To ensure the effectiveness of the adopted security measures and minimize the impact of security issues on the rights and freedom of individuals, the General Data Protection Regulation (GDPR) requires to carry out a Data Processing Impact Assessment (DPIA). Such an assessment differs from traditional risk analyses in which the actor carrying out the evaluation is also the one interested in reducing its risk. Conflicts may thus arise between the need of protecting data subjects rights and organizations that shall provide adequate security measures while struggling with various types of constraints (e.g., budget). To alleviate this problem, we introduce the Multi-Stakeholder Risk Trade-off Analysis Problem, (MSRToAP) and propose an automated technique to solve their instances. We then show how this can help data controllers make more informed decisions about which security mechanisms allow for a better trade-off between their requirements and those of the data subjects. For concreteness, we illustrate the proposed on a simple yet realistic use case scenario.

Multi-stakeholder cybersecurity risk assessment for data protection / Mollaeefar, M.; Siena, A.; Ranise, S.. - 3:(2020), pp. 349-356. (Intervento presentato al convegno 17th International Conference on Security and Cryptography, SECRYPT 2020 - Part of the 17th International Joint Conference on e-Business and Telecommunications, ICETE 2020 tenutosi a fra nel 2020) [10.5220/0009822703490356].

Multi-stakeholder cybersecurity risk assessment for data protection

Ranise S.
2020-01-01

Abstract

To ensure the effectiveness of the adopted security measures and minimize the impact of security issues on the rights and freedom of individuals, the General Data Protection Regulation (GDPR) requires to carry out a Data Processing Impact Assessment (DPIA). Such an assessment differs from traditional risk analyses in which the actor carrying out the evaluation is also the one interested in reducing its risk. Conflicts may thus arise between the need of protecting data subjects rights and organizations that shall provide adequate security measures while struggling with various types of constraints (e.g., budget). To alleviate this problem, we introduce the Multi-Stakeholder Risk Trade-off Analysis Problem, (MSRToAP) and propose an automated technique to solve their instances. We then show how this can help data controllers make more informed decisions about which security mechanisms allow for a better trade-off between their requirements and those of the data subjects. For concreteness, we illustrate the proposed on a simple yet realistic use case scenario.
2020
ICETE 2020 - Proceedings of the 17th International Joint Conference on e-Business and Telecommunications
AV D MANUELL, 27A 2 ESQ, SETUBAL, 2910-595, PORTUGAL
SciTePress
978-989-758-446-6
Mollaeefar, M.; Siena, A.; Ranise, S.
Multi-stakeholder cybersecurity risk assessment for data protection / Mollaeefar, M.; Siena, A.; Ranise, S.. - 3:(2020), pp. 349-356. (Intervento presentato al convegno 17th International Conference on Security and Cryptography, SECRYPT 2020 - Part of the 17th International Joint Conference on e-Business and Telecommunications, ICETE 2020 tenutosi a fra nel 2020) [10.5220/0009822703490356].
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/333044
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 4
  • ???jsp.display-item.citation.isi??? 4
social impact