A privacy-by-design framework based on information control and zero trust
Information privacy has been a concern in the digital age. Unauthorized information disclosure and misuse have been an ongoing challenge within a highly connected society. Numerous privacy breaches have raised the need for effective and robust information protection. Information owners are incapabl...
Saved in:
Main Author: | |
---|---|
Other Authors: | |
Format: | Thesis-Master by Coursework |
Language: | English |
Published: |
Nanyang Technological University
2020
|
Subjects: | |
Online Access: | https://hdl.handle.net/10356/138084 |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Institution: | Nanyang Technological University |
Language: | English |
id |
sg-ntu-dr.10356-138084 |
---|---|
record_format |
dspace |
spelling |
sg-ntu-dr.10356-1380842020-04-23T10:30:33Z A privacy-by-design framework based on information control and zero trust Anis Yusof Brendan Luyt Wee Kim Wee School of Communication and Information Brendan@ntu.edu.sg Library and information science::Knowledge management Information privacy has been a concern in the digital age. Unauthorized information disclosure and misuse have been an ongoing challenge within a highly connected society. Numerous privacy breaches have raised the need for effective and robust information protection. Information owners are incapable of exercising their rights to protect and control their information in the event of a privacy breach. Existing security and privacy frameworks were chronologically analyzed on their respective techniques in safeguarding information. The analysis allows an understanding of contextual issues and privacy challenges. Technical security mechanisms in the existing frameworks were identified and critically examined based on its effectiveness in resolving privacy challenges. The technological advancement in the past decades has seen an evolution of privacy framework that addresses contemporary information privacy issues. These frameworks signify that an information owner does not have the necessary level of control for their personal information. By understanding existing technical security mechanisms, a privacy framework is proposed based on the principles of privacy-by-design that achieve the Zero Trust principles. The focus of the proposed framework is to empower information owners to protect, secure and control their information before sharing. This framework will revolutionize the existing perspective towards information privacy as privacy control is shifted from third parties to the information owners. However, transferring the control from third parties to information owners is associated with both technical and non-technical challenges. While technical challenges are rectifiable, human-related challenges pose a higher privacy risk that will require non-technical solutions. Therefore, a holistic approach must be conceived to resolve privacy issues, which have the potential to accelerate technological advancement that benefits the community. Master of Science (Information Systems) 2020-04-23T10:30:33Z 2020-04-23T10:30:33Z 2020 Thesis-Master by Coursework https://hdl.handle.net/10356/138084 en application/pdf Nanyang Technological University |
institution |
Nanyang Technological University |
building |
NTU Library |
country |
Singapore |
collection |
DR-NTU |
language |
English |
topic |
Library and information science::Knowledge management |
spellingShingle |
Library and information science::Knowledge management Anis Yusof A privacy-by-design framework based on information control and zero trust |
description |
Information privacy has been a concern in the digital age. Unauthorized information disclosure and misuse have been an ongoing challenge within a highly connected society. Numerous privacy breaches have raised the need for effective and robust information protection. Information owners are incapable of exercising their rights to protect and control their information in the event of a privacy breach. Existing security and privacy frameworks were chronologically analyzed on their respective techniques in safeguarding information. The analysis allows an understanding of contextual issues and privacy challenges. Technical security mechanisms in the existing frameworks were identified and critically examined based on its effectiveness in resolving privacy challenges. The technological advancement in the past decades has seen an evolution of privacy framework that addresses contemporary information privacy issues. These frameworks signify that an information owner does not have the necessary level of control for their personal information. By understanding existing technical security mechanisms, a privacy framework is proposed based on the principles of privacy-by-design that achieve the Zero Trust principles. The focus of the proposed framework is to empower information owners to protect, secure and control their information before sharing. This framework will revolutionize the existing perspective towards information privacy as privacy control is shifted from third parties to the information owners. However, transferring the control from third parties to information owners is associated with both technical and non-technical challenges. While technical challenges are rectifiable, human-related challenges pose a higher privacy risk that will require non-technical solutions. Therefore, a holistic approach must be conceived to resolve privacy issues, which have the potential to accelerate technological advancement that benefits the community. |
author2 |
Brendan Luyt |
author_facet |
Brendan Luyt Anis Yusof |
format |
Thesis-Master by Coursework |
author |
Anis Yusof |
author_sort |
Anis Yusof |
title |
A privacy-by-design framework based on information control and zero trust |
title_short |
A privacy-by-design framework based on information control and zero trust |
title_full |
A privacy-by-design framework based on information control and zero trust |
title_fullStr |
A privacy-by-design framework based on information control and zero trust |
title_full_unstemmed |
A privacy-by-design framework based on information control and zero trust |
title_sort |
privacy-by-design framework based on information control and zero trust |
publisher |
Nanyang Technological University |
publishDate |
2020 |
url |
https://hdl.handle.net/10356/138084 |
_version_ |
1681056697946210304 |