On Parametric Obligation Policies: Enabling Privacy-Aware Information Lifecycle Management in Enterprises

  • Authors:
  • Marco Casassa Mont;Filipe Beato

  • Affiliations:
  • Hewlett-Packard Laboratories, UK;Hewlett-Packard Laboratories, UK

  • Venue:
  • POLICY '07 Proceedings of the Eighth IEEE International Workshop on Policies for Distributed Systems and Networks
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

Enterprises that collect and process personal data must deal with related privacy management issues. It is not just a matter of privacy-aware access control: privacy obligation policies, dictating duties and expectations on how personal data has to be handled, must be considered too. The management of obligation policies is a promising area but it is still underestimated. Enterprises require solutions that enable automation and can leverage their current identity management solutions. HP Labs have been working on this topic in the last few years, also in the context of the EU PRIME project. In this paper we present our recent work on parametric obligation policies and a related obligation management framework to deal with a scalable management of these policies on large amounts of data, stored in distributed data repositories.