首页 | 本学科首页   官方微博 | 高级检索  
     


The principle of security safeguards: Unauthorized activities
Authors:Rasika DayarathnaAuthor Vitae
Affiliation:Department of Computer and Systems Sciences, Stockholm University and the Royal Institute of Technology (KTH), Sweden
Abstract:The principle of information security safeguards is a key information privacy principle contained in every privacy legislation measure, framework, and guideline. This principle requires data controllers to use an adequate level of safeguards before processing personal information. However, privacy literature neither explains what this adequate level is nor how to achieve it. Hence, a knowledge gap has been created between privacy advocates and data controllers who are responsible for providing adequate protection. This paper takes a step toward bridging this knowledge gap by presenting an analysis of how Data Protection and Privacy Commissioners have evaluated the adequacy level of security protection measures given to personal information in selected privacy invasive cases. This study addresses both security measures used to protect personal information against unauthorized activities and the use of personal information in authentication mechanisms. This analysis also lays a foundation for building a set of guidelines that can be used by data controllers for designing, implementing, and operating both technological and organizational measures used to protect personal information.
Keywords:Information privacy   Information security   Data control   Privacy guidelines   Unauthorized data usage   Information systems design   Password/passphrase
本文献已被 ScienceDirect 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号