A framework for data privacy and security accountability in data breach communications

被引:6
|
作者
Thomas, Louise [1 ]
Gondal, Iqbal [1 ,2 ]
Oseni, Taiwo [1 ]
Firmin, Selena [1 ]
机构
[1] Federat Univ Australia, Sch Engn IT & Phys Sci, Brisbane, Qld, Australia
[2] RMIT Univ, Melbourne, Vic, Australia
关键词
Data breach; Data breach notification; Cyber security incident; Privacy; Security; Data management; NOTIFICATION; PROTECTION; CRISIS;
D O I
10.1016/j.cose.2022.102657
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Organisations need to take steps to protect the privacy and security of the personal information they hold. However, when data is breached, how do individuals know whether the organisation took reasonable steps to protect their data? When breached organisations notify affected individuals, this communication is likely to be one of the few windows into the incident from the outside and can become an important artefact for research. This desktop study aimed to consider the extent to which publicly available Australian data breach communications reflect data privacy and security best practices. This paper presents a brief review of literature and government guidance on data security and privacy best practices, along with the results of a qualitative content analysis of 33 publicly available Australian data breach communications. This analysis illustrated that there was little reflection of data privacy and security practices. Literature, government guidance and the content analysis were used to inform and develop a new voluntary framework for organisations. This consists of a series of evaluation questions divided into two broad categories: responsible data management and responsible portrayal of the breach. The framework has the potential to help organisations plan the inclusion of data privacy and security management aspects in their data breach communications. This could assist organisations to address their legal and ethical responsibility to account for their actions in managing privacy and security of the personal data they hold.(c) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Data privacy breach prevention framework for the cloud service
    Dhasarathan, Chandramohan
    Thirumal, Vengattaraman
    Ponnurangam, Dhavachelvan
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (06) : 982 - 1005
  • [2] Multidomain Fusion Data Privacy Security Framework
    Yang, Jing
    Qu, Lianwei
    Wang, Yong
    [J]. WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2021, 2021
  • [3] Application of the holistic Data Privacy and Security Framework PaaSword
    Schork, Sebastian Thomas
    Schwichtenberg, Antonia
    Alexakis, Spiros
    Moldovan, George
    [J]. PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2017), 2017,
  • [4] A Novel Framework to Prevent Privacy Breach in Cloud Data Storage Area Service
    Chandramohan, D.
    Vengattaraman, T.
    Rajaguru, D.
    Baskaran, R.
    Dhavachelvan, P.
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON GREEN HIGH PERFORMANCE COMPUTING (ICGHPC), 2013,
  • [5] Privacy and Data Security
    Gaff, Brian M.
    Smedinghoff, Thomas J.
    Sor, Socheth
    [J]. COMPUTER, 2012, 45 (03) : 8 - 10
  • [6] Developments in Data Security Breach Liability
    Black, John
    [J]. BUSINESS LAWYER, 2013, 69 (01): : 199 - 207
  • [7] Developments in Data Security Breach Liability
    Silverman, David L.
    [J]. BUSINESS LAWYER, 2014, 70 (01): : 231 - 245
  • [8] Data protection - Security: Data security - The key to privacy
    Carey, Peter
    Berry, David
    [J]. Computer Law and Security Report, 2002, 18 (02): : 112 - 113
  • [9] PRIVACY MATTERS: DATA BREACH LITIGATION IN JAPAN
    Pardieck, Andrew M.
    [J]. WASHINGTON INTERNATIONAL LAW JOURNAL, 2024, 33 (01):
  • [10] Data-centric security: Integrating data privacy and data security
    Hennessy, Shawn D.
    Lauer, George D.
    Zunic, Nev
    Gerber, Benjamin
    Nelson, Adam C.
    [J]. IBM Journal of Research and Development, 2009, 53 (02):