Chapter 19. Customer Data Access Strategy
At some point in a startup’s lifecycle, its leaders decide that they need to be ready to go public in 18 months, and a flurry of IPO-readiness activity kicks off. This strategy focuses on a company working on IPO readiness that has identified a gap in internal controls for managing user data access. The company wants to meaningfully improve its security posture around user data access, but it has had a number of failed security initiatives over the years.
Most of those initiatives failed because they significantly degraded internal workflows for teams like customer support, reverting and subverting the initial progress over time and eventually resulting in little long-term effect. This strategy represents the Chief Information Security Officer’s (CISO’s) attempt to acknowledge and overcome those historical challenges while meeting the company’s IPO readiness obligations and—most importantly—doing right by its users.
Reading This Document
This chapter contains just one document, Document 19-1: How Should We Control Access to User Data?, from 2022. Security topics are always sensitive, and as such this document is not from any given company, but is rather the amalgamation of experiences at several distinct companies.
If you’re reading this document with the goal of applying the strategies it puts forward, start at the top and read to the end. If, on the other hand, your main goal is to understand the thinking behind it, read the sections ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access