Title
Privacy enforcement for IT governance in enterprises: doing it for real
Abstract
This paper describes issues and requirements related to privacy management as an aspect of improved governance in enterprises. Most of the existing related technical work is based on auditing and reporting mechanisms. The focus of this paper is on privacy enforcement for personal data: this is still a green field. To enforce the execution of privacy policies, requests to access personal data need to be checked against data requestors' rights and intents, data subjects' consent and the stated data purposes. Being able to automate and simplify the enforcement of privacy and reduce the involved costs is important for enterprises. We describe our approach and compare it against related work. In particular, we discuss our work done to add privacy-aware access control capabilities to HP Select Access – a leading-edge access control solution. A prototype has been implemented as a proof of concept. Current results, open issues and next steps are discussed.
Year
DOI
Venue
2005
10.1007/11537878_23
TrustBus
Keywords
Field
DocType
privacy enforcement,personal data,privacy policy,data subject,related work,privacy-aware access control capability,leading-edge access control solution,data requestors,it governance,privacy management,stated data purpose,proof of concept,access control
Internet privacy,Corporate governance,Privacy by Design,Computer security,Computer science,Privacy policy,Proof of concept,Information repository,Access control,Enforcement,Information privacy
Conference
Volume
ISSN
ISBN
3592
0302-9743
3-540-28224-6
Citations 
PageRank 
References 
2
0.52
4
Authors
3
Name
Order
Citations
PageRank
Marco Casassa Mont128933.03
Robert Thyne2222.78
Pete Bramhall314911.42