Chuyển đến nội dung chính

Security, Privacy & Compliance Requirements for BA

Duy Tran12 min
Security, Privacy & Compliance Requirements for BA

Many BAs think security/privacy is the job of the Tech Lead or Security team. Yes, they design and test extensively. But if the original requirement does not clearly state what data is sensitive, who can view it, who can export it, how long it will be saved, and what audits will be performed, then the technical team will easily build a flawed structure.

BAs do not need to know pentesting, but need to know how to ask the right questions and write requirements clearly enough.

1. What do BAs need to pay attention to?

Main requirement groups:

GroupBA needs clarification
AuthenticationHow do users log in? SSO/MFA?
AuthorizationWhich role can do what?
Data classificationWhat data is PII/PHI/payment/confidential?
PrivacyConsent, retention, deletion, masking
AuditLog what action, how long to keep?
ComplianceGDPR, PDPA, HIPAA, PCI-DSS or internal policy
IncidentHow to escalate when there is a leak/wrong permissions?

2. Authentication vs Authorization

Authentication replies: who are you?

Authorization answers: what can you do?

Example requirements:

AUTHN-001:
User nội bộ phải đăng nhập bằng SSO công ty. Nếu user truy cập từ thiết bị mới, hệ thống yêu cầu MFA.

AUTHZ-001:
Chỉ role Finance Manager được approve refund trên 50 triệu VND.

Don't write in general terms:

The system must be decentralized.

Let's write it in RBAC matrix.

3. RBAC matrix sample

RoleView customersEdit customerExport customersDelete customer
Support AgentYes, maskedNoNoNo
Support ManagerYesYesNoNo
Compliance OfficerYesNoYesNo
AdminYesYesYesYes, with approval

Requirement from table:

AUTHZ-004:
Support Agent chỉ được xem email và số điện thoại ở dạng masked, ví dụ du***@mail.com và 090***123.

4. Data classification

BA should classify data right in SRS:

TypeExampleHow to handle
PublicProduct name, FAQCan display wide
InternalOperational reportInternal only
ConfidentialContract price, marginPermission Restriction
PIIEmail, phone number, CCCDMasking, consent, retention
PHIHealth recordsStrict regulations
PaymentCard data, transactionsPCI-DSS, tokenization

Without classification, Dev/QA does not know which data needs to be masked, which logs should not record raw values, and which exports need approval.

5. Privacy requirements BA is forgetful

Consent

PRIV-001:
Trước khi dùng email khách hàng cho marketing, hệ thống phải ghi nhận explicit consent gồm user_id, timestamp, consent_version và channel.

Retention

PRIV-002:
Chat transcript chứa PII chỉ được lưu tối đa 180 ngày, sau đó phải anonymize hoặc xóa theo policy.

Deletion request

PRIV-003:
Khi khách gửi yêu cầu xóa dữ liệu, hệ thống tạo ticket DSAR và hoàn tất trong SLA 30 ngày nếu không có ràng buộc pháp lý giữ lại.

Data minimization

PRIV-004:
Form đặt lịch không được yêu cầu CCCD nếu quy trình chỉ cần tên, số điện thoại và email.

6. Audit log requirements

A good audit log should answer:

  • Who did it?
  • Doing what?
  • When?
  • From where?
  • What is before/after data?
  • What is the reason if the operation is sensitive?

For example:

AUD-001:
Khi user export danh sách khách hàng, hệ thống phải ghi audit log gồm user_id, role, timestamp, IP, filter sử dụng, số dòng export và file_id.

Note: audit log should not record raw passwords, tokens, full card numbers or unnecessary sensitive data.

7. Compliance in requirements

BA is not a lawyer, but BA needs to bring compliance owner in at the right time.

Checklist:

  • Which country/region does the data belong to?
  • Is there child, health, financial, payment data?
  • Does a vendor/third-party process the data?
  • Is there cross-border transfer?
  • Is there a request to delete data?
  • Is there mandatory audit/reporting?
  • Are there any internal policies that need to be followed?

8. Security acceptance criteria

Story example:

As a Support Manager, I want to view customer profile so that I can resolve escalated tickets.

AC should have:

Scenario: Support Manager xem hồ sơ
Given user có role Support Manager
When user mở hồ sơ khách hàng
Then hệ thống hiển thị thông tin đầy đủ theo quyền
And ghi audit log hành động view_profile

Scenario: Support Agent xem hồ sơ
Given user có role Support Agent
When user mở hồ sơ khách hàng
Then email và số điện thoại được masked
And nút Export không hiển thị

Scenario: User không có quyền
Given user không thuộc team Support
When user truy cập URL hồ sơ khách hàng
Then hệ thống trả 403 và ghi security event

9. Common errors

Error 1: Only write "according to authorization"

Decentralization must have a matrix. Otherwise, everyone understands it differently.

Error 2: Forgot to export

Many screensaver systems look great but export CSV too widely.

Error 3: Logging too much sensitive data

Audit is necessary, but logging raw PII/token/password is a big risk.

Error 4: Privacy later

Leaving privacy behind often leads to costly changes to the data model, UI, consent flow and job retention.

Security/privacy example for scheduling

Access matrix:

RoleView calendarCreate calendarChange/cancel scheduleView phone numberExport
CustomersJust my calendarYesJust my calendar according to the cutoff ruleMineNo
ConsultingSchedule assignedNoNoMaskedNo
Customer careCustomer CalendarThere is a change of guestsYes as per SOPFull if there is a reason to supportNo
Sales ManagerTeam dashboardNoNoMaskedYes, need audit
AdminFullYesYesFullYes, approval required

Security acceptance criteria:

Scenario: Customer tries to view another customer's appointment
  Given customer A is logged in
  When customer A opens /appointments/APT-of-customer-B
  Then the system returns 403
  And no appointment details are displayed
  And a security event is logged

Privacy requirements:

IDRequirements
PRIV-001The booking form only collects full name, email, phone number and optional consultation reason.
PRIV-002Reasons why consultants should not request sensitive information if it is not needed for the service.
PRIV-003Appointment data is kept for 7 years according to internal policy, then anonymized if there is no legal obligation.
PRIV-004Email/SMS reminder does not contain sensitive information, only contains time, consultant and calendar management link.
AUD-001Every export of appointment data must record user_id, role, timestamp, filter, line number, reason.

The BA should include this section in the SRS or security requirement section, without leaving the Dev wondering "which role can see what".

Reference source

Conclusion

Security, privacy and compliance are not part of requirements. With digital products, it's part of the quality. Good BAs don't consider themselves security experts, but know how to ask questions early, write clear requirements, and involve the right people in the review before the sprint begins.