科技报告详细信息
EnCoRe: Towards a holistic approach to privacy
Papanikolaou, Nick ; Creese, Sadie ; Goldsmith, Michael ; Casassa Mont, Marco ; Pearson, Siani
HP Development Company
关键词: privacy policies;    policy hierarchy;    policy refinement;   
RP-ID  :  HPL-2010-83
学科分类:计算机科学(综合)
美国|英语
来源: HP Labs
PDF
【 摘 要 】
Privacy requirements for IT systems and solutions arise from a variety of sources, including legislation, sector-specific regulation, organisational guidelines, social and user expectations. In this paper we present and discuss a holistic approach to the management of privacy - explored in the context of the EnCoRe project - which takes into account the need to deal with these different types of policies, at different levels of abstraction as well as risk assessment methods to assess them based on specific threats, needs and constraints. We discuss examples of privacy requirements and related policies coming from different sources. We then present how a 'privacy- aware risk assessment' approach (which leverages and extends traditional security-driven risk assessment approaches) can be used to analyse these policies, assess their compliance to requirements, identify gaps and mandate the adoption of specific controls. We explain its relevance and implications in an employee data case study, involving the management of privacy consent and revocation. This is work in progress, carried out in the context of the EnCoRe collaborative project [1].
【 预 览 】
附件列表
Files Size Format View
RO201804100002749LZ 102KB PDF download
  文献评价指标  
  下载次数:6次 浏览次数:27次