Aware Home
by Jacob Slonim
Friday, April 20, 2007, 14:00pm - Thursday, April 19, 2007, 15:25pm
325b ITE
This research describes a framework and methodology for managing the privacy policy of an enterprise, including creation (based on factors like privacy legislation and consumer preferences), validation and verification, deployment and enforcement, and compliance testing for business processes and software. To validate the framework, one module (compliance testing) is implemented for an existing prominent electronic commerce software application. Our unique approach monitors the personal information sent and received by the software application and converts it to a standardized representation. At defined points in the electronic commerce work flow, the transmissions are compared to a set of privacy rules to ascertain compliance. Non-compliant transmissions of personal information are labeled privacy infractions and are addressed by stopping the work flow or by generating a report and alerting the administrator.