Field lesson P1 / 10 min

Privacy is not a CIA checkbox

Separate security objectives (confidentiality, integrity, availability, and resilience) from privacy objectives (appropriate use, minimization, and individual rights) without treating encryption or a framework map as a legal determination.

foundationsprivacygrccia

What you’ll be able to do

  • Distinguish a security objective (CIA plus resilience) from a privacy objective (appropriate collection, use, retention, disclosure, and individual expectations).
  • Name one control that can serve both security and privacy, and one situation where those goals can conflict.
  • Explain why encryption or access control is not the same as privacy done.
  • Write an overlap, conflict, and escalate note for a synthetic HR export, and name counsel or a privacy officer as the people who decide obligations.

A locked file can still be the wrong use

Riverstone locks TrackPort. Customer delivery addresses are encrypted at rest, only the dispatch role can export them, and the export writes an audit trail. Maya can still watch the file be used badly. A wellness vendor asks HR for the same export, plus driver home addresses and medical-clearance flags, “because the file is already encrypted.” The lock held. The purpose did not.

F1 taught confidentiality, integrity, and availability as three jobs on one asset. The TrackPort figure stops there on purpose: authenticity, non-repudiation, privacy, and safety are not a fourth letter on that picture. This lesson is the habit those letters do not cover. Read F6 if classification, retention, and restore are still fuzzy, and the GRC risk-sentence lesson (R1) if you want the loss written with an owner before you talk about a control. Neither is required to start.

Security protects the asset. Privacy asks whether the use fits.

Security, in the sense F1 and F6 already use, is about protecting assets from unauthorized activity and from loss of confidentiality, integrity, or availability, and about resilience when a loss happens anyway. A ransomware event that stops the dock is a security failure even if nobody’s personal life is exposed. A destroyed backup is a security failure. So is a stranger reading the HR export.

Privacy, kept jurisdiction-light, is about whether collection, use, retention, and disclosure fit the reason the information was gathered, and about the expectations and obligations owed to the person the record describes. Data minimization is the habit of taking and keeping only what that purpose needs. Individual rights and obligations—access, correction, limits on further use—belong in that column. This page does not say which right applies to Riverstone, and it is not advice for a real employer.

NIST SP 800-53 Revision 5 is the vocabulary bridge. Its title and catalog are security and privacy controls for information systems and organizations (final Revision 5, with Update 1 on the CSRC page, and Release 5.2.0 noted by NIST on 27 August 2025). Use a control name when you need a shared word. Do not treat the catalog as homework to implement every control, and do not treat a control ID as a ruling that a statute applies.

  • Security question: who must not read, change, or knock this asset over, and how do we recover?
  • Privacy question: why was this collected, who may use it, how long may it stay, and what does the person get to expect?
  • Same file can raise both questions. Answer them in different sentences.

One control can serve both

Named access control on the HR export serves both columns. Only the HR owner, Jordan’s manager for a stated employment task, can open the file. That protects confidentiality, which is a security objective. It also reduces the chance that a wellness vendor or a marketing list uses home addresses for a purpose HR never collected them for. An audit trail of who exported the file supports the security review and gives a privacy reviewer something to check. Encryption of the file at rest supports confidentiality in the same way F6 already taught: it stops a stranger who steals the disk.

None of those controls finishes the privacy column. Encryption does not choose the purpose. Access control does not decide the retention date. An audit trail that copies the whole medical-clearance flag into every log line can itself be more collection. “We encrypted it, so privacy is handled” is the mistake this lesson exists to kill.

Monitoring and retention can pull the other way

Security monitoring wants enough detail to reconstruct an export later: who, what file, when, and sometimes the contents. Privacy minimization wants the log to prove the event without keeping a second copy of the driver’s home address and medical flag. Both sentences can be true. The conflict is which fields the log is allowed to store, not whether logging is “good” or “bad.”

Retention is the other clash. A security lead wants the full HR export kept for years so a later investigation can replay it. A purpose limit may say the employment file should be deleted when that purpose ends. Long forensic retention and a short purpose limit are not the same clock. Broad break-glass admin access has the same shape: security wants a way in during an incident; least privilege and purpose limitation want that door narrow, named, and closed again. F5 already taught least privilege. This lesson only adds the privacy side of the tension.

Maya does not pick the winner in the lesson. She writes the conflict down and asks counsel or the privacy officer which clock and which log fields apply. The security team does not own every privacy obligation by holding the keys.

Laws stay in labeled explainers

HIPAA, GDPR, FERPA, and similar names are sector obligations. Atlas keeps them as separate labeled explainers on the industry paths, with the publisher’s own scope notes. This lesson does not decide whether Riverstone, a clinic, or a school is covered, and it does not give effective dates or a compliance verdict. Healthcare readers already have a signpost that health data is not one law. Education readers already have a signpost that FERPA coverage depends on the institution. Follow those pages, and the labeled explainers they link, when the question is whether a sector rule might apply. Stay here when the question is whether the job is security, privacy, or both.

CSF 2.0 (NIST CSWP 29, final 26 February 2024) is a cybersecurity framework: outcomes for protecting information and systems. ISO/IEC 27001:2022, with Amd 1:2024, is a certifiable information security management system, scoped to the system that was audited. Privacy programs often sit beside those efforts. An ISO/IEC 27001 certificate is not privacy-law compliance, and a mapping from SP 800-53 to a statute does not settle GDPR or HIPAA. One green framework row is not that determination.

Exit: overlap, conflict, escalate

The practice artifact is a synthetic HR export: driver home addresses and medical-clearance flags, collected so dispatch and occupational health can staff the Oakland dock. It is not an employer file and not a place to paste a real roster. Write three lines. Overlap: one control that helps both security and privacy. Conflict: one place the security habit and the privacy habit disagree. Escalate: counsel or the privacy officer, not a sentence that says “we are compliant.”

At work, name one data type you already keep where a security retention clock and a privacy retention clock might disagree. Keep the employer’s records off this page.

Exit ticket for the synthetic HR export. Teaching note only. Not a compliance determination.
LineWhat Maya writesWhat she does not write
OverlapNamed access control: only the HR owner can open the export. That protects confidentiality and limits use to the employment purpose.“Encrypted, so privacy is done.”
ConflictSecurity wants the full export and detailed logs kept for a later investigation. A purpose limit may require deletion sooner, and a log may not need the medical flag.A retention period invented in the incident channel.
EscalateAsk counsel or the privacy officer which clock and which log fields apply, and record their answer.“Security owns HIPAA, GDPR, and FERPA because we hold the keys.”

CHECK YOUR JUDGMENT

The HR export is encrypted, access is limited to the HR owner, and every export is logged. A vendor still wants the file for a neighborhood flyer because “the security controls are green.” What does Maya record?

Put your learning to work ↗

Find your next idea.

Tip: press / to open search. Escape closes this window.