Nist special Publication 1500-4 draft: nist big Data Interoperability Framework: Volume 4, Security and Privacy

Opt-In Revisited

While standards organizations grapple with frameworks such as the one developed here, and until an individual's privacy and security can be fully protected using such a framework, some observers believe that the following two simple “protocols” ought to govern PII Big Data collection in the meantime.

Suggested Protocol one: An individual can only decide to opt-in for inclusion of their personal data manually, and it is a decision that they can revoke at any time.

Suggested Protocol two: The individual's privacy and security opt-in process should enable each individual to modify their choice at any time, to access and review log files and reports, and to establish a self-destruct timeline (similar to the EU’s “right to be forgotten”).

17. Acronyms

The acronym list will be updated when the text has been finalized.

AC&S access control and security

ACL Access Control List

AuthN/AuthZ Authentication/Authorization

BAA business associate agreement

CDC U.S. Centers for Disease Control and Prevention

CEP complex event processing

CIA confidentiality, integrity, and availability

CINDER DARPA Cyber-Insider Threat

CoP communities of practice

CSA Cloud Security Alliance

CSA BDWG Cloud Security Alliance Big Data Working Group

CSP Cloud Service Provider

DARPA Defense Advanced Research Projects Agency’s

DDoS distributed denial of service

DOD U.S. Department of Defense

DoS denial of service

DRM digital rights management

EFPIA European Federation of Pharmaceutical Industries and Associations

EHR electronic health record

EU European Union

FBI U.S. Federal Bureau of Investigation

FTC Federal Trade Commission

GPS global positioning system

GRC governance, risk management, and compliance

HIE Health Information Exchange

HIPAA Health Insurance Portability and Accountability Act

HITECH Act Health Information Technology for Economic and Clinical Health Act

HR human resources

IdP identity provider

IoT Internet of Things

IP Internet Protocol

IT information technology

LHNCBC Lister Hill National Center for Biomedical Communications

M2M machine to machine

MAC media access control

NBD-PWG NIST Big Data Public Working Group

NBDRA NIST Big Data Reference Architecture

NIEM National Information Exchange Model

NIST National Institute of Standards and Technology

OSS operations systems support

PaaS platform as a service

PHI protected health information

PII personally identifiable information

PKI public key infrastructure

SAML Security Assertion Markup Language

SDLC Systems Development Life Cycle

SIEM security information and event management

SKU stock keeping unit

SLA service-level agreement

STS Security Token Service

TLS Transport Layer Security

VM virtual machine

VPN virtual private network

XACML eXtensible Access Control Markup Language

18. References

This reference section needs to be consolidated, linked to text, and formatted.


Reference from Mark during 1/24/17 NBD-PWG meeting:

a “Contributors” are members of the NIST Big Data Public Working Group who dedicated great effort to prepare and substantial time on a regular basis to research and development in support of this document.

b Typically such supporting SnP Big Data is provided as part of a fully integrated Build Phase, but some solutions can implement “Security as a Service,” with some or all Security and Privacy resources provided by third parties. Third parties may specialize in SnP for specific domains, with machine learning, ontologies and other specialized resources that may be beyond the capabilities of Build architects.

c Gunderson, "Drone patrol: Unmanned craft find key role in U.S. border security," Minnesota Public Radio, Feb. 2015. [Online]. Available:

d US Department of Justice, “Guidance on Domestic Use of Unmanned Aircraft Systems,”, undated.

e Source:


g For further information, see the frameworks suggested by the Association for Information and Image Management (AIIM; /) and the MIKE 2.0 Information Governance Association (

h The concept of a “fabric” for security and privacy has precedent in the hardware world, where the notion of a fabric of interconnected nodes in a distributed computing environment was introduced. Computing fabrics were invoked as part of cloud and grid computing, as well as for commercial offerings from both hardware and software manufacturers.

i CISSP is a professional computer security certification administered by (ISC)).2. (

