You are the PM for privacy and security at Facebook. What goal would you set and how would you measure success?
You'll get access to over 3,000 product manager interview questions and answers
Recommended by over 100k members
Step 1 - Understand the privacy and Security Product
Set of features which prevent oversharing of personal information of user
Sharing when user does not want it to be shared
Sharing when the cost of information share is less than the business benefit it entails
Partner with the user to keep them abreast of when and where the data is being shared
Do we have a list of features included? If not, I would presume it would include
Disclaimer / notices
User preferences
Communication outside the platform
Step 2- How does it fit into the facebook mission ?
Facebook’s mission is to connect people, enable them to create communities and express themselves.
How Privacy and security helps
Increasing user trust and confidence that the information is secured and under the control of the user themselves.
Indirect impact on users' motivation and openness to participate in making new connections and sharing information.
Vision for the product and focus area
Vision: Improve user trust and confidence in the platform so that they can participate in making of new connections and share information
Focus Area - Three potential areas of focus
Acquisition & Activations | Engagement & Retention | Monetization | |
Privacy and security | Good to have | In Focus | N/A |
Facebook platform | Good to have | In Focus | Good to have |
Metrics to measure the impact in focus area
How would people interact / Use the privacy & security feature
User Journey
Discovery
Initiation
Update themselves with controls and checks which Facebook has implemented
Interact and provide proactive inputs where possible (say setting up the preferences)
Completion
Are aware of all the latest initiatives / policies
Save / complete the proactive inputs
Feedback
Feel one way or the other about the controls provided and convey the same
Metrics
Discovery | # of people who are aware of the privacy and security controls | |
# of users who have a privacy or security related query | ||
Initiation & completion | # of visits to the privacy and security resources | |
# of users who are confidently aware of last set of changes made by facebook | ||
# of users who have visited and setup/edited privacy and security preferences | ||
Feedback | CSAT , NPS score | |
# of users who have expressed negative opinion about the security and privacy |
Let us think about the impact it will have on the usage of facebook and its product. Ideally, a robust privacy and security solution will increase user trust and increase engagement with the product
Breadth | DAU, MAU |
New sign ups | |
Depth | Average/ weighted engagement with facebook product per user per day |
Frequency | Time between two logins |
Value | CSAT score , feedback |
- Too much focus may not be the best thing
- Think of it as insurance, you got it but wish you will never use it
Hence the feedback metrics may be good one to focus on
North star metric
Given the nature of product, I would like to focus on the following metrics
Product Level | # of users who have expressed negative opinion about the security and privacy |
Platform level | Average/ weighted engagement with facebook product per user per day + DAU |
Risks and contra metrics
Platform engagement could be impacted by multitude of factors other than privacy
Contra metric
Benchmark against the competition - # of complaints received by facebook vs # of complaints received by a competition (Google) on public forums
That's an interesting question because most people don't know that there is a product around privacy and safety. I also think that this product is encompasing FB wholistically across mutiple of externally facing FB products. Is my assumption correct here? (yes). Ok, let me ask if this comes into play for cosnumers and businesses since FB is a 2 sided market place. (correct). And also, this comes into play right from signing up to be a member of FB to buying EVent or an item being sold, etc. (correct). And I also assume that privacy and security /safety isn't just one big gaint product? (you can assume so but for the intention of this case you may consider it to be 1 product). Yes, I was about to ask that so thank you.
Ok, so isnce I understnad the consumer side more becuase I have experienced the consumer side of user journey, can we take that route as I think about this? (sure). Shall I also assume that our goal is to increase safety / security / privacy of users? (yes that's fair).
Alright, so I think what I will do is first think of areas where safety / security come into play because that may help me. I am not sure yet but if you are ok can I do that? (sure).
1) Registration
2) Making payments (for an event, buying something from Marketplace or maybe even Games, etc.)
3) Identity theft
These are the only areas I am able to think off hand. Are there any others you may want me to consider? (no for now 3 is fine).
Ok, so I am thinking measuring this and seeing if it meets our threshold is important for user experience and if we provide a bad user experience or get bad press due to failures in this area, that could literally lead to loss of market value and worse case huge litigations and even dilution of FB. (correct). Understnading the importance of this, let me see what we may want to evalute.
1) % of users reporting privacy / security concerns per day (such as didn't receive products paid for, charged double the amount, etc.)
2) # of privacy breaches reported / day
3) # of non-human created accounts (registrations) / day
4) # of transactions from a non-human account / day
5) # of melicious / fradualant activities stopped / day
I am measuring these over a period of a day since while FB is quite advanced in it's cyber security practices it's also one of the most widely used site and the most active social media and hence prob is the most vulenerable. Also, mesuring frequently is important since even a day of security breach could result in huge detrimental impact to our trusting customers. While all the above measures are critical I believe #3 is the primary one we should really keep an eye on. #3 is the core resultant of the rest (transactions, safety impacts to users and hence # of reported concerns, etc.). In terms of goal, ideal would be 0 but that's too unrealistic, I pressume, so I wuol work with Data Scientist to see what the norm is and look at what's the lowest we have obtained in a year maybe or some other time period that makes sense based on data. I would keep that number to be my min goal or maybe stretch that goal by 5% (again that specific % is soemthing that may require some thinkinng).
Overall, we wanted to measure success and set a goal for
privacy and security at Facebook. My approach was to think of what areas this product applies and hence what are those things we should measure.Product:
This product helps the user from protectig his account from being public for everyone and on the other side of the coin it helps the user to understand the new security changes and make changes to the account as per need
Users: Facebook User (Creator, consumer)
Value Proposition:
Privacy: This feature allows for the content creators to decide on who should watch their content and for the normal user they can control on who can view the profile and access the features like viewing image, sending friend request and that
Security: This feature allows for the users to prevent their account from being hacked or accessed by other by enabling the two factor autherntication or changing passwords
Metrics to be monitored
Compared to the other products security and privacy is totall different which needs users to go through the awreness, adoption and rentension phase and does not have much to do with the engagement
Northstar Metric:
1. Total number of users who made applied privacy/security changes (This adoption metric is considered as NSM because applying privacy and secority setting might removes the reluctance from posing content to the community and provides confidence in using facebook)
Supporting Metric
1. Total number of users who applied these settings (Demographics wise)
2. Increase in the number of users who started contributing to content after applying the privacy changes
3. Time spent in facebook after making the security changes
4. Number of account that drop in the intermidently while making changes - Helps understans the UX or technical difficulties
Tradeoff
1. Drop in account usage to the security constraints
2. Limited content available for the comminuty dues to lot of privacy settings from users
Counter Metric:
1. Number of reports on account hacked after applying the changes
Top Meta (Facebook) interview questions
- What is your favorite product? Why?89 answers | 263k views
- How would you design a bicycle renting app for tourists?62 answers | 82.5k views
- Build a product to buy and sell antiques.54 answers | 66.8k views
- See Meta (Facebook) PM Interview Questions
Top Execution interview questions
- Imagine you were in charge of Facebook Watch. What metric would you want to measure?13 answers | 9.1k views
- Weekly active users (WAU) for iPhone app dropped. What happened?10 answers | 6.3k views
- You are the PM of Instagram stories. What goal would you set and how would you measure success?10 answers | 14k views
- See Execution PM Interview Questions
Top Execution interview questions
- How would you decide between showing more ads on the Facebook Newsfeed vs showing a "People you may know" recommendation widget?9 answers | 8.9k views
- You are the PM of Facebook Lite. What goals would you set?7 answers | 8.2k views
- Define the metrics for YouTube search.6 answers | 4k views
- See Execution PM Interview Questions