PP-SDLC The Privacy Protecting Systems Development Life Cycle
نویسندگان
چکیده
Many new Privacy Laws and Regulations have placed an increased importance on the correct design and implementation of information systems. This is an attempt to preserve and protect user and information privacy. Incorporating privacy regulations and guidelines into an active information system is often unsuccessful and ineffective. In addition, systems that have already progressed through the development life cycle can very expensive to change once implemented. We propose the integration of privacy preservation methodologies and techniques into each phase of the system development life cycle (SDLC). This is to preserve the privacy of individuals and to protect PII (Personally Identifiable Information) data. The incorporation of IT Security measures in each SDLC phase is also discussed. This is due to its direct relevance and correlation with information system privacy issues. The proposed methodology involves identifying the privacy and security issues in each phase. From there appropriate privacy protecting and security techniques are applied to address these issues. Special mention is made of the recently proposed Common Criteria. The CC is an international standard for IT Security for Information Systems. Specifically, this paper will analyse the way the Common Criteria currently deals with privacy in information systems, and what is needed to improve its current inadequate handling of information privacy.
منابع مشابه
Integrating Risk Management in System Development Life Cycle
Integrating Risk Management in System Development Life Cycle 1 M. F. Unuakhalu, 2 D.Sigdel, 3 M. Garikapati, Kentucky State University, U.S.A _____________________________________________________________________________________ Abstract: While impossible to eliminate all risk from organizational operations, one of the most effective ways to protect organization assets is through the incorporati...
متن کاملIntegrating Human-Computer Interaction Development into the Systems Development Life Cycle: A Methodology
Incorporating a human computer interaction (HCI) perspective into the systems development life cycle (SDLC) is necessary to information systems (IS) success and, in turn, to the success of businesses. However, modern SDLC models are based more on organizational needs than human needs. The human interaction aspect of an information system is usually considered far too little (only the screen int...
متن کاملA System Development Life Cycle for Persuasive Design for Sustainability
The impact of a system development lifecycle (SDLC) often determines the success of a project from analysis to evolution. Although SDLC can be universally used design projects, a focused SDLC for a specific complex design issue could be valuable for understanding diverse user needs. The importance of sustainability elevation using a persuasive system is not new. Previous research presented fram...
متن کاملImplications from Decision Science for the Systems Development Life Cycle in Information Systems
Nomology, a decision science approach to structuring qualitative decisions, is used to show that the Systems Development Life Cycle (SDLC) corresponds to a generic structure based on a Convincing process embedded within a Committing process, both of which were formalised originally by Kant as dialectical processes. The key decision issue in the SDLC is shown to be that of ownership of the proce...
متن کاملIntegrating Human-Computer Interaction Development into SDLC: A Methodology
Incorporating a human computer interaction (HCI) perspective into the systems development life cycle (SDLC) is critical to information systems (IS) success and in turn to the success of businesses. However, modern SDLC models are based more on organizational needs than human needs. The human interaction aspect of an information system is considered far too little (only the screen interface) and...
متن کامل