References and Further Reading
Standards and Frameworks
- NIST Privacy Framework: A tool for improving privacy through enterprise risk management.
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations.
- ISO/IEC 27701: Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management.
Methodologies
- LINDDUN: A Privacy Threat Modeling Framework (https://www.linddun.org/).
- Privacy by Design: Ann Cavoukian's foundational 7 principles.
Regulations
- GDPR: General Data Protection Regulation (EU).
- CCPA / CPRA: California Consumer Privacy Act.