Authors: Naila Azam, Anna Lito Michala, Shuja Ansari, Nguyen Truong
Published on: April 22, 2024
Impact Score: 8.0
Arxiv code: Arxiv:2404.13979
Summary
- What is new: A new threat modelling technique tailored to address GDPR compliance in systems handling personal data, integrating GDPR principles with existing security and privacy models.
- Why this is important: Existing threat modelling techniques do not adequately address GDPR compliance in complex systems dealing with personal data.
- What the research proposes: A comprehensive solution combining GDPR requirements with STRIDE and LINDDUN models, introducing a new data flow diagram integrated with GDPR principles and a knowledge base for non-compliance threats.
- Results: The proposed model successfully identifies and mitigates threats of non-compliance concerning legal basis and accountability in a telehealth system, proving the approach’s feasibility and effectiveness.
Technical Details
Technological frameworks used: Integration of GDPR principles with STRIDE and LINDDUN for threat modeling
Models used: A new data flow diagram specific to GDPR compliance, an inference engine for reasoning over the knowledge base
Data used: nan
Potential Impact
Telehealth systems, Data-driven service providers, Companies dealing with personal data in healthcare and other industries requiring GDPR compliance
Want to implement this idea in a business?
We have generated a startup concept here: PrivacyGuardAI.
Leave a Reply