People are surprised by what the system does with their data. That is a predictability gap. Records cannot be corrected, deleted or disclosed selectively. That is manageability. Identifiers travel further than the transaction needs, even though every recipient is authorised. That is disassociability.

Reasoning from the missing capability is faster and more reliable than reasoning from the label.

Privacy engineering objectives and privacy risk

The same report pairs the privacy engineering objectives with a privacy risk model. Likelihood there means the probability that a data action becomes problematic for a typical individual. So user perception and context form part of the assessment.

Impact is harder. Only individuals experience a privacy problem directly. NIST suggests proxies an organisation can measure: legal compliance costs, mission failure costs such as reluctance to use the service, reputational costs, and internal culture costs affecting morale and productivity.

Cryptographic techniques map neatly onto disassociability. NIST notes that anonymity, de-identification, unlinkability, unobservability and pseudonymity could sit in a taxonomy underneath it. That is the bridge to the de-identification content elsewhere in the exam.

The piece on answering the definition question first sets out a method for definitional questions. The guide to studying for the CIPT covers how the domains fit together.

Similar Posts