메뉴 건너뛰기




Volumn 23, Issue 2, 2014, Pages 126-150

A systematic methodology for privacy impact assessments: A design science approach

Author keywords

design science; privacy impact assessment; privacy by design; security risk assessment

Indexed keywords

DESIGN; PERSONNEL; RADIO FREQUENCY IDENTIFICATION (RFID); RISK ASSESSMENT;

EID: 84896803078     PISSN: 0960085X     EISSN: 14769344     Source Type: Journal    
DOI: 10.1057/ejis.2013.18     Document Type: Review
Times cited : (151)

References (67)
  • 1
    • 85016755131 scopus 로고    scopus 로고
    • The accountability principle in data protection regulation: Origin, development and future directions
    • Palgrave Macmillan, New York
    • ALHADEFF J, VAN ALSENOY B and DUMORTIER J (2012) The accountability principle in data protection regulation: origin, development and future directions. In Managing Accountability through Privacy, pp 49-82, Palgrave Macmillan, New York.
    • (2012) Managing Accountability Through Privacy , pp. 49-82
    • Alhadeff, J.1    Van Alsenoy, B.2    Dumortier, J.3
  • 3
    • 0002437413 scopus 로고    scopus 로고
    • Investigating information systems with action research
    • BASKERVILLE R (1999) Investigating information systems with action research. Communications of the AIS 2(3), 1-32.
    • (1999) Communications of the AIS , vol.2 , Issue.3 , pp. 1-32
    • Baskerville, R.1
  • 4
    • 0030509189 scopus 로고    scopus 로고
    • A critical perspective on action research as a method for information system research
    • BASKERVILLE RL and WOOD-HARPER AT (1996) A critical perspective on action research as a method for information system research. Journal of Information Technology 11(3), 235-246
    • (1996) Journal of Information Technology , vol.11 , Issue.3 , pp. 235-246
    • Baskerville, R.L.1    Wood-Harper, A.T.2
  • 5
    • 84896751262 scopus 로고    scopus 로고
    • BBBOnLine, accessed 5 December 2011
    • BBBOnLine. (2011) BBBOnLine-BBB Accredited Business Seal. [WWW document] http://www.bbb.org/online/(accessed 5 December 2011).
    • (2011) BBBOnLine-BBB Accredited Business Seal
  • 7
    • 80455123284 scopus 로고    scopus 로고
    • BSI (Bundesamt für Sicherheit in der Informationstechnik)., BSI Standard 100-3. [WWW document], Accessed 20 March 2012
    • BSI (Bundesamt für Sicherheit in der Informationstechnik). (2008) Risk analysis on the basis of IT-Grundschutz, BSI Standard 100-3. [WWW document] https://www.bsi.bund.de/ContentBSI/Publikationen/BSI- Standard/it- grundschutzstandards.html#doc471418bodyText3 (accessed 20 March 2012).
    • (2008) Risk Analysis on the Basis of IT-Grundschutz
  • 8
    • 84896792600 scopus 로고    scopus 로고
    • BSI (Bundesamt für Sicherheit in der Informationstechnik)., IT-Grundschutz-Kataloge. [WWW document], accessed 29 February 2012
    • BSI (Bundesamt für Sicherheit in der Informationstechnik). (2011a) IT-Grundschutz-Kataloge. [WWW document] https://www.bsi.bund.de/DE/Themen/ ITGrundschutz/StartseiteITGrundschutz/startseiteit-grundschutz-node.html (accessed 29 February 2012).
    • (2011)
  • 9
    • 84896754868 scopus 로고    scopus 로고
    • BSI (Bundesamt für Sicherheit in der Informationstechnik)., Privacy impact assessment guideline for RFID applications. [WWW.document], accessed 7 March 2012
    • BSI (Bundesamt für Sicherheit in der Informationstechnik). (2011b) Privacy impact assessment guideline for RFID applications. [WWW.document] https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/ElekAusweise/PIA/ Privacy-Impact-Assessment-Guideline-Langfassung.pdf;jsessionid= 4BE04C3871C6AEB0CD78E76F22F0153A.2-cid244?blob=publicationFile (accessed 7 March 2012).
    • (2011)
  • 10
    • 84896774528 scopus 로고    scopus 로고
    • Privacy by design Take the challenge. Information and Privacy Commissioner of Ontario (Canada). [WWW document], accessed 10 October 2012)
    • CAVOUKIAN A (2009a) Privacy by design Take the challenge. Information and Privacy Commissioner of Ontario (Canada). [WWW document] http://www.ipc.on.ca/ images/Resources/PrivacybyDesignBook.pdf (accessed 10 October 2012).
    • (2009)
    • Cavoukian, A.1
  • 11
    • 84896799596 scopus 로고    scopus 로고
    • Privacy by design: the 7 foundational principles. Information and Privacy Commissioner of Ontario (Canada). [WWW document], (accessed 10 October 2012)
    • CAVOUKIAN A (2009b) Privacy by design: the 7 foundational principles. Information and Privacy Commissioner of Ontario (Canada). [WWW document] http://privacybydesign.ca/about/principles/(accessed 10 October 2012).
    • (2009)
    • Cavoukian, A.1
  • 12
    • 63849328022 scopus 로고    scopus 로고
    • Privacy impact assessment: Its origins and development
    • CLARKE R (2009) Privacy impact assessment: its origins and development. Computer Law & Security Review 25(2), 123-135.
    • (2009) Computer Law & Security Review , vol.25 , Issue.2 , pp. 123-135
    • Clarke, R.1
  • 13
    • 84864061144 scopus 로고    scopus 로고
    • An evaluation of privacy impact assessment guidance documents
    • CLARKE R (2011) An evaluation of privacy impact assessment guidance documents. International Data Privacy Law 1(2), 111-120.
    • (2011) International Data Privacy Law , vol.1 , Issue.2 , pp. 111-120
    • Clarke, R.1
  • 14
    • 0013243382 scopus 로고    scopus 로고
    • Specification-W3C Working Group Note 13 November 2006. [WWW document], (accessed 1 March 2012)
    • CRANOR LF et al (2006) The platform for privacy preferences 1.1 (P3P1.1) Specification-W3C Working Group Note 13 November 2006. [WWW document] http://www.w3.org/TR/P3P11/(accessed 1 March 2012).
    • (2006) The Platform for Privacy Preferences 1.1 (P3P1.1)
    • Cranor, L.F.1
  • 18
    • 84896756171 scopus 로고    scopus 로고
    • ENDORSE, [WWW document], accessed 1 March 2012
    • ENDORSE. (2011) ENDORSE Project. [WWW document] http://ict-endorse.eu/ (accessed 1 March 2012).
    • (2011) ENDORSE Project
  • 19
    • 0003187764 scopus 로고
    • Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data
    • EC (European Parliament and Council of the European Union).
    • EC (European Parliament and Council of the European Union). (1995) Directive 95/46/EC on the protection of individuals with regard to the processing of personal data and on the free movement of such data. Official Journal of the European Communities L 281/31: 31-50.
    • (1995) Official Journal of the European Communities L , vol.281 , Issue.31 , pp. 31-50
  • 22
    • 84896793019 scopus 로고    scopus 로고
    • EuroPriSe, [WWW document], accessed 5 December 2011
    • EuroPriSe. (2011) EuroPriSe-European privacy seal. [WWW document] https://www.european-privacy-seal.eu/(accessed 5 December 2011).
    • (2011) EuroPriSe-European Privacy Seal
  • 25
    • 33846102423 scopus 로고    scopus 로고
    • The nature of theory in information systems
    • GREGOR S (2006) The nature of theory in information systems. MIS Quarterly 30(3), 611-642.
    • (2006) MIS Quarterly , vol.30 , Issue.3 , pp. 611-642
    • Gregor, S.1
  • 27
    • 0242652022 scopus 로고    scopus 로고
    • Design science in information systems research
    • HEVNER AR, MARCH ST, PARK J and RAM S (2004) Design science in information systems research. MIS Quarterly 28(1), 75-105.
    • (2004) MIS Quarterly , vol.28 , Issue.1 , pp. 75-105
    • Hevner, A.R.1    March, S.T.2    Park, J.3    Ram, S.4
  • 28
    • 55949134407 scopus 로고    scopus 로고
    • A paradigmatic analysis of information systems as a design science
    • IIVARI J (2007) A paradigmatic analysis of information systems as a design science. Scandinavian Journal of Information Systems 19(2), 39-64
    • (2007) Scandinavian Journal of Information Systems , vol.19 , Issue.2 , pp. 39-64
    • Iivari, J.1
  • 29
    • 70349833881 scopus 로고    scopus 로고
    • Information & Privacy Commissioner of Ontario (IPCO), [WWW document], accessed 7 February 2011
    • Information & Privacy Commissioner of Ontario (IPCO). (2011) Privacy by design. [WWW document] http://privacybydesign.ca (accessed 7 February 2011)
    • (2011) Privacy by Design
  • 30
    • 84896755702 scopus 로고    scopus 로고
    • Intelligentpia (iPIA), [WWW document], accessed 1 March 2012
    • Intelligentpia (iPIA). (2011) intelligentPIA-a privacy impact assessment tool. [WWW document] http://www.wu.ac.at/ec/research/ipia (accessed 1 March 2012).
    • (2011) IntelligentPIA a Privacy Impact Assessment Tool
  • 31
    • 80052673108 scopus 로고    scopus 로고
    • INFSO (European Commission Information Society and Media Directorate-General)., 12 January 2011, Brussels
    • INFSO (European Commission, Information Society and Media Directorate-General). (2011) Privacy and data protection impact assessment framework for RFID applications, 12 January 2011, Brussels.
    • (2011) Privacy and Data Protection Impact Assessment Framework for RFID Applications
  • 32
    • 84896756447 scopus 로고    scopus 로고
    • ISO (International Organization for Standardization), ISO FDIS 22307 Financial Services-privacy impact assessment
    • ISO (International Organization for Standardization). (2002) ISO FDIS 22307 Financial Services-privacy impact assessment.
    • (2002)
  • 38
    • 0005487402 scopus 로고    scopus 로고
    • Reason, relativity, and responsibility in computer ethics
    • MOOR JH (1998) Reason, relativity, and responsibility in computer ethics. Computers and Society 28(1), 14-21.
    • (1998) Computers and Society , vol.28 , Issue.1 , pp. 14-21
    • Moor, J.H.1
  • 40
    • 1842829828 scopus 로고    scopus 로고
    • NIST (National Institute of Standards and Technology)., NIST Special Publication
    • NIST (National Institute of Standards and Technology). (2002) Risk management guide for information technology systems, NIST Special Publication 800-30.
    • (2002) Risk Management Guide for Information Technology Systems , pp. 800-830
  • 43
    • 84905736726 scopus 로고    scopus 로고
    • Surveillance: Extending the limits of privacy impact assessments
    • Springer, Dordrecht
    • RAAB C and WRIGHT D (2012) Surveillance: extending the limits of privacy impact assessments. In Privacy Impact Assessment (WRIGHT D and DE HERT P, Eds) pp 363-383, Springer, Dordrecht.
    • (2012) Privacy Impact Assessment (WRIGHT D and de HERT P, Eds , pp. 363-383
    • Raab, C.1    Wright, D.2
  • 45
    • 84864126972 scopus 로고    scopus 로고
    • Privacy by design und die Neuen Schutzziele
    • ROST M and BOCK K (2011) Privacy by design und die Neuen Schutzziele. Datenschutz und Datensicherheit-DuD 35(1), 30-35.
    • (2011) Datenschutz und Datensicherheit-DuD , vol.35 , Issue.1 , pp. 30-35
    • Rost, M.1    Bock, K.2
  • 48
    • 38849114766 scopus 로고    scopus 로고
    • Oldenbourg Verlag, München, Wien
    • SEIBILD H (2006) IT-Risikomanagement, Oldenbourg Verlag, München, Wien.
    • (2006) IT-Risikomanagement
    • Seibild, H.1
  • 49
    • 78549232777 scopus 로고    scopus 로고
    • Report, Office of the Privacy Commissioner, Auckland, New Zealand
    • SHROFF M (2007) Privacy Impact Assessment Handbook, Report, Office of the Privacy Commissioner, Auckland, New Zealand.
    • (2007) Privacy Impact Assessment Handbook
    • Shroff, M.1
  • 50
    • 33747194078 scopus 로고    scopus 로고
    • Information security standards-focus on the existence of process, not its content
    • SIPONEN M (2006) Information security standards-focus on the existence of process, not its content. Communications of the ACM 49(8), 97-100.
    • (2006) Communications of the ACM , vol.49 , Issue.8 , pp. 97-100
    • Siponen, M.1
  • 51
    • 67651102640 scopus 로고    scopus 로고
    • Information security management standards: Problems and solutions
    • SIPONEN M and WILLISON R (2009) Information security management standards: problems and solutions. Information & Management 46(5), 267-270.
    • (2009) Information & Management , vol.46 , Issue.5 , pp. 267-270
    • Siponen, M.1    Willison, R.2
  • 52
    • 0036045758 scopus 로고    scopus 로고
    • Conceptualizing privacy
    • SOLOVE DJ (2002) Conceptualizing privacy. California Law Review 90(4), 1087-1156.
    • (2002) California Law Review , vol.90 , Issue.4 , pp. 1087-1156
    • Solove, D.J.1
  • 55
    • 84863760903 scopus 로고    scopus 로고
    • The challenges of privacy by design
    • SPIEKERMANN S (2012) The challenges of privacy by design. Communications of the ACM 55(7), 38-40.
    • (2012) Communications of the ACM , vol.55 , Issue.7 , pp. 38-40
    • Spiekermann, S.1
  • 57
    • 0000400750 scopus 로고
    • An assessment of the scientific merits of action research
    • SUSMAN GI and EVERED RD (1978) An assessment of the scientific merits of action research. Administrative Science Quarterly 23(4), 582-603
    • (1978) Administrative Science Quarterly , vol.23 , Issue.4 , pp. 582-603
    • Susman, G.I.1    Evered, R.D.2
  • 58
    • 84896744310 scopus 로고    scopus 로고
    • TRUSTe., [WWW document], accessed 5 December 2011
    • TRUSTe. (2011) TRUSTe privacy seal. [WWW document] http://www.truste.com/ (accessed 5 December 2011).
    • (2011) TRUSTe Privacy Seal
  • 59
    • 78549232777 scopus 로고    scopus 로고
    • UK Information Commissioners Office (ICO)., UK Information Commissioners Office (ICO), London
    • UK Information Commissioners Office (ICO). (2009) Privacy Impact Assessment Handbook (Version 2.0), UK Information Commissioners Office (ICO), London.
    • (2009) Privacy Impact Assessment Handbook (Version 2.0)
  • 62
    • 0002430582 scopus 로고
    • Building an information system design theory for vigilant EIS
    • WALLS JG, WIDMEYER GR and EL SAWY OA (1992) Building an information system design theory for vigilant EIS. Information Systems Research 3(1), 36-59.
    • (1992) Information Systems Research , vol.3 , Issue.1 , pp. 36-59
    • Walls, J.G.1    Widmeyer, G.R.2    Sawy, E.L.3
  • 65
    • 77955619458 scopus 로고    scopus 로고
    • Should privacy impact assessments be mandatory?
    • WRIGHT D (2011) Should privacy impact assessments be mandatory? Communications of ACM 54(8), 121-131.
    • (2011) Communications of ACM , vol.54 , Issue.8 , pp. 121-131
    • Wright, D.1


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.