The Experts below are selected from a list of 7032 Experts worldwide ranked by ideXlab platform

Larry Korba - One of the best experts on this subject based on the ideXlab platform.

  • Chapter e54 – Personal Privacy Policies1
    Computer and Information Security Handbook, 2020
    Co-Authors: Larry Korba
    Abstract:

    The rapid growth of the Internet has been accompanied by similar growth in the availability of Internet electronic services (e-services) such as online booksellers and stockbrokers. This proliferation of e-services has in turn fueled the need to protect the Personal Privacy of e-service users or consumers. This chapter proposes the use of Personal Privacy policies to protect Privacy. It is evident that the content must match the user's Privacy preferences as well as Privacy legislation. It is also evident that the construction of a Personal Privacy policy must be as easy as possible for the consumer. Furthermore, the content and construction must not result in negative unexpected outcomes (an unexpected outcome that harms the user in some manner). The chapter begins with the derivation of policy content based on Privacy legislation, followed by a description of how a Personal Privacy policy may be constructed semiautomatically. It then shows how to specify policies so that negative unexpected outcomes can be avoided. Finally, it describes our Privacy Management Model, which explains how to use Personal Privacy policies to protect Privacy, including what is meant by a “match” of consumer and service provider policies and how nonmatches can be resolved through negotiation. Hence, it has become hard for individuals to manage and control their Personal spheres. Both legal and technical means are needed to protect Privacy and to (re)establish individuals' control. This chapter provides an overview of the area of Privacy-enhancing technologies (PETs), which protect Privacy by technically enforcing legal Privacy principles. It starts by defining the legal foundations of PETs, and presents a classification of PETs as well as a definition of traditional Privacy properties that PETs address and metrics for measuring the level of Privacy that PETs provide. Then, a selection of the most relevant PETs is presented.

  • Personal Privacy Policies
    Computer and Information Security Handbook, 2020
    Co-Authors: Larry Korba
    Abstract:

    The rapid growth of the Internet has been accompanied by a similar growth in the availability of Internet e-services (such as online booksellers and stockbrokers). This proliferation of e-services has in turn fueled the need to protect the Personal Privacy of e-service users or consumers. This chapter proposes the use of Personal Privacy policies to protect Privacy. It is evident that the content must match the user’s Privacy preferences as well as Privacy legislation. It is also evident that the construction of a Personal Privacy policy must be as easy as possible for the consumer. Further, the content and construction must not result in negative unexpected outcomes (an unexpected outcome that harms the user in some manner). The chapter begins with the derivation of policy content based on Privacy legislation, followed by a description of how a Personal Privacy policy may be constructed semiautomatically. It then shows how to additionally specify policies so that negative unexpected outcomes can be avoided. Finally, it describes our Privacy Management Model that explains how to use Personal Privacy policies to protect Privacy, including what is meant by a “match” of consumer and service provider policies and how nonmatches can be resolved through negotiation. difficulty. Hence, it has become hard for individuals to manage and control their Personal spheres. Both legal and technical means are needed to protect Privacy and to (re-)establish the individuals’ control. This chapter provides an overview to the area of Privacy-enhancing Technologies (PETs), which help to protect Privacy by technically enforcing legal Privacy principles. It will start with defining the legal foundations of PETs, and will present a classification of PETs as well as a definition of traditional Privacy properties that PETs are addressing and metrics for measuring the level of Privacy that PETs are providing. Then, a selection of the most relevant PETs is presented.

  • Semiautomatic Derivation and Use of Personal Privacy Policies in E-Business
    International Journal of E-business Research, 2020
    Co-Authors: Larry Korba
    Abstract:

    The growth of the Internet has been accompanied by the growth of Internet e-business services (e.g., electronic bookseller services, electronic stock-transaction services). This proliferation of e-business services has in turn fueled the need to protect the Personal Privacy of e-business users or consumers. We advocate a Privacy policy approach to protecting Personal Privacy. However, it is evident that the specification of a Personal Privacy policy must be as easy as possible for the consumer. In this paper, we define the content of Personal Privacy policies using Privacy principles that have been enacted into legislation. We then present two semiautomated approaches for the derivation of Personal Privacy policies. The first approach makes use of common Privacy rules obtained through community consensus. This consensus can be obtained from research and/or surveys. The second approach makes use of existing Privacy policies in a peer-to-peer community. We conclude the paper by explaining how Personal Privacy policies can be applied in e-business to protect consumer Privacy.

  • Semi-Automated Seeding of Personal Privacy Policies in E-Services
    Encyclopedia of E-Commerce E-Government and Mobile Commerce, 2020
    Co-Authors: Larry Korba
    Abstract:

    The rapid growth of the Internet has been accompanied by a proliferation of e-services targeting consumers. E-services are available for banking, shopping, learning, government online, and healthcare. However, each of these services requires a consumer’s Personally identifiable information (PII) in one form or another. This leads to concerns over Privacy. In order for e-services to be successful, Privacy must be protected (Ackerman, Cranor, & Reagle, 1999). An effective and flexible way of handling Privacy is management via Privacy policies. In this approach, a consumer of an e-service has a Personal Privacy policy that describes what private information the consumer is willing to give up to the e-service, with which parties the provider of the e-service may share the private information, and how long the private information may be kept by the provider. The provider likewise has a provider Privacy policy describing similar Privacy constraints as in the consumer’s policy, but from the viewpoint of the provider, (i.e., the nature of the private information and the disclosure/retention requirements that are needed by the e-service). Before the consumer engages the e-service, the provider’s Privacy policy must match with the consumer’s Privacy policy. In this way, the consumer’s Privacy is protected, assuming that the provider complies with the consumer’s Privacy policy. Note that policy compliance is outside the scope of this work but see Yee and Korba (July, 2004). Initial attempts at conserving consumer Privacy for e-services over the last few years have focused on the use of Web site Privacy policies that state the Privacy rules or preferences of the Web site or service provider. Some of these policies are merely statements in plain English and it is up to the consumer to read it. This has the drawback that very few consumers take the trouble to read it. Even when they do take the time to look at it, online Privacy policies have been far too complicated for consumers to understand and suffer from other deficiencies (Lichtenstein, Swatman, & Babu, 2003; Jensen & Potts, 2004). Still other Privacy policies are specified using P3P (W3C) that allows a consumer’s browser to automatically check the Privacy policy via a browser plug-in. This, of course, is better than plain English policies but a major drawback is that it is a “take-it-or-leave-it” approach. There is no recourse for the consumer who has a conflict with the Web site’s P3P policy, except to try another Web site. In this case, we have advocated a negotiations approach to resolve the conflict (Yee & Korba, Jan., May, 2003). However, this requires a machine-processable Personal Privacy policy for the consumer. We assume that providers in general have sufficient resources to generate their Privacy policies. Certainly, the literature is full of works relating to enterprise Privacy policies and models (e.g., Barth & Mitchell, 2005; Karjoth & Schunter 2002). Consumers, on the other hand, need help in formulating machine-processable Privacy policies. In addition, the creation of such policies needs to be as easy as possible or consumers would simply avoid using them. Existing Privacy specification languages such as P3P, APPEL (W3C; W3C, 2002), and EPAL (IBM) are far too complicated for the average internet user to understand. Understanding or changing a Privacy policy expressed in these languages effectively requires knowing how to program. Moreover, most of these languages suffer from inadequate expressiveness (Stufflebeam, Anton, He, & Jain, 2004). What is needed is an easy, semi-automated way of seeding a Personal Privacy policy with a consumer’s Privacy preferences. In this work, we present two semi-automated approaches for obtaining consumer Personal Privacy policies for e-services through seeding. This article is based on our work in Yee and Korba (2004). The section “Background” examines related work and the content of Personal Privacy policies. The section “Semi-Automated Seeding of Personal Privacy Policies” shows how Personal Privacy policies can be semi-automatically seeded or generated. The section “Future Trends” identifies some of the developments we see in this area over the next few years. We end with ”Conclusion”.

  • Legislative Based for Personal Privacy Policy Specification
    Privacy Protection for E-Services, 2020
    Co-Authors: Larry Korba, Ronggong Song
    Abstract:

    The growth of the Internet has been accompanied by a proliferation of e-services, especially in the area of e-commerce (e.g., Amazon.com, eBay.com). However, consumers of these e-services are becoming more and more sensitive to the fact that they are giving up private information every time they use them. At the same time, legislative bodies in many jurisdictions have enacted legislation to protect the Privacy of individuals when they need to interact with organizations. As a result, e-services can only be successful if there is adequate protection for user Privacy. The use of Personal Privacy policies to express an individual’s Privacy preferences appears best-suited to manage Privacy for e-commerce. We first motivate the reader with our e-service Privacy policy model that explains how Personal Privacy policies can be used for e-services. We then derive the minimum content of a Personal Privacy policy by examining some key Privacy legislation selected from Canada, the European Union, and the United States.

Dixie B. Baker - One of the best experts on this subject based on the ideXlab platform.

Carl Chang - One of the best experts on this subject based on the ideXlab platform.

  • Towards the Modeling of Personal Privacy in Ubiquitous Computing Environments
    31st Annual International Computer Software and Applications Conference (COMPSAC 2007), 2007
    Co-Authors: Ryan Babbitt, Johnny Wong, Carl Chang
    Abstract:

    Privacy is a known barrier to the acceptance of ubiquitous computing technologies because they require individuals to trade control of their Personal information and Personal spaces for improved quality of life and assistance with daily activities. Previous work has been done to analyze and protect Privacy in ubiquitous computing environments, but such efforts do not include a formal underlying model. We seek to approach the Privacy problem from a different perspective. Namely, we seek to propose, verify, and analyze a formal model of Privacy for these environments. In this paper, we discuss the beginning stages of our model, namely the resources that need to be protected, the guidelines for constructing the model, and the high-level components of our Personal Privacy model.

  • COMPSAC (2) - Towards the Modeling of Personal Privacy in Ubiquitous Computing Environments
    31st Annual International Computer Software and Applications Conference - Vol. 2 - (COMPSAC 2007), 2007
    Co-Authors: Ryan Babbitt, Johnny Wong, Carl Chang
    Abstract:

    Privacy is a known barrier to the acceptance of ubiquitous computing technologies because they require individuals to trade control of their Personal information and Personal spaces for improved quality of life and assistance with daily activities. Previous work has been done to analyze and protect Privacy in ubiquitous computing environments, but such efforts do not include a formal underlying model. We seek to approach the Privacy problem from a different perspective. Namely, we seek to propose, verify, and analyze a formal model of Privacy for these environments. In this paper, we discuss the beginning stages of our model, namely the resources that need to be protected, the guidelines for constructing the model, and the high-level components of our Personal Privacy model.

Ryan Babbitt - One of the best experts on this subject based on the ideXlab platform.

  • Towards the Modeling of Personal Privacy in Ubiquitous Computing Environments
    31st Annual International Computer Software and Applications Conference (COMPSAC 2007), 2007
    Co-Authors: Ryan Babbitt, Johnny Wong, Carl Chang
    Abstract:

    Privacy is a known barrier to the acceptance of ubiquitous computing technologies because they require individuals to trade control of their Personal information and Personal spaces for improved quality of life and assistance with daily activities. Previous work has been done to analyze and protect Privacy in ubiquitous computing environments, but such efforts do not include a formal underlying model. We seek to approach the Privacy problem from a different perspective. Namely, we seek to propose, verify, and analyze a formal model of Privacy for these environments. In this paper, we discuss the beginning stages of our model, namely the resources that need to be protected, the guidelines for constructing the model, and the high-level components of our Personal Privacy model.

  • COMPSAC (2) - Towards the Modeling of Personal Privacy in Ubiquitous Computing Environments
    31st Annual International Computer Software and Applications Conference - Vol. 2 - (COMPSAC 2007), 2007
    Co-Authors: Ryan Babbitt, Johnny Wong, Carl Chang
    Abstract:

    Privacy is a known barrier to the acceptance of ubiquitous computing technologies because they require individuals to trade control of their Personal information and Personal spaces for improved quality of life and assistance with daily activities. Previous work has been done to analyze and protect Privacy in ubiquitous computing environments, but such efforts do not include a formal underlying model. We seek to approach the Privacy problem from a different perspective. Namely, we seek to propose, verify, and analyze a formal model of Privacy for these environments. In this paper, we discuss the beginning stages of our model, namely the resources that need to be protected, the guidelines for constructing the model, and the high-level components of our Personal Privacy model.

Yekta Ülgen - One of the best experts on this subject based on the ideXlab platform.

  • ICIMTH - Network security vulnerabilities and Personal Privacy issues in Healthcare Information Systems: a case study in a private hospital in Turkey.
    Studies in health technology and informatics, 2020
    Co-Authors: Nihan Namoglu, Yekta Ülgen
    Abstract:

    : Healthcare industry has become widely dependent on information technology and internet as it moves from paper to electronic records. Healthcare Information System has to provide a high quality service to patients and a productive knowledge share between healthcare staff by means of patient data. With the internet being commonly used across hospitals, healthcare industry got its own share from cyber threats like other industries in the world. The challenge is allowing knowledge transfer to hospital staff while still ensuring compliance with security mandates. Working in collaboration with a private hospital in Turkey; this study aims to reveal the essential elements of a 21st century business continuity plan for hospitals while presenting the security vulnerabilities in the current hospital information systems and Personal Privacy auditing standards proposed by regulations and laws. We will survey the accreditation criteria in Turkey and counterparts in US and EU. We will also interview with medical staff in the hospital to understand the needs for Personal Privacy and the technical staff to perceive the technical requirements in terms of network security configuration and deployment. As hospitals are adopting electronic transactions, it should be considered a must to protect these electronic health records in terms of Personal Privacy aspects.

  • Network security vulnerabilities and Personal Privacy issues in healthcare information systems: A case study in a private hospital
    2014 18th National Biomedical Engineering Meeting, 2014
    Co-Authors: Nihan Namoglu, Yekta Ülgen
    Abstract:

    Healthcare industry has become widely dependent on information technology and internet; as it moves from paper to electronic records. Despite the benefits of electronic system, good quality may not be totally achieved unless its risks to security are mitigated. Working in collaboration with a 150 bed private hospital in Turkey; this study aims to present a secure healthcare network infrastructure while presenting the security vulnerabilities in the current hospital information systems. The regulation criteria in Turkey and counterparts in USA and EU are compared according to their Privacy approach and a list of items for common security controls from different industries is proposed as a best practice. The study shows that the hospital is not compliant with known healthcare standards like HIPAA or ISO 80001. Management's attitude against Privacy and security shows that the responsibility is totally to IT and Biomedical Engineering Departments. As hospitals are adopting electronic transactions, consideration must be given to protect public electronic health records in terms of Personal Privacy aspects. Healthcare industry in Turkey should benefit from best practices in other industries and applications in other countries. This study can lead the pathway for policy makers in healthcare organizations and regulation authorities to implement a more secure environment for every citizen.