Privacy, security and ethical reflection
ITC568 Cloud Privacy and Security
Knowledge Management and Privacy
Week 11
Dr Peter White
be able to examine the legal, business and privacy requirements for a cloud deployment model;
be able to evaluate the risk management requirements for a cloud deployment model;
be able to critically analyse the legal, ethical and business concerns for the security and privacy of data to be deployed to the cloud;
be able to develop and present a series of proposed security controls to manage the security and privacy of data deployed to the cloud;
Agenda
© Peter White, 2017
2
Knowledge Management (KM) is defined as
“the systematic and organizationally specified process for acquiring, organising and communicating knowledge of employees so that other employees may make use of it to be more effective and productive in their work”
It consists of the processes of:
Discovering: where the knowledge resides
Gathering: obtaining knowledge from tacit (individual) and explicit (documentary) sources
Filtering: rejecting redundancy in knowledge
Organizing: rearranging & composing the knowledge so it can be retrieved and used, and
Sharing: transferring knowledge between individuals and groups
© Peter White, 2017
3
What is Knowledge Management?
Technology is always used as a tool in KM to support the implementation of KM processes and activities
But the limitations of Technology in KM are:
It is mainly used for storage of knowledge
It works better with explicit knowledge
It overlooks the social interaction between people
Access procedures can be either too restrictive or too loose
Finding knowledge can sometimes be quite difficult
Knowledge may not be indexed, so searching is difficult and costly
But, if indexed, users may be swamped with many returns that are not sufficiently accurate
© Peter White, 2017
4
KM & Technology
KaaS can be described as:
the knowledge extracted from the owners datasets
by consumers through a knowledge extracting service
upon the consumers request
This model is based on a model used in China to support medical services in hospitals and radiology centres
External consultants use the hospital information to give expert opinions
The information is also used to support additional medical research and treatment development
© Peter White, 2017
5
Knowledge as a Service (KaaS)
Consider the types, and classifications, of data that are likely to be included in a KaaS:
PII data?
PII transactional data?
Sensitive information?
Usage data, eg. Internet access, medical services, prescription drugs, etc.?
What are the likely privacy concerns for that KaaS data?
Transparency?
Minimisation of data?
Accessibility?
Limitations on usage?
Security controls?
Regulatory/Legislative issues?
© Peter White, 2017
6
Privacy and Security in KaaS
© Peter White, 2017
7
Modelling a KaaS
A Knowledge Organisation (KO) consists of groups, users and roles
A user can be a member of more than 1 group, or of no groups
Groups can be members of other groups
A user can hold roles in more than 1 group
More than 1 user can hold the same role
This organisation allows users to:
develop knowledge from data,
share it
Within their group, or
With other groups
Here a set of discovered Knowledge Elements is handled by 3 sub-groups:
Discovery
Gathering
Filtering
Each of these groups has a coordinator to provide for:
Sub-group collaboration and
Sub-group knowledge sharing
A group manager may coordinate knowledge sharing between higher level groups
Knowledge sharing becomes as much a social issue as a technical one.
© Peter White, 2017
8
Modelling a KaaS
We can see that different users can have quite different KM activities
Some users will be solely concerned with one KM aspect, such as the bag
Some will be concerned only with the KM health aspects
Others will be concerned with overlapping KM activities
Note also that there are management activities that add nothing to the KM activities, but are essential for coordination and sharing
© Peter White, 2017
9
Modelling a KaaS
The privacy approach used here is a distributed approach:
There are separate services for
Coordination
Discovery
Sharing
Creation
Each of these services passes through an Access Control service
The underlying Knowledge Sets are held in separate databases
Access to the databases is controlled by the Access Control service.
© Peter White, 2017
10
Privacy in a KaaS
© Peter White, 2017
11
Privacy in a KaaS
Does a distributed approach, as used in the previous diagram, provide sufficient privacy and security protection to the knowledge sets?
Is there another approach that could be used?
How would you approach securing a KaaS?
Reading:
Ali, A., Hawryskziewycz, I. (2015). Cloud as infrastructure for managing complex scalable business networks, privacy perspective. In Ko, R., & Choo, K.(Eds.). (2015). The Cloud Security Ecosystem: Technical, Legal, Business and Management Issues. Waltham, MA: Syngress.
deHert, P., Papakonstantinou, V., & Kamara, I. (2016). The cloud computing standard ISO/IEC 27018 through the lens of EU legislation on data protection. Computer Law and Security Review, 32(1), 16-30. https://ezproxy.csu.edu.au/login?url=http://dx.doi.org/10.1016/j.clsr.2015.12.005
Additional Reading
Bertino, E., et al. (2006). "Secure knowledge management: confidentiality, trust, and privacy." IEEE Transactions on systems, man, and cybernetics-Part A: Systems and humans 36(3): 429-438. http://www.utd.edu/~bxt043000/Publications/Journal-Papers/DAS/J42_Secure_Knowledge_Management_Confidentiality_Trust_and_Privacy.pdf
Watch:
The impact of ISO27018 on Cloud Contracts https:// youtu.be/y1h18Xq4NvE
Webinar: ISO Cloud Security & Privacy Standards https:// youtu.be/q2dnZuanPy4
© Peter White, 2017
12
Tasks: