【24h】

Privacy Enforcement for IT Governance in Enterprises: Doing it for Real

机译:企业IT治理的隐私实施:真正做到这一点

获取原文
获取原文并翻译 | 示例

摘要

This paper describes issues and requirements related to privacy management as an aspect of improved governance in enterprises. Most of the existing related technical work is based on auditing and reporting mechanisms. The focus of this paper is on privacy enforcement for personal data: this is still a green field. To enforce the execution of privacy policies, requests to access personal data need to be checked against data requestors' rights and intents, data subjects' consent and the stated data purposes. Being able to automate and simplify the enforcement of privacy and reduce the involved costs is important for enterprises. We describe our approach and compare it against related work. In particular, we discuss our work done to add privacy-aware access control capabilities to HP Select Access - a leading-edge access control solution. A prototype has been implemented as a proof of concept. Current results, open issues and next steps are discussed.
机译:本文介绍了与隐私管理相关的问题和要求,这些问题和要求是企业改进治理的一个方面。现有的大多数相关技术工作都是基于审计和报告机制的。本文的重点是针对个人数据的隐私保护:这仍然是一个绿色领域。为了强制执行隐私策略,需要对照数据请求者的权利和意图,数据主体的同意以及陈述的数据目的来检查访问个人数据的请求。能够自动化和简化隐私的执行并减少所涉及的成本对企业很重要。我们描述了我们的方法,并将其与相关工作进行了比较。特别是,我们将讨论为将领先的访问控制解决方案HP Select Access添加具有隐私意识的访问控制功能而进行的工作。已实现了原型作为概念证明。讨论了当前结果,未解决的问题和下一步。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号