Compliance with data protection laws using Hippocratic Database active enforcement and auditing

17Citations
Citations of this article
26Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Governments worldwide are enacting data protection laws that restrict the disclosure and processing of personal information. These laws impose administrative and financial burdens on companies that manage personal information and may hinder the legitimate and valuable sharing and analysis of this information. In this paper we describe an integrated set of technologies, known as the Hippocratic Database (HDB), which enables compliance with security and privacy regulations without impeding the legitimate flow of information. HDB's Control Center allows companies to specify fine-grained disclosure policies based on the role of the user, the purpose of the access, the intended recipient, and other disclosure conditions. Its Active Enforcement component transparently enforces these policies by transforming user queries in a middleware layer to ensure that the database returns only policy-compliant information. HDB's Compliance Auditing system efficiently tracks all database accesses and allows auditors to formulate precise audit queries to monitor compliance with privacy and security policies. In this paper, we outline the basic architecture of the HDB solution, discuss the advantages of our approach, and illustrate the features of each component with practical compliance scenarios from the financial services industry. © 2007 IBM.

Cite

CITATION STYLE

APA

Johnson, C. M., & Grandison, T. W. A. (2007). Compliance with data protection laws using Hippocratic Database active enforcement and auditing. IBM Systems Journal, 46(2), 255–264. https://doi.org/10.1147/sj.462.0255

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free