This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
Security & Privacy Security and privacy encompass practices, technologies, norms, and laws that protect information, systems, and individuals from unauthorized access, disclosure, alteration, or destruction. The field intersects with National Institute of Standards and Technology, European Union Agency for Cybersecurity, Internet Engineering Task Force, World Wide Web Consortium, and major technology firms such as Microsoft, Google, Apple Inc., Amazon (company), and Meta Platforms; it also engages standards bodies like International Organization for Standardization and Institute of Electrical and Electronics Engineers.
The discipline integrates concepts from Alan Turing's theoretical work, Claude Shannon's information theory, and applied research at institutions like Massachusetts Institute of Technology, Stanford University, Carnegie Mellon University, University of Cambridge, and University of Oxford. Operational practice draws on frameworks developed by National Institute of Standards and Technology (including the NIST Cybersecurity Framework), guidance from European Union Agency for Cybersecurity, and procurement standards used by United States Department of Defense and multinational corporations such as Siemens. Historical incidents involving Equifax data breach, Yahoo data breaches, Target Corporation data breach, Sony Pictures hack, and operations like Stuxnet and NotPetya illustrate the convergence of espionage, sabotage, and criminality.
Threat actors range from state-sponsored groups like those attributed to Advanced Persistent Threat 28 and Fancy Bear to criminal organizations behind REvil and Conti (ransomware group), as well as opportunistic actors leveraging exploits disclosed by Shadow Brokers. Vectors include software vulnerabilities in products from Microsoft, Cisco Systems, Oracle Corporation, and open-source projects maintained by communities around Linux Foundation and Apache Software Foundation; supply chain compromises have targeted vendors like SolarWinds. Vulnerabilities arise from misconfigurations exemplified by incidents at Amazon Web Services and legacy protocols such as Secure Sockets Layer that were supplanted by Transport Layer Security. Social engineering campaigns exploit profiles on Facebook, LinkedIn, and Twitter and leverage techniques first categorized in work by Kevin Mitnick and documented in investigations like those into Cambridge Analytica.
Risk governance uses models developed by NIST, ISO/IEC 27001, and corporate governance approaches at firms such as IBM and Deloitte. Boards and executives reference guidance from Committee of Sponsoring Organizations of the Treadway Commission and reporting standards influenced by Securities and Exchange Commission mandates and European Union directives. Incident response and continuity planning coordinate with agencies like Cybersecurity and Infrastructure Security Agency and international cooperation through Interpol and NATO mechanisms. Third-party risk, vendor due diligence, and insurance markets involve firms such as Aon and Marsh & McLennan Companies.
Cryptographic controls build on algorithms standardized by National Institute of Standards and Technology and bodies like Internet Engineering Task Force; deployments use protocols such as Transport Layer Security, IPsec, and Secure Shell. Identity and access management practices leverage standards including OAuth 2.0, OpenID Connect, and Security Assertion Markup Language as implemented in platforms from Okta and Microsoft Azure Active Directory. Network defenses use architectures from Cisco Systems and Juniper Networks combined with detection technologies influenced by research at SANS Institute and VirusTotal. Endpoint protection, vulnerability management, patching processes, and application security (including OWASP Top Ten) are operationalized in continuous integration pipelines pioneered by organizations like GitHub and GitLab.
Privacy regimes reflect principles from instruments such as the Organisation for Economic Co-operation and Development Guidelines and the Council of Europe Convention 108, and statutory regimes like the General Data Protection Regulation and the California Consumer Privacy Act. Data handling employs techniques including anonymization, pseudonymization, and differential privacy informed by research at Google Research and Microsoft Research. Consent frameworks, data subject rights, and cross-border transfer mechanisms involve legal instruments like Privacy Shield (and its judicial scrutiny in cases involving the Court of Justice of the European Union). Advocacy and watchdog roles are played by organizations such as Electronic Frontier Foundation and Privacy International.
Regulatory landscapes include sectoral rules such as Health Insurance Portability and Accountability Act in the United States, financial regulations from Financial Industry Regulatory Authority, and telecommunications directives from European Commission. Enforcement actions by bodies like the Federal Trade Commission, Information Commissioner's Office, and Data Protection Commission (Ireland) shape compliance behavior; high-profile litigation and settlements have involved entities including Facebook (now Meta Platforms), Google LLC, and Equifax. International agreements and norms development occur via forums like the United Nations General Assembly and G20.
Emerging areas include risks from quantum computing to current public-key cryptography, prompting standardization efforts at National Institute of Standards and Technology and research in quantum-safe schemes by teams at IBM Research and Google Quantum AI. Machine learning systems developed by OpenAI, DeepMind, and academic labs raise concerns about data poisoning, model inversion, and automated decision-making accountability; mitigation strategies draw on work at Allen Institute for AI and regulatory proposals from the European Commission on artificial intelligence. Other frontier issues involve Internet of Things security in products from Samsung Electronics and Huawei, supply chain integrity highlighted by SolarWinds and Kaseya incidents, and geopolitical tensions influencing norms in forums like United Nations cyber diplomacy.
Category:Information security