2019
Conference article  Restricted

GDPR-Based User Stories in the Access Control Perspective

Bartolini C., Daoudagh S., Lenzini G., Marchetti E.

User Story  Access Control Policy (ACP)  General Data Protection Regulation (GDPR) 

Because of GDPR's principle of "data protection by design and by default", organizations who wish to stay lawful have to re-think their data practices. Access Control (AC) can be a technical solution for them to protect access to "personal data by design", and thus to gain legal compliance, but this requires to have Access Control Policies (ACPs) expressing requirements aligned with GDPR's provisions. Provisions are however pieces of law and are not written to be immediately interpreted as technical requirements; the task is thus not straightforward. The Agile software development methodology can help untangle the problem. It has dedicated tools to describe requirements and one of such them, User Stories, seems up to task. Stories are concise yet informal descriptions telling who, what and why something is required by users; they are prioritized in lists, called backlogs. Inspired by these Agile tools this paper advances the notion of Data Protection backlogs, which are lists of User Stories about GDPR provisions told as technical requirements. For each User Story we build a corresponding ACP, so enabling the implementation of GDPR compliant AC systems.

Source: International Conference on the Quality of Information and Communications Technology QUATIC 2019, pp. 3–17, Ciudad Real, Spain, 11-13/09/2019

Publisher: Springer, Heidelberg ;, Germania


Metrics



Back to previous page
BibTeX entry
@inproceedings{oai:it.cnr:prodotti:415740,
	title = {GDPR-Based User Stories in the Access Control Perspective},
	author = {Bartolini C. and Daoudagh S. and Lenzini G. and Marchetti E.},
	publisher = {Springer, Heidelberg ;, Germania},
	doi = {10.1007/978-3-030-29238-6_1},
	booktitle = {International Conference on the Quality of Information and Communications Technology  QUATIC 2019, pp. 3–17, Ciudad Real, Spain, 11-13/09/2019},
	year = {2019}
}

CyberSec4Europe
Cyber Security Network of Competence Centres for Europe


OpenAIRE