Inicio  /  Future Internet  /  Vol: 13 Par: 2 (2021)  /  Artículo
ARTÍCULO
TITULO

A Perfect Match: Converging and Automating Privacy and Security Impact Assessment On-the-Fly

Dimitrios Papamartzivanos    
Sofia Anna Menesidou    
Panagiotis Gouvas and Thanassis Giannetsos    

Resumen

As the upsurge of information and communication technologies has become the foundation of all modern application domains, fueled by the unprecedented amount of data being processed and exchanged, besides security concerns, there are also pressing privacy considerations that come into play. Compounding this issue, there is currently a documented gap between the cybersecurity and privacy risk assessment (RA) avenues, which are treated as distinct management processes and capitalise on rather rigid and make-like approaches. In this paper, we aim to combine the best of both worlds by proposing the APSIA (Automated Privacy and Security Impact Assessment) methodology, which stands for Automated Privacy and Security Impact Assessment. APSIA is powered by the use of interdependency graph models and data processing flows used to create a digital reflection of the cyber-physical environment of an organisation. Along with this model, we present a novel and extensible privacy risk scoring system for quantifying the privacy impact triggered by the identified vulnerabilities of the ICT infrastructure of an organisation. We provide a prototype implementation and demonstrate its applicability and efficacy through a specific case study in the context of a heavily regulated sector (i.e., assistive healthcare domain) where strict security and privacy considerations are not only expected but mandated so as to better showcase the beneficial characteristics of APSIA. Our approach can complement any existing security-based RA tool and provide the means to conduct an enhanced, dynamic and generic assessment as an integral part of an iterative and unified risk assessment process on-the-fly. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them, so that such holistic security and privacy mechanisms can reach their full potential towards solving this conundrum.

 Artículos similares

       
 
Hanyue Xu, Kah Phooi Seng, Jeremy Smith and Li Minn Ang    
In the context of smart cities, the integration of artificial intelligence (AI) and the Internet of Things (IoT) has led to the proliferation of AIoT systems, which handle vast amounts of data to enhance urban infrastructure and services. However, the co... ver más
Revista: Future Internet

 
Nasour Bagheri, Ygal Bendavid, Masoumeh Safkhani and Samad Rostampour    
A smart grid is an electricity network that uses advanced technologies to facilitate the exchange of information and electricity between utility companies and customers. Although most of the technologies involved in such grids have reached maturity, smar... ver más
Revista: Future Internet

 
Keundug Park and Heung-Youl Youm    
The volume of the asset investment and trading market can be expanded through the issuance and management of blockchain-based security tokens that logically divide the value of assets and guarantee ownership. This paper proposes a service model to solve ... ver más

 
Azizah Assiri and Hassen Sallay    
Opportunistic mobile social networks (OMSNs) have become increasingly popular in recent years due to the rise of social media and smartphones. However, message forwarding and sharing social information through intermediary nodes on OMSNs raises privacy c... ver más
Revista: Future Internet

 
Sana Rasheed and Soulla Louca    
A national population census is instrumental in offering a holistic view of a country?s progress, directly influencing policy formulation and strategic planning. Potential flaws in the census system can have detrimental impacts on national development. O... ver más
Revista: Future Internet