Privacy, Security, and Organizational Use of Social Media
Policy development is a core competency required of Chief Information Security Officers. In order to develop policy, however, it is necessary that the CISO and other business leaders understand the underlying issues and, where technology is involved, they must also understand those issues as well.
Read this article: https://www.bigcommerce.com/blog/social-media-advertising/#the-6-best-social-networks-for-ecommerce-advertising
Choose one of the social media platforms listed in the article above and research its privacy policy. Then prepare an “expert opinion” paper for the senior leaders in your organization. (If you cannot find the privacy policy for a given social media platform, choose a different platform.)
For your opinion paper, you must
• perform additional research and then write your informed opinion as to the privacy issues that exist or may exist for that platform
• identify specific privacy issues which could adversely affect Padgett-Beale
• identify any additional issues with that platform which could adversely affect Padgett-Beale’s cybersecurity posture
• answer the following questions in your paper
- What do you think about your selected platform’s approach to privacy?
- How would the platform’s privacy policy impact an organization that is contemplating using the platform for advertising and marketing?
- Which of the social media services provided by the platform would you allow Padgett-Beale’s marketing department to use?
- Should Padgett-Beale’s employees in general be permitted to use the platform during the work day (using company networks and/or IT resources). What risks are involved with permitting such usage?
- What recommendations that Padgett-Beale adopt to govern the organization’s use of social media platforms for marketing and other forms of internal and external communications?
- What policies are required (what type of policy would you recommend that Padgett-Beale adopt to govern the organization’s use of social media platforms for marketing and other forms of internal and external communications)?
Post your 5 to 7 paragraph “expert opinion” as a reply to this topic. Remember to cite your sources and include your reference list at the end of your posting.
Sample Answer
Expert Opinion: Addressing Privacy and Cybersecurity Risks with TikTok for Padgett-Beale
To: Senior Leaders, Padgett-Beale, Inc.From: [Your Name], Chief Information Security Officer (CISO) Date: June 20, 2025 Subject: Analysis of TikTok’s Privacy Posture and Recommendations for Padgett-Beale’s Engagement
This paper provides an informed opinion on the privacy and cybersecurity implications of Padgett-Beale’s potential use of TikTok, a prominent social media platform, for advertising, marketing, and general employee usage. Given Padgett-Beale’s business in Resort Operations, Reservations Services, and Resort Affiliates, coupled with its past audit findings regarding data breach preparedness, a rigorous assessment of any third-party platform’s risk profile is paramount.
TikTok’s Approach to Privacy and Underlying Issues
TikTok’s privacy policy, while detailing extensive data collection, presents a complex picture. On one hand, it transparently lists numerous categories of data collected: information users provide (account details, user-generated content, messages, contacts, purchase info), automatically collected information (usage patterns, inferred demographics, technical device info, location data – approximate and precise with permission, image/audio data), and data from third parties. This broad collection, particularly the “inferred information” and the potential for background data collection even when the app is inactive, raises significant privacy concerns. TikTok’s stated