首页> 外文会议>Annual Privacy Forum >Conceptual Framework and Architecture for Privacy Audit
【24h】

Conceptual Framework and Architecture for Privacy Audit

机译:隐私审核的概念框架和架构

获取原文

摘要

Many ICT applications involve the collection of personal information or information on the behaviour of customers, users, employees, citizens, or patients. The organisations that collect this data need to manage the privacy of these individuals. In many organisations there are insufficient data protection measures and a low level of trust among those whose data are concerned. It is often difficult and burdensome for organisations to prove privacy compliance and accountability especially in situations that cross national boundaries and involve a number of different legal systems governing privacy. In response to these obstacles, we describe instruments facilitating accountability, audit, and meaningful certification. These instruments are based on a set of fundamental data protection goals (DPG): availability, integrity, confidentiality, transparency, intervenability, and unlinkability. By using the data protection goals instead of focusing on fragmented national privacy regulations, a well defined set of privacy metrics can be identified recognising privacy by design requirements and widely accepted certification criteria. We also describe a novel conceptual framework and architecture for defining comprehensive privacy compliance metrics and providing assessment tools for ICT applications and services using as much automation as possible. The proposed metrics and tools will identify gaps, provide clear suggestions and will assist audit and certification to support informed decisions on the trustworthiness of ICT for citizens and businesses.
机译:许多ICT应用程序涉及收集客户,用户,员工,公民或患者的行为的个人信息或信息。收集此数据的组织需要管理这些人的隐私。在许多组织中,数据保护措施不足以及数据所关注的人之间的信任程度不足。对于组织通常难以和繁重,以证明隐私合规性和责任,特别是在跨国界限的情况下,涉及许多有许多有关隐私的不同法律制度。为了应对这些障碍,我们描述了促进问责制,审计和有意义认证的文书。这些仪器基于一组基本数据保护目标(DPG):可用性,完整性,机密性,透明度,介入性和可解释性。通过使用数据保护目标,而不是专注于分散的国家隐私法规,可以通过设计要求和广泛接受的认证标准来确定一系列明确的隐私度量标准。我们还描述了一种新颖的概念框架和架构,用于定义全面的隐私合规度量,并为ICT应用程序和服务提供评估工具,使用尽可能多的自动化。拟议的指标和工具将识别差距,提供明确的建议,并协助审计和认证,以支持有关ICT的可信度为公民和企业的可信度决定。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号