lnu.sePublikasjoner
Endre søk
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
On System Thinking and Information Security
Linnéuniversitetet, Fakulteten för teknik (FTK), Institutionen för informatik (IK).ORCID-id: 0009-0000-8265-0944
Linnéuniversitetet, Fakulteten för teknik (FTK), Institutionen för informatik (IK). (Information Management)ORCID-id: 0000-0001-6227-0290
Linnéuniversitetet, Fakulteten för teknik (FTK), Institutionen för informatik (IK). (Information Management)ORCID-id: 0000-0002-3670-6537
2019 (engelsk)Inngår i: The OR Society Annual Conference OR61, 3-5 September 2019, Sibson Building, Kent University: Conference Handbook, The Operational Research Society , 2019, s. 161-162, artikkel-id OR61A151Konferansepaper, Oral presentation with published abstract (Fagfellevurdert)
Abstract [en]

Security problems we have to deal with today regarding Internet are created by ourselves. Internet, initially created to handle US Government data traffic, evolved to become communication between different research institutes. The protocols that were used had no security at all. Today we still use this network to almost everything and the complexity has grown tremendously. Compared to when the network initially was created, we now try to protect assets rather than just communicate, divide users according to permission and accessibility, and deal with privacy issues. Basically, everything is depending on the network that initially was created with no security.

Privacy has been a critical security aspect for the EU, but with the event of the GDPR privacy is both a legal aspect and an auditable ICT concept. GDPR includes topics like: owning your own data, independent of who collected it and where it is stored, and; the right to be forgotten. Each data collector also needs to have a complete data-flow map, describing any privacy data sets in a flow, to make these traceable and ready for audit inspection. Any organization handling EU residents’ data, needs to adhere to proactive Information Security processes. 

GDPR is based on the principles of Governance, Risk, and Compliance. It is not a purely legal construct; it is a management and strategy issue, not an IT issue. Further examples relate to cloud services with distributed resources, which illustrate the complex problem situation.

There is a need for a new perspective, moving from systems management to data flow management. We propose a systemic model which illustrate processes and flows within a fractal structure; we build on Beer’s Viable System Model. Such a model enables mapping of complexity and data flows and provide a tool for auditing and, thus, enable meeting the requirements of GDPR.

sted, utgiver, år, opplag, sider
The Operational Research Society , 2019. s. 161-162, artikkel-id OR61A151
HSV kategori
Forskningsprogram
Data- och informationsvetenskap, Informatik
Identifikatorer
URN: urn:nbn:se:lnu:diva-89020OAI: oai:DiVA.org:lnu-89020DiVA, id: diva2:1349425
Konferanse
The Operational Research Society OR61 Annual Conference
Tilgjengelig fra: 2019-09-09 Laget: 2019-09-09 Sist oppdatert: 2024-08-28bibliografisk kontrollert

Open Access i DiVA

Fulltekst mangler i DiVA

Person

Magnusson, LarsElm, PatrikMirijamdotter, Anita

Søk i DiVA

Av forfatter/redaktør
Magnusson, LarsElm, PatrikMirijamdotter, Anita
Av organisasjonen

Søk utenfor DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric

urn-nbn
Totalt: 336 treff
RefereraExporteraLink to record
Permanent link

Direct link
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annet format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annet språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf