Note: this blog is a mirror of my HP Labs Blog, on the same topic, accessible at: http://h30507.www3.hp.com/t5/Research-on-Security-and/bg-p/163

Saturday, September 29, 2007

Privacy Management in Enterprises? It is a matter of Enforcement and Automation …

Privacy policy enforcement and automation are, in my view, two key aspects necessary to improve enterprise privacy management practices.

Privacy auditing and compliance checking are reactive approaches, definitely important but of little help when violations occur and the “privacy” of people has been compromised (e.g. their personal data has been misused, identity thefts, etc.). More effort is required to enforce privacy policies, in particular by introducing more automation (and integration with current enterprise identity management solutions …).

At HP Labs we have been researching for years in this direction. Some relevant projects have focused on:

In the context of the PRIME project, various Privacy Enhancing Approaches and Technologies have also been researched and developed.

More recently, the Identity Governance Framework (IGF) effort has introduced use cases, approaches and criteria to deal with data governance and enforce privacy both in enterprises and federated identity management contexts.

I argue that the decision on the “actual blend” of policy enforcement and auditing/compliance checking should be the outcome of a “risk analysis” process, which must keep into account the specific enterprise context and the assets to be protected.

--- NOTE: my original HP blog can be found here ---

No comments: