Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • Persone
  • Pubblicazioni
  • Strutture
  • Competenze
  1. Pubblicazioni

GDPR-Based User Stories in the Access Control Perspective

Contributo in Atti di convegno
Data di Pubblicazione:
2019
Abstract:
Because of GDPR's principle of "data protection by design and by default", organizations who wish to stay lawful have to re-think their data practices. Access Control (AC) can be a technical solution for them to protect access to "personal data by design", and thus to gain legal compliance, but this requires to have Access Control Policies (ACPs) expressing requirements aligned with GDPR's provisions. Provisions are however pieces of law and are not written to be immediately interpreted as technical requirements; the task is thus not straightforward. The Agile software development methodology can help untangle the problem. It has dedicated tools to describe requirements and one of such them, User Stories, seems up to task. Stories are concise yet informal descriptions telling who, what and why something is required by users; they are prioritized in lists, called backlogs. Inspired by these Agile tools this paper advances the notion of Data Protection backlogs, which are lists of User Stories about GDPR provisions told as technical requirements. For each User Story we build a corresponding ACP, so enabling the implementation of GDPR compliant AC systems.
Tipologia CRIS:
04.01 Contributo in Atti di convegno
Keywords:
Access Control Policy (ACP); General Data Protection Regulation (GDPR); User Story
Elenco autori:
Daoudagh, Said; Marchetti, Eda
Autori di Ateneo:
DAOUDAGH SAID
MARCHETTI EDA
Link alla scheda completa:
https://iris.cnr.it/handle/20.500.14243/376436
Titolo del libro:
Quality of Information and Communications Technology. QUATIC 2019. Communications in Computer and Information Science
Pubblicato in:
COMMUNICATIONS IN COMPUTER AND INFORMATION SCIENCE (PRINT)
Series
  • Dati Generali

Dati Generali

URL

https://link.springer.com/chapter/10.1007%2F978-3-030-29238-6_1
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)