Privacy enforcement for IT governance in enterprises: doing it for real

  • Authors:
  • Marco Casassa Mont;Robert Thyne;Pete Bramhall

  • Affiliations:
  • Trusted Systems Lab, Hewlett-Packard Labs, Bristol, United Kingdom;Trusted Systems Lab, Hewlett-Packard Labs, Bristol, United Kingdom;Trusted Systems Lab, Hewlett-Packard Labs, Bristol, United Kingdom

  • Venue:
  • TrustBus'05 Proceedings of the Second international conference on Trust, Privacy, and Security in Digital Business
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper describes issues and requirements related to privacy management as an aspect of improved governance in enterprises. Most of the existing related technical work is based on auditing and reporting mechanisms. The focus of this paper is on privacy enforcement for personal data: this is still a green field. To enforce the execution of privacy policies, requests to access personal data need to be checked against data requestors' rights and intents, data subjects' consent and the stated data purposes. Being able to automate and simplify the enforcement of privacy and reduce the involved costs is important for enterprises. We describe our approach and compare it against related work. In particular, we discuss our work done to add privacy-aware access control capabilities to HP Select Access – a leading-edge access control solution. A prototype has been implemented as a proof of concept. Current results, open issues and next steps are discussed.