Identifying and Quantifying Trade-offs in Multi-Stakeholder Risk Evaluation with Applications to the Data Protection Impact Assessment of the GDPR

07/15/2022
by   Majid Mollaeefar, et al.
0

Cybersecurity risk management consists of several steps including the selection of appropriate controls to minimize risks. This is a difficult task that requires to search through all possible subsets of a set of available controls and identify those that minimize the risks of all stakeholders. Since stakeholders may have different perceptions of the risks (especially when considering the impact of threats), conflicting goals may arise that require to find the best possible trade-offs among the various needs. In this work, we propose a quantitative and (semi)automated approach to solve this problem based on the well-known notion of Pareto optimality. For validation, we show how a prototype tool based on our approach can assist in the Data Protection Impact Assessment mandated by the General Data Protection Regulation on a simplified but realistic use case scenario. We also evaluate the scalability of the approach by conducting an experimental evaluation with the prototype with encouraging results.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/24/2023

Changes in Conducting Data Protection Risk Assessment and After GDPR implementation

Based on Article 35 of the EU (European Union) General Data Protection R...
research
03/11/2019

Security, Performance and Energy Trade-offs of Hardware-assisted Memory Protection Mechanisms

The deployment of large-scale distributed systems, e.g., publish-subscri...
research
07/07/2022

A Methodology to Support Automatic Cyber Risk Assessment Review

Cyber risk assessment is a fundamental activity for enhancing the protec...
research
11/11/2022

Normative Challenges of Risk Regulation of Artificial Intelligence and Automated Decision-Making

Recent proposals aiming at regulating artificial intelligence (AI) and a...
research
01/18/2021

Data Protection Impact Assessment for the Corona App

Since SARS-CoV-2 started spreading in Europe in early 2020, there has be...
research
10/14/2021

Privacy Impact Assessment: Comparing methodologies with a focus on practicality

Privacy and data protection have become more and more important in recen...
research
06/18/2021

Bayesian decision theory for tree-based adaptive screening tests with an application to youth delinquency

Crime prevention strategies based on early intervention depend on accura...

Please sign up or login with your details

Forgot password? Click here to reset