PRIAM: A Privacy Risk Analysis Methodology

被引:29
|
作者
De, Sourya Joyee [1 ]
Le Metayer, Daniel [1 ]
机构
[1] Univ Lyon, INRIA, Lyon, France
关键词
Privacy; Personal data; Privacy Impact Assessment; PIA; Privacy Risk Analysis; PRA; Risk; Harm; IMPACT ASSESSMENT;
D O I
10.1007/978-3-319-47072-6_15
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Privacy Impact Assessments (PIA) are recognized as a key step to enhance privacy protection in new information systems and services. They will be required in Europe when the new General Data Protection Regulation becomes effective. From a technical perspective, the core of a PIA is a Privacy Risk Analysis (PRA), which has received relatively less attention than organizational and legal aspects of PIAs. In this work, we propose a rigorous and systematic PRA methodology. We illustrate it with a quantified self use-case in the extended paper [9].
引用
收藏
页码:221 / 229
页数:9
相关论文
共 50 条
  • [1] Towards an Effective Privacy Impact and Risk Assessment Methodology: Risk Analysis
    Alshammari, Majed
    Simpson, Andrew
    DATA PRIVACY MANAGEMENT, CRYPTOCURRENCIES AND BLOCKCHAIN TECHNOLOGY, 2018, 11025 : 209 - 224
  • [2] PRIAM: Privacy Preserving Identity and Access Management Scheme in Cloud
    Xiong, Jinbo
    Yao, Zhiqiang
    Ma, Jianfeng
    Liu, Ximeng
    Li, Qi
    Ma, Jun
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2014, 8 (01): : 282 - 304
  • [3] Privacy Risk Analysis
    1600, Morgan and Claypool Publishers (08):
  • [4] Towards an Effective Privacy Impact and Risk Assessment Methodology: Risk Assessment
    Alshammari, Majed
    Simpson, Andrew
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, 2018, 11033 : 85 - 99
  • [5] Quantitative Privacy Risk Analysis
    Cronk, R. Jason
    Shapiro, Stuart S.
    2021 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2021), 2021, : 340 - 350
  • [6] EPIC: a Methodology for Evaluating Privacy Violation Risk in Cybersecurity Systems
    Mascetti, Sergio
    Metoui, Nadia
    Lanzi, Andrea
    Bettini, Claudio
    TRANSACTIONS ON DATA PRIVACY, 2018, 11 (03) : 239 - 277
  • [7] Privacy Risk Analysis to Enable Informed Privacy Settings
    De, Sourya Joyee
    Le Metayer, Daniel
    2018 3RD IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2018), 2018, : 95 - 102
  • [8] A risk-based methodology for privacy requirements elicitation and control selection
    Manna, Asmita
    Sengupta, Anirban
    Mazumdar, Chandan
    SECURITY AND PRIVACY, 2022, 5 (01)
  • [9] Towards a Privacy Risk Assessment Methodology for Location-Based Systems
    Friginal, Jesus
    Guiochet, Jeremie
    Killijian, Marc-Olivier
    MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING, AND SERVICES, 2014, 131 : 748 - 753
  • [10] Privacy risk analysis in the IoT domain
    Hernandez-Serrano, Juan
    Munoz, Jose L.
    Leon, Olga
    Mikkelsen, Lars
    Schwefel, Hans-Peter
    Broering, Arne
    2018 GLOBAL INTERNET OF THINGS SUMMIT (GIOTS), 2018, : 289 - 294