Information privacy is one of the most important ethical issues of the information age. Consequently, personal data is described as the new oil of the Internet and the new currency of the digital world. Appropriate management of the protection and use of personal information is important as almost every organization stores and uses (processes) personal information that can include names, addresses, contact details, staff, and medical records. According to ISO/IEC 27701 privacy information management is an extension of information security management, described in ISO/IEC 27001. Key elements of the operation of a management system in general and of an Information Privacy Management System (IPMS) are processes. Unlike for information security management, currently there is no process framework or process reference model for information privacy management available. IPMS processes are not in focus of current research. This article aims to fill this research gap by proposing such an IPMS process framework as the main contribution. Based on a set of agreed upon IPMS processes in existing standards like ISO/IEC 27701, ISO/IEC 29100, ISO/IEC 29134, ISO/IEC 29190, ISO/IEC 29151, and BS 10012. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the IPMS, instead of focusing on privacy measures and controls. By this, as a main finding, the systemic character of the IPMS consisting of processes and the perception of relevant roles of the IPMS is strengthened.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Information Privacy Management—A Process Reference Model

  • Knut Haufe

摘要

Information privacy is one of the most important ethical issues of the information age. Consequently, personal data is described as the new oil of the Internet and the new currency of the digital world. Appropriate management of the protection and use of personal information is important as almost every organization stores and uses (processes) personal information that can include names, addresses, contact details, staff, and medical records. According to ISO/IEC 27701 privacy information management is an extension of information security management, described in ISO/IEC 27001. Key elements of the operation of a management system in general and of an Information Privacy Management System (IPMS) are processes. Unlike for information security management, currently there is no process framework or process reference model for information privacy management available. IPMS processes are not in focus of current research. This article aims to fill this research gap by proposing such an IPMS process framework as the main contribution. Based on a set of agreed upon IPMS processes in existing standards like ISO/IEC 27701, ISO/IEC 29100, ISO/IEC 29134, ISO/IEC 29190, ISO/IEC 29151, and BS 10012. Within the framework, identified processes are described and their interaction and interfaces are specified. This framework helps to focus on the operation of the IPMS, instead of focusing on privacy measures and controls. By this, as a main finding, the systemic character of the IPMS consisting of processes and the perception of relevant roles of the IPMS is strengthened.