Modeling ecosystems of reference frameworks for assurance: a case on privacy impact assessment regulation and guidelines

Author:

Ruiz AlejandraORCID,Martin Yod-SamuelORCID,Martinez JabierORCID,Quintans Jacobo,Mockly Guillaume,Gyrard AmelieORCID,Crepax TommasoORCID

Abstract

AbstractTo assure certain critical quality properties (e.g., safety, security, or privacy), supervisory authorities and industrial associations provide reference frameworks such as standards or guidelines that in some cases are enforced (e.g., regulations). Given the pace at which both technical advancements and risks appear, there is an increase in the number of reference frameworks. As several frameworks might apply for same systems, certain overlaps appear (e.g., regulations for different countries where the system will operate, or generic standards in conjunction with more concrete standards for a given industrial sector or system type). We propose the use of modelling for alleviating the complexity of these reference frameworks ecosystems, and we provide a tool-supported method to create them for the benefit of different stakeholders. The case study is based on privacy data protection, and more concretely on privacy impact assessment processes. The European GDPR regulates the movement and processing of personal data, and, contrary to available software engineering privacy guidelines, articles in legal texts are usually difficult to translate to the underlying processes, artefacts and roles that they refer to. To facilitate the mutual comprehension of legal experts and engineers, in this work we investigate how mappings can be created between these two domains of expertise. Notably, we rely on modelling as a central point. We modelled the legal requirements of the GDPR on data protection impact assessments, and then, we selected the ISO/IEC 29134, a mainstream engineering guideline for privacy impact assessment, and, taking a concrete sector as example, the EU Smart Grid Data Protection Impact Assessment template. The OpenCert tool was used for providing technical support to both the modelling and the creation of the mapping models in a systematic way. We provide a qualitative evaluation from legal experts and privacy engineering practitioners to report on the benefits and limitations of this approach.

Funder

European Unions Horizon 2020

Publisher

Springer Science and Business Media LLC

Subject

Modeling and Simulation,Software

Reference38 articles.

1. North Atlantic Treaty Organization, Nato Standard AEP-67. Engineering For System Assurance In Nato Programmes, Edition B Version 1., https://nso.nato.int/nso/zPublic/ap/PROM/AEP-67%20EDB%20V1%20E.pdf (October 2017)

2. ISO/IEC, ISO/IEC 29134:2017 Information technology, Security techniques, Guidelines for privacy impact assessment, https://www.iso.org/standard/62289.html (2017)

3. Smart Grid Task Force 2012-14 Expert Group 2, Regulatory Recommendations for Privacy, Data Protection and Cyber-Security in the Smart Grid Environment. Data Protection Impact Assessment Template for Smart Grid and Smart Metering systems, https://ec.europa.eu/energy/sites/default/files/documents/dpia_for_publication_2018.pdf (2018)

4. Union, E.: Regulation (eu) 2016/679 of the european parliament and of the council of 27 april 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing directive 95/46/ec (general data protection regulation) (2016-05-04)

5. Ruiz, A., Lopez, A., Juez, G., Martinez, C., de la Vara, J., Álvarez, J., Parra, E., Alonso, L., Lopez, B., Puri, S., et al.: AMASS platform validation, D2.9, 2019, https://www.amass-ecsel.eu/sites/amass.drupal.pulsartecnalia.com/files/D2.9_AMASS-platform-validation_AMASS_Final.pdf

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3