A privacy-by-design framework based on information control and zero trust

Information privacy has been a concern in the digital age. Unauthorized information disclosure and misuse have been an ongoing challenge within a highly connected society. Numerous privacy breaches have raised the need for effective and robust information protection. Information owners are incapabl...

Full description

Saved in:
Bibliographic Details
Main Author: Anis Yusof
Other Authors: Brendan Luyt
Format: Thesis-Master by Coursework
Language:English
Published: Nanyang Technological University 2020
Subjects:
Online Access:https://hdl.handle.net/10356/138084
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Nanyang Technological University
Language: English
id sg-ntu-dr.10356-138084
record_format dspace
spelling sg-ntu-dr.10356-1380842020-04-23T10:30:33Z A privacy-by-design framework based on information control and zero trust Anis Yusof Brendan Luyt Wee Kim Wee School of Communication and Information Brendan@ntu.edu.sg Library and information science::Knowledge management Information privacy has been a concern in the digital age. Unauthorized information disclosure and misuse have been an ongoing challenge within a highly connected society. Numerous privacy breaches have raised the need for effective and robust information protection. Information owners are incapable of exercising their rights to protect and control their information in the event of a privacy breach. Existing security and privacy frameworks were chronologically analyzed on their respective techniques in safeguarding information. The analysis allows an understanding of contextual issues and privacy challenges. Technical security mechanisms in the existing frameworks were identified and critically examined based on its effectiveness in resolving privacy challenges. The technological advancement in the past decades has seen an evolution of privacy framework that addresses contemporary information privacy issues. These frameworks signify that an information owner does not have the necessary level of control for their personal information. By understanding existing technical security mechanisms, a privacy framework is proposed based on the principles of privacy-by-design that achieve the Zero Trust principles. The focus of the proposed framework is to empower information owners to protect, secure and control their information before sharing. This framework will revolutionize the existing perspective towards information privacy as privacy control is shifted from third parties to the information owners. However, transferring the control from third parties to information owners is associated with both technical and non-technical challenges. While technical challenges are rectifiable, human-related challenges pose a higher privacy risk that will require non-technical solutions. Therefore, a holistic approach must be conceived to resolve privacy issues, which have the potential to accelerate technological advancement that benefits the community. Master of Science (Information Systems) 2020-04-23T10:30:33Z 2020-04-23T10:30:33Z 2020 Thesis-Master by Coursework https://hdl.handle.net/10356/138084 en application/pdf Nanyang Technological University
institution Nanyang Technological University
building NTU Library
country Singapore
collection DR-NTU
language English
topic Library and information science::Knowledge management
spellingShingle Library and information science::Knowledge management
Anis Yusof
A privacy-by-design framework based on information control and zero trust
description Information privacy has been a concern in the digital age. Unauthorized information disclosure and misuse have been an ongoing challenge within a highly connected society. Numerous privacy breaches have raised the need for effective and robust information protection. Information owners are incapable of exercising their rights to protect and control their information in the event of a privacy breach. Existing security and privacy frameworks were chronologically analyzed on their respective techniques in safeguarding information. The analysis allows an understanding of contextual issues and privacy challenges. Technical security mechanisms in the existing frameworks were identified and critically examined based on its effectiveness in resolving privacy challenges. The technological advancement in the past decades has seen an evolution of privacy framework that addresses contemporary information privacy issues. These frameworks signify that an information owner does not have the necessary level of control for their personal information. By understanding existing technical security mechanisms, a privacy framework is proposed based on the principles of privacy-by-design that achieve the Zero Trust principles. The focus of the proposed framework is to empower information owners to protect, secure and control their information before sharing. This framework will revolutionize the existing perspective towards information privacy as privacy control is shifted from third parties to the information owners. However, transferring the control from third parties to information owners is associated with both technical and non-technical challenges. While technical challenges are rectifiable, human-related challenges pose a higher privacy risk that will require non-technical solutions. Therefore, a holistic approach must be conceived to resolve privacy issues, which have the potential to accelerate technological advancement that benefits the community.
author2 Brendan Luyt
author_facet Brendan Luyt
Anis Yusof
format Thesis-Master by Coursework
author Anis Yusof
author_sort Anis Yusof
title A privacy-by-design framework based on information control and zero trust
title_short A privacy-by-design framework based on information control and zero trust
title_full A privacy-by-design framework based on information control and zero trust
title_fullStr A privacy-by-design framework based on information control and zero trust
title_full_unstemmed A privacy-by-design framework based on information control and zero trust
title_sort privacy-by-design framework based on information control and zero trust
publisher Nanyang Technological University
publishDate 2020
url https://hdl.handle.net/10356/138084
_version_ 1681056697946210304