首页> 外文会议>Research and practical issues of enterprise information systems >Business Process-Based Legitimacy of Data Access Framework for Enterprise Information Systems Protection
【24h】

Business Process-Based Legitimacy of Data Access Framework for Enterprise Information Systems Protection

机译:基于业务流程的企业信息系统保护数据访问框架的合法性

获取原文
获取原文并翻译 | 示例

摘要

Nowadays European context is introducing a new directive for data protection, which imposes new constraints to business owners which manipulate personal data. Among imposed constraints, we find that while a disclosure occurs on user's personal data, the burden of proof is now in the charge of business owners. In this context, data access has to be managed according to what is mentioned in Terms of Service and logged in a way to prove the occurrence of a disclosure or not. This work, part of Personal Information Controller Service project proposes a data-driven privacy control system, based on Collaborative Usage Control (CUCON), allows organizations to manage the access authorizations they provide to stakeholders. The proposed system intervenes in two contexts, which are ad-hoc business processes and while using big data techniques. In fact, new data usage introduces changes in usage-based models since used systems are usually distributed and involving several organizations which can have different definitions for a given role. This framework manages the consistency between already allowed data access rights and potential given rights to a given business stakeholder according to business process's activity affected to him/her. It also warns when a conflict occurs and when the aggregation of the rights granted to a given stakeholder lead to having rights to a sensitive data.
机译:如今,欧洲环境正在引入一个新的数据保护指令,该指令对操纵个人数据的企业所有者施加了新的约束。在施加的限制中,我们发现,尽管在用户的个人数据上发生了披露,但举证责任现在由企业所有者负责。在这种情况下,必须根据服务条款中提到的内容来管理数据访问,并以证明是否存在披露的方式进行记录。这项工作是“个人信息控制器服务”项目的一部分,提出了一个基于协作使用控制(CUCON)的数据驱动的隐私控制系统,该系统使组织可以管理向利益相关者提供的访问授权。拟议的系统在两个环境中进行干预,这两个环境是临时业务流程,同时使用大数据技术。实际上,新数据使用情况会导致基于使用情况的模型发生变化,因为使用过的系统通常是分布式的,并且涉及多个组织,这些组织对于给定角色可能具有不同的定义。该框架根据影响到他/她的业务流程的活动来管理已允许的数据访问权与给定业务利益相关者的潜在给定权利之间的一致性。它还会在发生冲突时以及授予给特定利益相关者的权限汇总导致对敏感数据拥有权限时发出警告。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号