CSAA IG 2023 Impact Report 0424 Rev1 - Flipbook - Page 41
Practice
Our Impact
2023
From Our Interim CEO
CSAA is committed to protecting
the privacy and security of the
personal information we maintain. All
employees and contingent workers
are required to comply with our
privacy and security notices, policies,
processes and standards.
To increase employee vigilance and
awareness of our collective and
individual responsibility to safeguard
personal information, we deployed
yearlong phishing campaigns and
information security awareness
training. This training highlights the
importance of cybersecurity and
handling data appropriately, and
all new employees and contingent
workers are required to take the
course. Additionally, to combat the
continued cyber threat posed to the
company, we matured our privacy
incident response plan and trained
dedicated personnel on their role in
privacy and security incident response.
In May 2023, we held our annual
Lighten Up Week. This recordscleanup event lowers volume and
storage costs, reduces privacy risk
and supports regulatory retention
requirements. It also helps lessen
our carbon footprint: Less data in the
cloud means fewer emissions.
During Cybersecurity Awareness
Month in October, we launched a
monthlong Cyber Expo, kicking off
HUMAN FOCUS
People
Practice
Data privacy and security
O U R
BACK TO TOP
Planet
G U I D I N G
with a fireside chat led by the chief
information security officer (CISO)
and chief information officer (CIO),
followed by sessions with practical
tips on cyber safety and artificial
intelligence and a conversation with
the CISO of AAA Inc.
In addition, we continue to implement
privacy and security controls to
reduce the likelihood of loss, misuse
or other inappropriate disclosure
of personal information. Examples
include ongoing testing and courses
on email phishing and security best
practices, and data classification
and handling applications, among
other initiatives.
P R I N C I P L E S
ACCOUNTABILIT Y
F O R
In 2023, we focused heavily on
artificial intelligence (AI) governance,
ensuring we uphold the trust
placed in us by our customers,
employees, agents and other
partners through the responsible
use of AI—including generative AI.
This included generating CSAA’s
Guiding Principles for AI and founding
an AI governance group that meets
biweekly. Our Guiding Principles for
AI now provide the organization with
high-level guidance when considering
opportunities to leverage AI in our
business operations. They also
outline CSAA’s vision for AI at the
company and offer transparency to
customers, agents, media and other
external stakeholders.
A I
TRANSPARENCY