Towards a socio-technical approach for privacy requirements analysis for next-generation trusted research environments

Towards a socio-technical approach for privacy requirements analysis for next-generation trusted research environments
复制标题

面向下一代可信研究环境的隐私需求分析的社会技术方法

DOI:
10.1049/icp.2022.2061
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Carmichael L
Carmichael L
中科院分区:
--
文献类型:
--
作者:
Carmichael L

文献摘要

被引文献

相似文献

越来越多的先进分析方法--人工智能/机器学习--被用来发现大数据集中的价值。这些方法正在推动新的数据处理模式和研究合作形式,这些模式和形式以数据的联合共享和处理为基础。这种多利益攸关方处理提出了一个标准的隐私风险评估框架,可以充分处理在这种情况下产生的隐私风险的需要。在本文中,我们认为,隐私需求分析的社会技术方法提供了一个重要的起点,发展这样一个框架-作为一种手段,以促进在特定的背景下,有效的风险沟通,建模,模拟和评估的隐私风险的共同理解。举例来说,我们集中在三个主要领域。首先,为了描述隐私风险评估的范围和边界,我们概述了可信的研究环境和运营健康网络中新兴的数据使用模式。其次,为了就隐私问题、期望和保护措施进行有效和有意义的风险沟通,我们将重点放在五个保险箱上,作为用于构建有关访问敏感数据的讨论和决策的众所周知的原则和维度。第三,为了通过对常见风险因素的概念映射来促进共同理解,我们将ISO/IEC 27005信息安全风险管理方法与其他选定的隐私风险评估方法进行了比较。
Increasingly, advanced analytics methods – artificial intelligence/machine learning – are being used to discover value in big datasets. These methods are driving new data processing patterns and forms of research collaborations underpinned by the federated sharing and processing of data. Such multi-stakeholder processing raises the need for a standard privacy risk assessment framework that can fully deal with privacy risks arising in this context. In this paper, we argue that a socio-technical approach to privacy requirements analysis provides a crucial starting point for developing such a framework – as a means to foster a shared understanding of privacy risk in a specific context for effective risk communication, modelling, simulation, and evaluation. By way of example, we concentrate on three main areas. First, to describe the scope and boundaries for privacy risk assessment, we provide an overview of trusted research environments and emerging data usage patterns in operational health networks. Second, for effective and meaningful risk communication in respect of privacy concerns, expectations, and protective measures, we focus on the Five Safes as well-known principles and dimensions used to structure discussions and decision-making about access to sensitive data. Third, to promote a shared understanding through a conceptual mapping of common types of risk factors, we compare the ISO/IEC 27005 methodology for information security risk management with other selected privacy risk assessment methodologies.