DocumentCode :
541925
Title :
EnCoRe: Towards a holistic approach to privacy
Author :
Papanikolaou, Nick ; Creese, Sadie ; Goldsmith, Michael ; Mont, Marco Casassa ; Pearson, Siani
Author_Institution :
International Digital Laboratory, University of Warwick, U.K.
fYear :
2010
fDate :
26-28 July 2010
Firstpage :
1
Lastpage :
6
Abstract :
We make the case for an integrated approach to privacy management within organisations. Current approaches to privacy management are either too high-level, enforcing privacy of personal data using legal compliance, risk and impact assessments, or too low-level, focusing only on the technical implementation of access controls to personal data held by an enterprise. High-level approaches tend to address privacy as an afterthought in ordinary business practice, and involve ad hoc enforcement practices; low-level approaches often leave out important legal and business considerations. As part of the EnCoRe project we are developing a methodology which tries to bridge the gap between privacy risk and impact assessment with the technical management of privacy policies. We are working to define a conceptual model as a means of expressing policy requirements as well as users´ privacy preferences and as a way to bridge the gap described above. We aim to show the value of this approach in collaborative case studies (including corporate personnel management, biobanks and assisted living) in the context of the EnCoRe project.
Keywords :
Access control; Business; Data privacy; Law; Privacy; Policy hierarchy; Policy refinement; Privacy policies;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Security and Cryptography (SECRYPT), Proceedings of the 2010 International Conference on
Conference_Location :
Athens
Type :
conf
Filename :
5741646
Link To Document :
بازگشت