首页> 外文期刊>European journal of information systems >Taking stock of organisations' protection of privacy: categorising and assessing threats to personally identifiable information in the USA
【24h】

Taking stock of organisations' protection of privacy: categorising and assessing threats to personally identifiable information in the USA

机译:评估组织的隐私保护:在美国分类和评估对个人身份信息的威胁

获取原文
获取原文并翻译 | 示例
           

摘要

Many organisations create, store, or purchase information that links individuals' identities to other data. Termed personally identifiable information (PII), this information has become the lifeblood of many firms across the globe. As organisations accumulate their constituencies' PII (e.g. customers', students', patients', and employees' data), individuals' privacy will depend on the adequacy of organisations' information privacy safeguards. Despite existing protections, many breaches still occur. For example, US organisations reported around 4,500 PII-breach events between 2005 and 2015. With such a high number of breaches, determining all threats to PII within organisations proves a burdensome task. In light of this difficulty, we utilise text-mining and cluster analysis techniques to create a taxonomy of various organisational PII breaches, which will help drive targeted research towards organisational PII protection. From an organisational systematics perspective, our classification system provides a foundation to explain the diversity among the myriad of threats. We identify eight major PII-breach types and provide initial literature reviews for each type of breach. We detail how US organisations differ regarding their exposure to these breaches, as well as how the level of severity (i.e. number of records affected) differs among these PII breaches. Finally, we offer several paths for future research.
机译:许多组织创建,存储或购买将个人身份与其他数据相关联的信息。被称为个人身份信息(PII)的信息已成为全球许多公司的命脉。随着组织积累其选区的PII(例如客户,学生,患者和员工的数据),个人的隐私将取决于组织的信息隐私保护措施的充分性。尽管有现有的保护措施,但仍有许多违反行为发生。例如,美国组织报告说在2005年至2015年之间发生了约4,500起PII违规事件。由于违规数量如此之高,确定组织内对PII的所有威胁被证明是一项繁重的任务。鉴于这一困难,我们利用文本挖掘和聚类分析技术来创建各种组织PII违规的分类法,这将有助于推动针对组织PII保护的目标研究。从组织系统的角度来看,我们的分类系统为解释无数威胁之间的差异提供了基础。我们确定了八种主要的PII违规类型,并针对每种违规类型提供了初步的文献综述。我们将详细介绍美国组织在这些违规风险方面的差异,以及严重程度(即受影响的记录数)在这些PII违规之间的差异。最后,我们提供了一些未来研究的途径。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号