need a power point

profileajaychary18
LiteratureReview.docx

Research Paper: The Internet of Things and its impact on individual privacy and security

University of the Cumberland

The Internet of things and its impact on individual privacy and security

October 13, 2019

Vishnu Kiran Gollapudi

Rambabu Potluri

ABSTRACT

The Internet of Things (IoT) is something that has potential to have an impact on how we live. Internet of Things is the concept of connecting devices such as mobile phones and all other electronic devices and has several significant benefits including storing sensor data that can be mined and used in several ways. The data is typically transferred over network when it comes to Internet of things which leads to a lot of security and privacy concerns. This research topic belongs to the concerns and challenges related concerned to the privacy and security of the information related to the individuals in the world of Internet of things. In this article we researched items regarding the privacy of user information that is transferred across the networks. A number of challenges prevent IoT devices from being protected and ensure end-to-end safety in an IoT environment. Because the concept of networking devices and other artifacts is relatively new, protection has not always been considered a top priority during the design phase of the product.

INTRODUCTION

Although technologies spurred by the “Internet of things” are increasingly being introduced in homes, only a few studies have examined the adoption or diffusion of such household technologies. During the era of Internet of things and Information Technology, cooperation and mutual integration of the electronic and multimedia devices across the network that are participating in the Interne to things, information of the individuals or the data related to a particular device is becoming highly valued commodity of strategic importance. Despite its growing prominence, SMT implementation has met with various challenges across the world, including limited adoption by consumers. The Internet of things electronization and exchange of information between electronic devices, and these kinds of facts combined together gives the community a fresh view and the significance of appropriate safety of data or information. Moreover, privacy of information and securing that information relates to individual’s willingness to regulate or impact information about themselves. The concept of information privacy came into existence long before information and communication devices or Internet of things in particular, changed its occurrences, impacts and management when in the mid-1980’s researches suggested that the arrival of increased use of information technologies or the devices that transmit humungous amounts of data, or the information age would lead to four major concerns about the use of this data: privacy, accuracy, property and accessibility (Robert, France, 2011). To get to a conclusion, we have conducted an emphirical analysis from 20 different sources or journals available in MIS Quarterly, on various concepts that relate to our study or problem statement on the impact of individual’s privacy and security in the era of Internet of things. Most of our research is related to the privacy, how users can maintain their personal and sensitive information from this information web and security, how that private information that is being transmitted across devices is done securely. The results provide support for many of the hypothesis and highlight the importance of motivational factors and some household demographic, privacy, and innovation-related factors on consumers intention to adopt Internet of Things. The internet of things or IoT refers to a system of interrelated mechanical and digital machines, computing devices, people, objects or animals provided with unique identifiers (UIDs) that contain data transferring ability over a network without the necessity of human-computer interaction. Many organizations across industries have resorted to IoT for efficient operation, better customer relationship management, improved business value and decision making (Eltayeb, 2017).

Therefore, IoT does not only refer to consumer devices but also a range of manufacturing automated devices. IoT itself has caused a change of mindset as technology has operationalized the world and brought the world closer to everybody. Each and everyday objects are connected to the network and becoming smarter. In other words, computing has gradually diffused into the environment with or without knowledge. Unfortunately, the trails of footprints the devices left on the internet tell a lot of stories ("IEEE Internet of Things Journal publication information", 2015). Personal privacy of individuals and information security is potentially threatened IoT, in the sense that cybercriminals can utilize the information to cause severe damage to a person.

Research in information technology shows that in the next decade the world will be full of sensors whereby every object embedded with sensors. Notably, currently, sensors exist in mobile phones, fitness tracker, smart watches and all these sensors communicate to the internet. A lot of data transacted on the internet. Manufacturers of the devices have incorporated unique apps that offer free services such as maps in the smart devices as result people purchase the ‘free' services through buying the accessories. Metadata from the internet created by small things expose a lot of information about private lifestyle and habits.

Today’s Internet has dramatically changed the way of relationships or communication between people. This is because, the Internet allows connections between people among acquaintances. Lot of practitioners and firms showed immense interest in this unique nature of communication and encourage their existing clients to propagate word of mouth through their client’s social connections. “Considering its significance, incentives and social dynamics are both core components of the IT artifact (e.g., Ba et al. 2001; Hevner et al. 2004)”, the design of online referral systems lead to a significant question for IS researches. In this article, “On the role of fairness and social distance in designing effective social referral systems”, the authors performed an experiment to investigate the effects of social distance and monetary incentives based on the performance of three designs on online referral systems which include rewarding only the proposer, rewarding only the responder and spliting the rewards fairly between the proposer and responder. Authors also derived how these social referral systems are different from recommender systems.

Moreover, We are in the midst of a major change in the manner we generate humungous amounts of data in the industries and thanks to the digitization of manufacturing. These facts led to a new revolutionary mechanism called IIoT (Industrial Internet of Things). The unprecedented proliferation of miniaturized sensors and intelligent communication, computing and control technologies have paved the way for the development of Industrial Internet of Things (Rehman et al, 2018). This industrial Internet of things include machine learning, parallel processing systems such as clusters, to store, process and perform some analytics on the data. The key technologies that include in this IIoT are, intelligent wireless sensors networks, IoT devices, cyber physical systems, edge servers on the internet, and cloud data centers to name few. In this article “Big Data Analytics in industrial IOT using concentric computing model” the authors came up with a new architecture to orchestrate all these devices for instance, IoT devices that are participating in the IIoT. This model simplifies the way we can run machine learning models are do Big Data Analytics on this huge in-network data transmission.

RESEARCH DESIGN

In our research design, we mainly focused our emphirical analysis on five key points that relate to our problem statement.

1. The ability for individuals to share, and to figure out how their data or information is being accumulated, transmitted and being used in this IOT hub;

2. The right to be isolated from others in terms of information and create an independent impression of the individual’s data and to reserve from others;

3. The ability to have containment on individual’s information when participating in any offline or online activities across the network;

4. The right to have access to the centralized storage or the storage location for the individual’s data or information; and

5. How will the individual be notified if any theft or a data breach is happened either when the data is persisted or when it is being transmitted across the networks.

Today, in the world of Internet of things, as most communications are digitized and stored as information, personal communication privacy and data privacy across the network can me merged into the construct of information privacy which focuses on information privacy because most privacy related Information Systems research has been focused on this construct (Robert, France, 2011). We have gathered various conceptualizations and the baseline studies to support our problem statement. We found from our research that the above mentioned five points are the main concerns shown in all the supporting research papers that we were presenting. There are a lot of solutions defined in various articles but most of them were proven theoretically and focused on securing the data that is stored on the edge meaning the device that is sending and receiving data. But, our concern of data privacy and security is about the data stored in common places or network.

In few of our analyzed case studies, Authors conducted few lab experiments and performed some arbitrary field experiments to test their theory. Overall, they have conducted four experiments. They mainly focused on effects of social distance and effect of fairness on referral performance. “Social distance is related to affective distance or how much sympathy a person feels for another within a social relationship (Bogardus 1947)”. The lab experiment provides basic insights into the effect of social distance and fairness into the referral performance by experimenting on a referral to purchase products from a website called “GroupBy”. The second one is a field experiment conducted with an online retail company which is being supported by first experiment to verify external validity and robustness. In the experiment 3, to gain more robustness from the first two experiments, the authors have changed the measurement of social distance to interactive referral which is often used in ordinance with affective social distance. Finally, experiment four is another lab experiment conducted with non-cash incentives. This experiment is mainly to provide further evidence on previous experiments and to improve the generalizability of their hypothesis considering various contexts. Finally, all these four experiments together contributed robust empirical analysis on the authors hypothesis.

The authors have analyzed that both social distances including interactive referral measurement and fairness combinedly effect the success of online referral systems. By divergence, when there is a possibility of small social distance, for instance, between friends, the proposers and responders most likely lean to send and accept unfair splits. This concludes that the referral performance is bound to dyadic relationship between proposers and responders in effective with fairness. Finally, authors conclude that effective referral systems provide substantial value for the firms and calls for attention on social relationships.

In one of our empirical analysis, they have proposed a layered architecture that authors came up with has multiple levels. The reason behind going with a multilayered data model to ingest, clean and verify data quality for big data analytics is, the IoT devices that are participating in this mechanism, are largely dispersed across various sites which may reside in multiple locations. The device sizes may vary from small digital devices such as thermostats, mobile devices to huge industrial oil and gas plants. To brief each layer, firstly, the outer gateway processors. These processors reside one step away from these sensing devices and are use full for data filtration and data reduction at the edge of the network. Secondly, the Inner gateway processors. These processors are one step below the outer gateway, helpful to deploy the Big Data Analytics applications. By deploying big data applications in this layer, we can ensure that the data is secured, and the work is done on the edge which means on premise. Third layer is outer central processor which reside at the forefront of centralized computing systems. These servers facilitate in controlling data routing and data processing at inner central processors. Finally, the last layer, Inner central processors. These processors reside at maximum distance from the sensing systems. These are massive distributed systems such as clusters and are utilized to deploy huge Big Data Analytics applications and are supported by large scale storage and communication infrastructure.

LITERATURE REVIEW

The review is based out of various case studies performed on securing information on IoT devices in various industries such as medical, oil and gas, finance etc., Customers purchases a device, but the software installed and services remain under the control of the manufacturers which indirectly insinuates that manufacturers are partly the owner of the gadget. In the health sector, IoT provides a wide range of benefits which includes patient surveillance through analysis of generated data. Health centers utilize IoT systems to accomplish tasks for example management of inventory for both medical and pharmaceutical instruments (Banerjee, Dong, Taghizadeh & Biswas, 2014).

Since IoT links several devices to the web and traffic colossal data, it requires robust security (Maras, 2015). Therefore, IoT security and IoT privacy have become significant concerns. For instance, the most common and recent IoT attacks are Mirai, a botnet infiltrated domain name server provider Dyn and closed down several websites marked the most significant distributed denial-of-service (DDoS) witnessed in the world. Furthermore, attackers access network by exploiting non-secured or weakly secured IoT devices.

Since IoT devices are closely linked an attacker exploits a single vulnerability to temper with data making it useless. Again, most manufacturers do not update their devices frequently, and the situation allows the hackers to infiltrate the system efficiently. Most connected devices ask a consumer to input personal identification and other sensitive information such as name, age, phone number, addresses and social media accounts. Consumers can prevent cybercriminals from stealing the information by utilizing the privacy feature whereby a person decide which information the public can access. However, it is generally advisable not to share any sensitive information online (Maras, 2015). People should take extra caution when sharing information on the internet and make use of other security measures such as passwords that cannot easily crack. There is an increased need to protect the organizational information from a variety of security hazards such as trade secrets, malicious attacks, disruption of important systems etc. (Whitman & Mattord, 2012). There are various methods and controls including technical and contractual regulations that can be included to create awareness of various threats that an organization can face (Agudelo, Bosua, Ahmad, & Maynard, 2015). The most effective of this measure is implementing an Information Security Policy. This policy is a form of control by which the management of the Memorial EMR Services (MES) provides guidance strategically on a varied range of issues such as security structures, roles and process that must be instituted and proper use of technologies. The document is also a proof of commitment that the management makes to the security standards. It documents the need, the concepts and resource information. The policy will govern the various roles, responsibilities and security architecture of the MES organization (Whitman & Mattord, 2012). Patient data is the topmost importance to the organization. Access to the patient data will be on requirement basis to the users (Agudelo et al., 2015). Figure* shows the roles of the MES Staff and their proximity to the patient data. While patient information is important for customer facing information, the trade secrets of software developed in house should be safe guarded in development environment. The information security in both production and developmental environment will be governed by this policy.

This document defines the common practices that have adhered to by all personnel and systems that play a role in creating, maintain, storing, accessing, processing and transmitting patient and developmental information (Agudelo et al., 2015). This policy is applicable to the software, hardware, communication and other devices that are utilized in the above-mentioned processes (Bulgurcu, Cavusoglu, & Benbasat, 2010). These devices include those connected to the MES network wirelessly, remotely via VPN, or hardwired (Agudelo, Bosua, Ahmad, & Maynard, 2015).

Employer- Employee Responsibilities

The employer and employee both hold responsibilities that have to implement to secure the information in the organization (Bulgurcu, Cavusoglu, & Benbasat, 2010). All employees are required to strictly comply with all regulations. Failure to do so will call for a disciplinary action by the Human Resource Department and HIPAA Compliance Officer (CO).

Employee Responsibilities

The first layer of defense is the individual user at MES. Each user is responsible for the afro mentioned duties. Physical Identification: Every user is required to carry a physical ID badge at all time while on the MES premises (Whitman & Mattord, 2012). Visitors and Contractors should contact the security office for a temporary ID when visiting the premises.

Unattended Computer Security: All users should lock their computers when leaving their desks (Bulgurcu, Cavusoglu, & Benbasat, 2010). The inactivity period will be set to 10 minutes and should not be altered personally. Users should not share login information with other users. Portable Information Devices: User is prohibited from moving information from one system to another using USB drives, CDs or any other portable device. No user is allowed copy information on to an unsecure device.

Browsing: Patient level health information which is protected by HIPAA regulations. stipulate a "need to know" before approval is granted to view the information (United States of Health and Human Services, 2003). A user should not access the information if not required. Network connectivity in respective to these devices, the user should comply with the security requirements when remotely connecting to the MES domains. The user should use VPN to access any ‘need to know’ information.

When considering the employee responsibilities, the employer is required to provide the facilities to enable the employer to adhere to the Information Security Policy. Employee background checks: The MES management is required to conduct background check on every personnel hired in the company (Bulgurcu, Cavusoglu, & Benbasat, 2010). Security Awareness and Training: The employer should provide security compliance training to each personnel hired. The training should cover the basics of dos and don’ts. The users should be trained every year to keep the certification up to date. The user should be provided with the knowledge of what should be done in cases or crisis (Whitman & Mattord, 2012).

HIPAA Compliance Training: The CO office should make sure that each employee is trained to know the rules of the HIPAA law and what to do incase or a breach (United States of Health and Human Services, 2003). There should be an anonymous mailbox set up for users to report any breaches of the HIPAA law (United States of Health and Human Services, 2003). The training should be renewed every year to keep the information up to date.

Information assurance, compliance, and legal policy

Electronic Medical Records (EMR) is required by law to follow all the legal laws to protect patient data. With technology advances moving at an exponential rate, health organizations require assurances that patient data is secure and comply with the legal policy. At MES, the firm has put in place strict and diligent protocols to protect patient data.

Patients trust health organizations with their health information and trust is important part for health organizations to increase their overall business opportunities (HealthIT.gov, 2015). MES maintains accurate patient records with protocols to mitigate the risk of breaches in patient data (HealthIT.gov, 2015). MES’s experienced Information Assurance (AI) analyst asses the risks for various assets related to patient data and puts in protocols to limit the vulnerabilities and threats to patient data (HealthIT.gov, 2015). After these protocols are evaluated, IA analyst develops a risk management plan to mitigate, eliminate, and transfers risks. Countermeasure involved in information assurance may include firewalls and anti-virus software’s to prevent breaches in patient data.

MES’s IA also assures the process of providing patient data to the concerned authorities (Ferran, 2015). The firm has developed various security protocols which involve passwords and key security questions that allow only authorized users to access patient data. (Ferran, 2015)

The firm also complies with the Health Insurance Portability and Accountability Act (HIPAA) (United States of Health and Human Services, 2003). Privacy and security is required by HIPPA law while dealing with patient records. This law was passed by congress in 1996 which specifies the access of patient medical records (United States of Health and Human Services, 2003). Memorial has put in strict policies to its employees to follow the HIPPAA privacy law to all patient data.

MES has developed patient data records in a way that it is legally sound (United States of Health and Human Services, 2003). EMR data is in legal format and follows all the federal and state rules. All healthcare organizations are required by law to maintain medical records in a legal, regulatory, and professional requirement that can be used in both clinical and business purposes (Healthcare Information and Management Systems Society, 2015).

Structure of IoT Systems

The IoT framework comprises of various highlights that require a portion of the elements, knowledge, versatility, and substance while actualizing the utilization of various IT security for dangers alleviations.

Be that as it may, the IT designers have been searching for a portion of the security vulnerabilities by identifying IoT challenges, (Vasilomanolakis, Daubert, Luthra, Gazis et al (2018).

The clients ought to have clear data and abilities they can apply in running the IoT administrations. The principle point of the IoT gadgets is to get associated with the innovation arrange frameworks. There are three highlights utilized in IoT including Presentation, the equipment, and the middleware, Mendez, Papapanagiotou and Yang (2017, p. 2). The semantic-situated, the web arranged, and the things-arranged are a portion of the three elements occupied with structure the IoT conditions as referenced by Mendez, Papapanagiotou and Yang (2017, p. 2). Additionally, the IoT components ought to likewise be associated with their design layers including the observation layer checking the ecological information, the application layer that interfaces various individuals for the collaboration purposes, and the system layer that is a remote association between the information transmitted from the recognition layer consequently empowering the client communications.

IoT Properties

The IoT properties are more advanced compared to the use of the traditional IT system that was used previously such as cloud computing, enterprise application, data, and some of the IT security approaches used, Lin & Bergmann (2016, p. 3). Moreover, there are some of the properties that the user should understand their differences such as controlled resources, heterogeneity, unrestrained environment, and critical scalability.

The Uncontrolled Environment

There are some of the environmental factors that cannot be easily mitigated when there are some of the risks affecting the IoT devices. The IoT requires mobility environment where there can be an effective network connection which requires individual trusts while increasing influential relationship between different IoT users for better services. Some of the IoT devices are used to control some of the cameras and sensors that are useful IT devices.

The Heterogeneity

There is various internet connection for the IoT devices which can be implemented to compact to the different version by taking some of the consideration that has some of the interoperability features.

Essential Scalability

There are different scales that should be implemented when deploying the use of IoT devices by determining security protocols. It increases the security approaches that can help the user to mitigate any kind of threats using the symmetric key of information cryptography.

Controlled Resources

There is some pressure inserted when the IT developers create IoT devices which requires some of the effective security approaches while limiting the use of the power sources to generate the operations of the device such as micro-sensors.

Security Challenges of IoT Systems

Apparently, there are some of the challenges that have been detected to have a negative impact on the use of IoT. Therefore, some of the outdated software and hardware can lead to security breaches such as network system that can cause an error in the communication channel through Internet connections. Moreover, it is advisable to deploy some of the practices that can help in monitoring the IoT risks, threats, and vulnerabilities under secured control measures, (Liu, Zhao, Li, Zhang et al (2017, p. 1). There are some of the IoT security and privacy protection.

It requires a portion of the significant highlights when creating IoT uses, for example, the remote sensors including cameras that screen the client condition anyway doesn't offer any insurance at whatever point there is a physical assault. All things considered, there are a portion of the remote sensors that can distinguish security dangers in any event, when the client is in another area can recognize. In certain spots, the client relies upon a remote sensor confirmation for successful programming establishment that identifies and screen any malware dangers causing IT dangers. Notwithstanding, there are a portion of the difficulties that straightforwardly influence the utilization of the IoT including blunders happening during a correspondence procedure that is prompting information breaks.

At the point when we talk about the honesty, we consider the estimation of the data being gone through an alternate correspondence channel that depends on the utilization of the IoT gadgets. Accordingly, the client ought to convey probably the accepted procedures to guarantee the data is shielded from the interloper get to. Accordingly, encryption will confine programmer's dangers that will require valuable system security. Also, a portion of the programmers execute the utilization of the social building hacking strategy to meddle with the information respectability that causes information breaks making a portion of the IoT clients to lose significant information documents.

Additionally, before one takes part in the utilization of IoT, the individual should initially recognize the dangers of losing helpful and private data. The data ought to be a lot of private from some other clients, consequently the data administration strategy will help in recognizing the dangers, dangers, and vulnerabilities by executing a portion of the significant security techniques for IoT dangers moderation. A portion of the remote correspondence systems, for example, Wi-Fi ought to be associated with web gadgets under the tied down system to confine the programmers from getting to the client IoT gadgets. Such gadgets incorporate cell phones, PCs, and tablets. In this manner, there ought to be a security convention introduced between the product and remote systems to anticipate information breaks while transmitting data to another client while limiting the interlopers from getting to the IoT gadgets. In any case, a portion of the IT specialists state that there are contrasts among IoT and cell phones, PCs, and tablets because of their propelled highlights with well-planned sensors that identify and relieve the IoT danger in a split second. There ought to be information encryption to help in verifying and shielding the information from security ruptures that can meddle with data privacy.

The Solution: IoT Security Requirements

The IoT designers consistently have deliberately moved toward how they can improve security prerequisites. The principal safety efforts that one ought to comprehend when conveying the utilization of IoT is security. One ought to make and shield their data secretly from being gotten to by interlopers. Also, IoT clients ought to distinguish dangers causes that can prompt IoT gadgets activity disappointments through an improved structural plan for security purposes.

Additionally, the utilization of distributed computing and Big Data were recently used to ensure and verify data while expanding the degree of IoT framework security. At last, the IoT designers have been making a portion of the powerful dangers relief that aides in limiting every one of the difficulties through new progressed inclining IT apparatuses, Zhou, Zhang and Liu (2018, p. 5). The usage of the Big Data help in making a portion of the huge stockpiling gadgets to build the IoT data proficiency. The enormous information investigation additionally help in keeping up and verifying client data utilizing distributed computing administrations. In addition, distributed computing administrations are likewise useful where the client can scramble their data in their servers consequently expanding the IoT activity to an increasingly adaptable and valuable methodology utilizing physical sensors in identifying security ruptures.

The IoT security prerequisites help in improving various gadgets with an upgraded security convention, Vasilomanolakis, Daubert, Luthra, Gazis et al (2018). Furthermore, distributed computing comprises of various spaces that are associated with the IT servers. Consequently, it is the duty of the IoT clients to recognize the five principle zones for security necessities including Trust, Network wellbeing, the Elasticity, the Self-administration, and protection. Also, there are a portion of the confinement that can be executed to help in limiting the dangers influencing the utilization of IoT. The IoT has a portion of the highlights, for example, heterogeneity that requires data adaptability for the uncontrolled condition.

System Security: System security is probably the best methodologies where there is the execution of the utilization of IT credibility, accessibility, secrecy, and uprightness for the better Internet of Things administrations. There are a portion of the controllable highlights that one needs to comprehend for the IoT security reflection. System security help in relieving a portion of the information phishing through social building hacking dangers. Along these lines, the clients ought to be prepared and instructed on a portion of the development methodologies of utilizing IoT under well-verified system gadgets.

Apparently, transport security is another prerequisite for IoT gadgets through a valuable innovation approach. Assets can be obliged the utilization of assets to executes the best arrangements that help in overseeing and controlling the IoT confirmation level while limiting unapproved client for getting to significant data. Such data ought to be secret and private for the client to keep up their information uprightness without causing information breaking.

There must be an association among respectability and genuineness for better security breaks location while moderating the dangers influencing the IoT frameworks. Accessibility manages the data associated with the gadgets consequently should be verified and shielded from any dangers.

Personality the board

Personality the board is one of the levels where the client ought to have the option to recognize a portion of the IoT gadgets challenges. character the board is one of the IoT proprietors and the administrations they get from the utilization of the gadgets. Thusly, the security must be conveyed following the framework approval, confirmation, disavowal, and non-renouncement. At times it is extremely difficult to actualize the utilization of IoT personality the executives since it dwarfs the validation steps required to assume responsibility for different gadgets through valuable system association by means of the web server areas.

Approval of individual access is additionally compelling to support the client while validating the client to get to a portion of the data by keeping an eye on their own spaces. Responsibility of the IoT framework administrations ought to be well-broke down by the engineers to expand its security level and abstain from reaching negative effects.

Security

Security is required in each IoT gadgets that help the clients to keep up and control any relating difficulties that can meddle with the activity offered by the utilization of the IT framework. In addition, it manages information development and security to guarantee the client has kept up its data trustworthiness through private access. The execution of the username and a solid secret word is one of the private and classified logins data that one needs to have to empower the security progressively dynamic in verifying the data from any gatecrasher get to. One ought to guarantee there is valuable information encryption which just validates the approved clients to access the most private data that is viewed as a Personal Identifiable Information (PII).

The obscurity is one of the specialized terms used to portray the client and perceive its recognizable highlights for the information gathered while limiting the dangers, dangers, and helplessness of the IoT gadgets.

Pseudonymity is a methodology that is associated with both data responsibility and secrecy. It has various alternatives that empower the client to make viable methodology because of aliases a gave connection that can prompt the information rupture. It includes the client security that has distinctive data administration approaches helping in recognizing IoT dangers and actualizes the best dangers alleviation rehearses that help in lessening digital assaults when utilizing IoT gadgets. There are a portion of the IoT gadgets that require programming establishment that can distinguish any infection dangers and aiding is filtering other framework weakness expanding the client security insurance.

Trust

The trust is perhaps the most methodologies that ought to be included between the client and the IoT designers while embedding the best subjective strategy of dealing with the trust between the two gatherings. The utilization of IoT ought to have a portion of the data administration arrangements that ensure and secure customers data. The gadget ought to have better security building plans that empower the client to have a superior association with the engineer for improving the security layers in their IoT frameworks. Better connection between the gatherings will upgrade even the security of the client information from any social designing control of the client private information along these lines making a powerful trust for better IoT gadgets. For one to have a trust, the information put away ought to be accessible, classified, and fundamental when required by the client while shielding their own data from the programmer interruption. Untrusted issues can emerge when the gadgets are increasingly powerless contrasted with their advantages. Also, it is prudent for both IoT gadgets engineers to prepare and teach the client on a portion of the security data to acquire trust and alleviate the dangers influencing IoT gadgets.

Also, Today’s E-Commerce companies are providing customers with real-time sales information such as the volume of products purchased in certain time period. The Authors Xitong Li and Lynn Wu in this article “Herding and Social Media Word-Of-Mouth: Evidence from Groupon” made a Hypothesis to convey that this strategy of sharing real-time sales information will potentially increase the demand in products. The Authors spoke about a couple of approaches, one is to share the sales information to the customers as mentioned above to increase the demand individually or collectively which eventually will decrease the product uncertainty and the other is to incorporate social media platforms (e.g., Facebook, Twitter) into the sales allowing customers to share and express their sentiment towards the product which will intensify the awareness of the product. Authors also discussed the effects when both strategies are applied collectively and few downsides on performing these strategies. In this article, the products are differentiated into two experience goods and search goods to understand the underlying mechanism.

Flexibility

There are a portion of the difficulties impacting the utilization of the IoT because of a more extensive surface that has vulnerabilities expanding the pace of versatility driving framework disappointments. Along these lines, versatility is a portion of the framework disappointments in this manner limiting the IoT framework execution gauges. At last, the IoT designers should search for the most ideal ways they should execute the best strategy to help information transmission without causing any issues influencing the IoT gadgets.

We took a research over 4000 online users that are participating in the IOT devices into consideration and made an analysis on how the conceptualization of the Internet privacy concerns sees the problem statement. Based on MDT and an extensive literature review and by building up the existing knowledge and information about privacy, the development of integrated conceptualized model for IPC came up with third-order general factor, two second-order factors of interaction management and information management and six first-ordered factors(Hong, James, 2013). This analysis conveys that even by conceptualizing the concerns of information security in a connected network, the generated integrated model became a baseline for the future research on regards to information security. This just proved few theoretical aspects of information privacy and security. The user information is even sold across multiple third-party merchants to make their business profited for instance, ad services like Google, Yahoo. User data is sold and resold among various ad agency services is making the privacy problem worse than what we conceive (Ram et al., 2018)

In terms of Information security in IOT devices, RFID (Radio Frequency Identification) is currently one of the most widely used device to transmit information between devices more securely. This Radio Frequency Identification technology whereby refers to digital data encoded in tags that are specific to RFID or small labels kind of things, captures information and communicate with the nearby devices through radio waves. However, a research conducted by Hartmut in 2017, says there are other alternative devices that can breach the information that is being passed through these RFID chips. Given the paucity, not only did the research observes the positive outcome of the RFID devices, but also, we found different types of content were generally viewed favorably (Hartmut et al., 2017). Moreover, the data transmitted should have less content.

CONCLUSION

Internet of Things has emerged and that connects sensors that are integrated in different electronic devices and produces real-time streaming data from humans that can be used to monitor the users and their activities. To perform these activities there should be a way of communication for these devices to transmit the data and produce coherent results or conclusions. Most of the information that is being transmitted through the internet or the data that is stored in some centralized servers is lacking the security and users privacy as the individual’s information can be viewed and transmitted to various devices in the network with out the user having visibility. This problem will keep increasing rationally up as the number of devices and the users associated to those devices in the Internet of things increases. Currently, the devices that are participating in IoT are increasing drastically and there are more IoT devices than the number of humans on planet.

The research design model, analysis and various conclusions presented in this paper corners around the possibilities, issues and concerns related to individual’s information and data in accordance with Internet of things devices. The presented emphirical analysis shows various ways of expressing the concerns related to information privacy and security with limitations to their work. From all the research done, we conclude that there are emerging technologies currently solving the issues of information privacy and security but with limitations. Moreover, as the data grows, the problems related to privacy and security are proportionally increasing. But the problem of information security and privacy when the data is persisted in a centralized location or when it is being transmitted through a network is not addressed to its full potential. Our research could help in the future analysis of securing and maintaining the privacy of individual’s information when the data is being transmitted through these IOT devices.

RESEARCH DIAGRAM

Internet of things privacy and security in a connected world with IoT devices

SECURITY GATEWAY ORCHESTRATOR

IOT DEVICES

CLIENTS AND END USER REPORTING TOOLS

INTERNET GATEWAY

M

O

D

E

L

S

Medical operators

Sensors

Multimedia devices

REFERENCES

Ahuja, M. K., & Thatcher, J. B. (2005). Moving beyond intentions and toward the theory of trying: Effects of work environment and gender on post-adoption information technology use. MIS Quarterly, 29, 427–459.

Ba, S., and Pavlou, P.A. "Evidence of the effect of trust building technology in electronic markets: price premiums and buyer behavior," MIS Quarterly (26:3), 2002, pp. 243-268.

Baronas, A.-M. K., & Louis, M. R. (1988). Restoring a sense of control during implementation: how user involvement leads to system acceptance. Mis Quarterly, 12, 111–124.

Bélanger, F., & Crossler, R. E. (2011). Privacy in the digital age: a review of information privacy research in information systems. MIS Quarterly, 35, 1017–1042

Juliana Sutanto, Elia Palme, Chuan-Hoo Tan, and Chee Wei Phang. 2013. Addressing the personalization-privacy paradox: An empirical assessment from a field experiment on smartphone users. MIS Quarterly 37, 4 (2013), 1141--1164.

Keil, M., Tan, BC., Wei, K.-K., Saarinen, T., Tuunainen, V. & Wassenaar, A. (2000). A cross-cultural study on escalation of commitment behavior in software projects. Mis Quarterly, 299–325.

Naveen Farag Awad and M. S. Krishnan. 2006. The personalization privacy paradox: An empirical evaluation of information transparency and the willingness to be profiled online for personalization. MIS Quarterly 30, 1 (March 2006), 13--28.

Pavlou, P. A., Liang, H., & Xue, Y. (2007). Understanding and mitigating uncertainty in online exchange relationships: A principal-agent perspective. MIS Quarterly, 31, 105–136

Eltayeb, M. (2017). Internet of Things. International Journal Of Hyperconnectivity And The Internet Of Things, 1(1), MIS Quarterly, 1-18. doi: 10.4018/ijhiot.2017010101

IEEE Internet of Things Journal publication information. (2015). IEEE Internet Of Things Journal, 2(5), C2-C2. MIS Quarterly doi: 10.1109/jiot.2015.2481937

Maras, M. (2015). Internet of Things: security and privacy implications. International Data Privacy Law, MIS Quarterly 5(2), 99-104. doi: 10.1093/idpl/ipv004

Wunderlich, P., Veit, D., & Sarker., S. (2019). Adoption of sustainable technologies: A mixed methods study of German households. MIS Quarterly 43(2), 673-691. DOI: 10.25300/MISQ/2019/12112

France, B., Robert, & E.C. (2011). Privacy in the digital age: A review of information privacy research in Information Systems. MIS Quarterly 35(4), 673-691. DOI: 10.25300/MISQ/2019/12112

Paul, A.P., Liang, H., & Xue, Y. (2007). Understanding and mitigating uncertainty in online

exchange relationships: A principle agent perspective. MIS Quarterly 31(1), 105-136.

DOI: 10.2307/25148783

Ram D.G., Hooman. H., Raymond A.P., Erik, R., & Dmitry, Z. (2018). How much to share with third parties? User privacy concerns and websites dilemmas. MIS Quarterly 42(1), 143-164. DOI:10.25300

Syam, M., & Sumit, S. (2016). Privacy and Big Data: Scalable approaches to sanitize large transactional databases for sharing. MIS Quarterly 40(4), 963-982.

Dong, J.L., Jae, H.A., & Youngsok, B. (2011). Managing consumer privacy concerns in

personalization: A strategic analysis of privacy protection. MIS Quarterly 35(2), 423-988.

DOI: 10.2307/23044050

Weiyin, H., & James, Y.L.T. (2013). Internet privacy concerns: An integrated conceptualization

           and four emphirical studies. MIS Quarterly 37(1), 275-298.

Tiago, M.F., Paula, F., Manuel, S., & Luis, C. (2017). Reverse engineering and security evaluation

of commercial tags for RFID based IoT applications. MIS Quarterly 17(1), 28-31, DOI:

10.3390/s17010028

Viswanath, V., John, A., Hartmut, H., & Scot, B (2017). Design and evaluation of auto ID enabled

shopping assistance artifacts in customers mobile phones: Two retail store laboratory

experiments. MIS Quarterly 41(1), 83-114. DOI:10.253000

Allen, C.J., Merrill, W., & Mikko, S. (2015). An enhanced fear appeal rhetorical framework:

Leveraging threats to the human asset through sanctioning rhetoric. MIS Quarterly 39(1),

113-107.

Janine, L.S., & Henri, B. (2010). User participation in information systems security risk

management. MIS Quarterly 34(3), 503-975. DOI:1 0.2307/25750689

Gove, N.A., & Salvatore, T.M. (2006). The effects of state-based and event-based data representation on user performance in query formulation tasks. MIS Quarterly 30(2), 269-290. DOI:10.2307/25148731

Jai, Y.S., & Sung, K. (2008). Internet user’s information privacy-protective responses: A taxonomy and a nomological model. MIS Quarterly 32(3). 503-529. DOI: 10.2307/25148854

Indrani, B., & Leung, A. (2019). Adoption of identity theft countermeasures and its short- and long-term impact on firm value. MIS Quarterly 43(1). 313-327. DOI:10.25300/MISQ/2019/14192

Stephen, S., Donald, W., Deborah, B., & Rodger, J. (2010). Circuits of power: A study of mandated compliance to an information systems security de jure standard in a government organization. MIS Quarterly 34(3). 463-486. DOI: 10.2307/25750687

Robert, W., & Merrill, W. (2013). Beyond deterrence: An expanded view of employee computer abuse. MIS Quarterly 37(1). 1-20.

Michael, R.G., & Mikhael, S. (2010). The impact of malicious agents on the enterprise software industry. MIS Quarterly 34(3). 595-910. DOI: 10.2307/25750693

Jeff, H.S., Sandra, M., & Sandra, B. (1996). Information privacy: Measuring individuals’ concerns about organizational practices. MIS Quarterly 20(2). 167-196. DOI: 1 0.2307/249477

Pei-yu, C., Gaurav, k., & Ramayya, K. (2011). Correlated failures, diversification, and information security risk management. MIS Quarterly 35(2). 397-829. DOI: 10.2307/23044049

Mary, J.C., & Cynthia, W. (2009). How ethics can enhance organizational privacy: Lessons from the choicepoint and TJX data breaches. MIS Quarterly 33(4). 673-687. DOI:10.2307/20650322

Mike, W. C., & Elizabeth, D. (2005). Taking industry seriously in information systems research. MIS Quarterly 29(4), 591-605. DOI: 10.2307/25148701

Xitong, L., & Lynn, W. (2018). Herding and social media word-of-mouth: Evidence from Groupon. MIS Quarterly 42(4), 1331-1351. DOI: 10.25300/MISQ/2018/14108

Hong, Y., Pavlou, P.A., Shi, N.A., & Wang, K.A. (2017). On the role of fairness and social distance in designing effective social referral systems. MIS Quarterly 41(3), 787-809. DOI: 10.25300/misq/2017/41.3.06

Daniel, S.L., Maruping, L.M., Cataldo, M., & Jim, H. (2018). The impact of ideology misfit on open source software communities and companies. MIS Quarterly 42(4), 1069-1096. DOI: 10.25300/MISQ/2018/14242

Gunarathne, P., Rui, H., & Seidmann, A. (2018). When social media delivers customer service: Differential customer treatment in the Airline industry. MIS Quarterly 42(2), 489-520. DOI: 10.25300/MISQ/2018/14290

Ahmed, A., Yilu, Z., Shasha, D., & Pengzhu, Z (2018), Text analytics to support sense-making in social media: A language action perspective. MIS Quarterly 42(2), 427-1038. DOI: 10.25300/MISQ/2018/13239

Kwark, Y., Chen, J., & Srinivasan, R. (2017). Platform or wholesale? A strategic tool for online retailers to benefit from third-party information. MIS Quarterly 41(3), 763-917. DOI: 1025300/MISQ/2017/14242

Rehman, H.M., Ahmed, E., Yaqoob, I., Hashem, T.I., Imran, M., & Ahmed, S. (2018). Big data analytics in industrial IoT using concentric computational model. IEEE 56(2), 37-43. DOI: 10.1109/MCOM.2018.1700632

Sidorova, A., Evangelopoulos, N., Valacich, J.s., & Ramakrishna, T (2009). Uncovering the intellectual core of the information system discipline. MIS Quarterly, 32(3), 467-920. DOI:10.2307/25148852

Swanson, E. (2019). Technology as routine capability. MIS Quarterly, 43(3), 1007-1024. DOI:10.25300/MISQ/2019/14653

2