Skip to Main Content (Press Enter)

Logo CNR
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills

UNI-FIND
Logo CNR

|

UNI-FIND

cnr.it
  • ×
  • Home
  • People
  • Outputs
  • Organizations
  • Expertise & Skills
  1. Outputs

GDPR-Based User Stories in the Access Control Perspective

Conference Paper
Publication Date:
2019
abstract:
Because of GDPR's principle of "data protection by design and by default", organizations who wish to stay lawful have to re-think their data practices. Access Control (AC) can be a technical solution for them to protect access to "personal data by design", and thus to gain legal compliance, but this requires to have Access Control Policies (ACPs) expressing requirements aligned with GDPR's provisions. Provisions are however pieces of law and are not written to be immediately interpreted as technical requirements; the task is thus not straightforward. The Agile software development methodology can help untangle the problem. It has dedicated tools to describe requirements and one of such them, User Stories, seems up to task. Stories are concise yet informal descriptions telling who, what and why something is required by users; they are prioritized in lists, called backlogs. Inspired by these Agile tools this paper advances the notion of Data Protection backlogs, which are lists of User Stories about GDPR provisions told as technical requirements. For each User Story we build a corresponding ACP, so enabling the implementation of GDPR compliant AC systems.
Iris type:
04.01 Contributo in Atti di convegno
Keywords:
Access Control Policy (ACP); General Data Protection Regulation (GDPR); User Story
List of contributors:
Daoudagh, Said; Marchetti, Eda
Authors of the University:
DAOUDAGH SAID
MARCHETTI EDA
Handle:
https://iris.cnr.it/handle/20.500.14243/376436
Book title:
Quality of Information and Communications Technology. QUATIC 2019. Communications in Computer and Information Science
Published in:
COMMUNICATIONS IN COMPUTER AND INFORMATION SCIENCE (PRINT)
Series
  • Overview

Overview

URL

https://link.springer.com/chapter/10.1007%2F978-3-030-29238-6_1
  • Use of cookies

Powered by VIVO | Designed by Cineca | 26.5.0.0 | Sorgente dati: PREPROD (Ribaltamento disabilitato)