Hide metadata

dc.date.accessioned2013-03-12T08:14:44Z
dc.date.available2013-03-12T08:14:44Z
dc.date.issued2006en_US
dc.date.submitted2006-05-14en_US
dc.identifier.citationHiorth-Schøyen, Helle. Enforcement of Privacy Policies in Enterprise Systems. Masteroppgave, University of Oslo, 2006en_US
dc.identifier.urihttp://hdl.handle.net/10852/9453
dc.description.abstractIn our daily life, large amounts of personal data are collected, stored and processed in enterprise systems. This is often done without our knowledge. The protection of these personal data has become a matter of concern for legislators, enterprises, and increasingly aware data subjects. The goal of this thesis is to investigate the use of a transparent privacy framework to enforce privacy policies in enterprise systems, and to establish a set of criteria for such a framework. In this thesis, the concepts of privacy and privacy enhancing technologies (PETs) including the Enterprise Privacy Authorisation Language (EPAL) are discussed, the current legislation pertaining to privacy is presented, enterprise systems including the technology of web services are introduced, and a set of criteria is derived from a study of these concepts. Further, the development of a demo enterprise application system is presented and its integration with a transparent privacy framework for the enforcement of privacy policies in enterprise systems is discussed. The modifications to the framework necessary for this integration are also discussed. The results obtained from this integration are discussed, and analysed and evaluated with respect to this set of derived criteria. These criteria imply that such frameworks must authenticate users and map system activities to purposes and privacy relevant actions. Data subjects must be identified and personal policies handled. Privacy relevant data categories of the enterprise must be identified and context data received to evaluate conditions. Obligations that may follow from processing personal data should be implemented. These are all criteria for protecting the confidentiality and integrity of personal data and have through this thesis showed to be difficult to implement in a transparent application framework. The results arrived in this Master’s thesis identify and highlight a number of challenges in the area of transparent privacy frameworks and make clear the need for further work on this subject.nor
dc.language.isoengen_US
dc.titleEnforcement of Privacy Policies in Enterprise Systems : Principles and Criteria for a Transparent Application Frameworken_US
dc.typeMaster thesisen_US
dc.date.updated2006-06-13en_US
dc.creator.authorHiorth-Schøyen, Helleen_US
dc.subject.nsiVDP::420en_US
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation&rft.au=Hiorth-Schøyen, Helle&rft.title=Enforcement of Privacy Policies in Enterprise Systems&rft.inst=University of Oslo&rft.date=2006&rft.degree=Masteroppgaveen_US
dc.identifier.urnURN:NBN:no-12369en_US
dc.type.documentMasteroppgaveen_US
dc.identifier.duo40902en_US
dc.contributor.supervisorJens Kaasbøllen_US
dc.identifier.bibsys060964057en_US
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/9453/1/HHS.pdf


Files in this item

Appears in the following Collection

Hide metadata