An Integrated Knowledge Graph to Automate GDPR and PCI DSS Compliance
An Integrated Knowledge Graph to Automate GDPR and PCI DSS Compliance
复制标题
用于自动化 GDPR 和 PCI DSS 合规性的集成知识图
DOI:
10.1109/bigdata.2018.8622236
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
K. Joshi
中科院分区:
文献类型:
--
作者:
Lavanya Elluri;Ankur Nagar;K. Joshi
Big data analytics related to consumer behavior, market analysis, opinions, and recommendation often deal with end user's derived and inferred data, along with the observed data. To ensure consumer data protection, rules defined by the European Union’s General Data Protection Regulation (EU GDPR) must be adhered to by every organization using Personally Identifiable Information (PII) data for Big Data analysis. Similarly, Payment Card Industry Data Security Standard (PCI DSS) has policy guidelines specifically for organizations handling consumer’s payment card data. Both data regulation policies are currently available only in textual format and require significant manual effort to ensure their compliance. We have developed an integrated, semantically rich Knowledge Graph (or Ontology) to represent the rules mandated by both PCI DSS and EU GDPR. In the Ontology, we have also identified the obligations defined in these regulations and related them with corresponding Cloud Security Alliance (CSA) controls. We have validated this Knowledge Graph against the data policies of major vendors that deal with Big Data. This Knowledge Graph that is available in the public domain can be used by Big Data practitioners to automate data protection compliance in their organization.