
In this article, the author focuses on four key issues that are expected to impact the future of privacy and security. These have been labeled — the Four Horsemen, for obvious reasons. In our assessment, these topics or “horsemen” have the potential to change the fundamental tenets of our society. They impact our banking system, medical breakthroughs, use of the internet and web-enabled devices and services. Together, these topics touch the entire range of technical, regulatory, social, legal, and commercial issues. The Four Horsemen are Net Neutrality (and U.S. Internet Privacy Laws), Internet of Things (IoT), Human Genome (Medical), and Cryptocurrency.
The Internet of Things (IoT) is a loosely defined term describing internet-connected sensors that among other capabilities enable companies to monitor individuals. New privacy-related challenges can arise when sensors communicate with each other. These challenges call for changes to corporate privacy policies to incorporate potential IoT issues and guidance. This research investigates existing privacy policies and IoT-related research to provide IoT privacy policy recommendations. Privacy policy questions include: Who or what is notified of monitoring? When and where should there be expectations of privacy? Why and how is user data collected and how should monitoring problems be communicated? The analysis concludes with IoT-related privacy policy recommendations.
Health-related data include not only the patient’s personal information, but also specific information about the patient health problems, supplementary diagnostic examination results, and much more. All this information is extremely sensitive and should only be accessed by the proper entities and actors, for special specific purposes. Described herein is an approach to address security and privacy of health-related data based on rights management technologies, with an architecture to minimize security risks and privacy conerns. This approach consists of the reutilisation of an open-source and open-specifications rights management system, and designing and adapting the necessary components to address the specific security and privacy requirements that must be faced when managing health and patient data.
Security and Privacy in Social Networks is an edited collection of an introduction and 10 scholarly articles, which are partially based on the research work presented at the Workshop on Security and Privacy in Social Networks, in connection with the 2012 IEEE Social Computing Conference. Given the growing prominence of online social networks (OSN) and their corresponding security and privacy problems, this book aims to propose solutions as well as develop a common language for use between researchers and practitioners. The authors organized the book into 11 chapters, dedicating the first chapter to introduction and the remaining 10 to research articles. In the upcoming paragraphs, I will provide a review of the key ideas discussed in each chapter and then conclude my review.
This study examines the privacy practices of organizations. We argue that successful deployment of privacy practices based on ethical actions will strengthen privacy protection measures to better protect clients’ PII. We propose a set of ethical actions based on six normative theories following multiple case study approach to study three prominent data breaches. Our analysis indicates that ethical actions based on normative theories can be effective in developing better privacy practices for organizations. The theory that has the strongest effect on privacy practices is the deontological approach, while the liberal-intuitive has the weakest effect on privacy practices.
ABSTRACT Government agencies, researchers, healthcare providers, and other organizations release data for public use. To protect the privacy of the data subjects, these organizations mask the data prior to release. One popular masking procedure is data swapping, by which values of records are exchanged before being released. Data swapping is one of the preferred techniques since it is simple, easy to implement, and---based on prior studies---provides a reasonable balance between disclosure risk and data utility. In this study, we investigate the ability of an adversary with limited knowledge (of just a single record) to re-identify a record in the swapped data by using a procedure that reverse engineers the data-swapping process. The study also provides the adversary with the ability to evaluate the effectiveness of the re-identification. We empirically evaluate the effectiveness of data swapping using a dataset that has been used previously to evaluate the effectiveness of masking techniques. Our results demonstrate that data swapping can be vulnerable to disclosure even against this limited knowledge adversary.
First of all, I’m glad to be back on board and allow Dr. Bagchi to take a good break for a while. It is nice to be in touch with everyone again. The second issue of the Journal of Information Privacy & Security (JIPS) for 2017 contains three articles, one expert opinion, and one book review. The first two articles focus on the importance of protecting personal information and securing data in the healthcare industries. The third article discusses the influence of consumers’ security perception on their social advertising usage. In the Expert Opinion section, Mr. Lionel Cassin, an information security officer at Texas A&M University–Corpus Christi, discusses the major issues of security and privacy that the university is facing, and points out that it is crucial to improve awareness of information security and privacy on campus. In the Book Review section, Dr. Arslan reviews the book titled Security and Privacy in Social Networks by Yaniv Altshuler, Yuval Elovici, Armin B. Cremers, Nadav Aharony, and Alex Pentland. More details are as follows: The first article is titled “Handling Confidentiality and Privacy on Cloud-based Health Information Systems.” The authors Carlos Serrao and Elsa Cardoso propose an approach to minimize the security risks in health-related data based on rights management technologies. Based on a trend that the health-related data may be migrated into the cloud, opportunities are increasing for cybercriminals to commit fraud or other similar criminal schemes after directing their attacks towards health and medical data of patients. To prevent organizations from financial and reputational losses, several initiatives have been created to improve the confidentiality and privacy requirements of the health and medical information. In this article, the authors propose the usage of the rights management systems as this approach can offer a governed environment and enables critical privacy and security mechanism. Although the system will not solve all the problems, it can help reducing the impact of large data breaches, making it more difficult for potential attacker to access unprotected information. The second article, “The Effect of Procedural and Technological Security Countermeasures on the Propensity to Misuse Medical Data,” authored by Wachiraporn Arunothong and Derek L. Nazareth, discusses the healthcare providers’ concern about the threat to misuse of medical data by internal users such as their employees. Even though the use of electronic medical records (EMRs) and electronic health records (EHRs) can help increase the efficiency and effectiveness of healthcare services, it is crucial to cultivate the awareness of security and to ensure that the employees follow the policy measures to avoid misuse. The results from conducting an online survey with physicians, nurses, medical students, and nursing students revealed that the healthcare providers who have more conscious of institutional security policy were less likely to engage in misuse. It is thus necessary for healthcare organizations to provide some training, such as robust training, coupled with periodic refresher training to educate their employees about the importance of HIPAA compliance and to inform them about the steps that the institution takes to maintain compliance, both from a procedural as well as technological standpoint. The study concluded that increasing the awareness of security and policy measures among employees is a vital part of preventing misuse. The last article in this issue titled “What Affects Users to Click on Display Ads on Social Media? The Roles of Message Values, Involvement, and Security” is authored by En Mao and Jing Zhang. These authors examined the three major communication components—message, channel/media, and receiver/audience—on advertising clicks, which impact the effectiveness of social media advertising. They then proposed a research model and tested it with online-survey data from 572 social JOURNAL OF INFORMATION PRIVACY AND SECURITY 2017, VOL. 13, NO. 2, 49–50 https://doi.org/10.1080/15536548.2017.1322413
"Thinking with Data: How to Turn Information into Insights, by Max Shron." Journal of Information Privacy and Security, 13(1), pp. 46–47
This is the third issue of 2017. I am glad to see that the journal continues to grow and we have begun to see articles submitted from many countries of the world as well as a variety of topics. The current issue includes a wide spectrum of articles. The main focus lies on the issues of protecting consumers’ privacy as well as strengthening the security by using a stronger password. The first article titled “Detecting and Preventing Inference Attacks in Online Social Networks: A DataDriven and Holistic Framework” by Xiaoyun He and Haibing Lu proposed a framework to alleviate the rule-based inference problem by detecting and breaking the inferences that are represented as rules of attributes and/or attribute values. The authors believed that the proposed framework should enable individual users to check their online profiles for satisfaction of their privacy preferences and allow them tomodify profiles to prevent the disclosure of private information. In this article, the authors also proposed a novel method to minimize the modifications to user profiles in order to prevent inference attacks while preserving the utility. In the second article titled “Invasion of Privacy by Smart Meters: An Analysis of Consumer Concerns,” the authors ZiyueHuang andPrashant Palvia developed an instrument tomeasure the consumers’ concerns for information privacy (CFIP) in adopting smart meters. They then proposed a conceptual model to examine the relationship between privacy concerns, trusting beliefs, risk beliefs, and intention to adopt smart meters. Based on the data collected from 217 survey respondents, the study findings revealed that consumers’ information privacy concerns about adopting smart meters can be measured by three dimensions: collection, secondary use, and improper access. In addition, the effect of information privacy concerns on behavioral intention is fully mediated by risk beliefs. The result also suggested that among the control variables, education has a positive effect on intention, while privacy experience has a negative effect. The third article titled “Valuing Information Security: A Look at the Influence of User Engagement on Information Security Strength” by Randall J. Boyle, Chandrashekar D. Challa, and Jeffrey A. Clements focused on the influence of user engagement on users’ information security practices. The study took a closer look at the passwords people are using. The authors pointed out that password strength is affected by some factors, such as the length of the password, the types of characters people used, the number of duplicate passwords, and the number of uncrackable passwords. The main focus of this study is to understand why some people choose better passwords than others. The findings generally support the view that higher levels of engagement are associated with stronger passwords. In the Book Review section, FarukArslan reviews the book titledWeapons ofMathDestruction: HowBig Data Increases Inequality and Threatens Democracy by Cathy O’Neil. The book consists of 10 chapters discussing the deficiencies of data sciences applications. Overall, Dr. Arslan finds the book to be an intriguing and well-written and the book containsmany real-life examples for researchers and practitioners alike. In his opinion, this book shall be incorporated in the curriculum of any serious academic program focusing on data science.
ABSTRACT This report assesses the impact disclosure of data breaches has on the total returns and volatility of the affected companies’ stock, with a focus on the results relative to the performance of the firms’ peer industries, as represented through selected indices rather than the market as a whole. financial performance is considered over a range of dates from 3 days post-breach through 6 months post-breach, in order to provide a longer-term perspective on the impact of the breach announcement.
ABSTRACT As healthcare providers seek to comply with HIPAA and endeavor to secure their data from external breaches, they also need to realize that another threat to misuse of this data is inappropriate internal use by employees. Not all instances of misuse constitute a HIPAA violation, but they have the potential to become one. Medical data misuse by employees can be alleviated and curbed through the appropriate use of procedural and technological countermeasures. This paper seeks to determine whether electronic health records (EHR) policy and auditing procedures play a role in the propensity of providers to misuse medical data. Through an on-line survey of US physicians, nurses, medical students, and nursing students, using four case vignettes representing various forms of misuse, this research found that providers who were more aware of institutional security policy were more likely to adhere to policies than their counterparts who were not similarly informed. Likewise, providers who believed that their organizations monitored their EHR usage were less likely to engage in misuse than their counterparts who believed they were not monitored. The findings underscore the need for healthcare organizations to emphasize the importance of HIPAA compliance, and inform employees about the steps that the institution takes to maintain compliance, both from a procedural as well as technological standpoint. This study suggests that increasing the awareness of security and policy measures among employees is a vital part of preventing misuse.
ABSTRACTEmployees’ non-compliance with organizational information security policies poses a significant threat to organizations. Enhancing our understanding of compliance behavior is crucial for improving security. Although research has identified numerous psychological factors that affect intentions to comply with security policies, how such intentions map onto actual compliance behavior is not well understood. Building on a well-supported model of security policy compliance intentions, we evaluate compliance with each of six types of information security policies using decision vignettes, and compare parameters across models. The study contributes to information security compliance research by examining each risk separately and exploring heterogeneity across risk types.
JIPS:Could you please briefly tell me your responsibilities and role as an Information Security Officer at Texas A&M University-Corpus Christi? LC:Some of my duties are defined by Texas state law. ...
As I was writing this book review, the announcement about Equifax’s data breach, which affected about 143 million people, was dominating the daily discussions within United States. Following this m...
We present a Rapid, Serial, Visual Presentation method (RSVP) for recognition-based graphical authentication. It presents a stream of rapid, degraded images, which makes the object recognition process difficult for casual attackers. Three studies investigated success rates for authenticating, RSVP’s resistance to over-the-shoulder attacks (OSAs), approaches for facilitating learnability, and effects of resetting a passcode. We found that participants could successfully authenticate and could not complete OSAs. Learnability was promoted by the presentation of degraded versions of the images during the memorization phase. When a passcode was reset, participants successfully retrained themselves even when the previous passcode was recycled as distractors.
Data science has become one of the prominent topics both in academia and in industry in the recent years. With the growing capability of big data technologies coupled with many extant quantitative ...
Growing use of the data generated via online social networking sites (SNS) for big data analytics renders the topic of information privacy as a critical concern and calls for a deeper investigation of individuals’ information privacy beliefs and behaviors. The primary goal of our research is to empirically test the effectiveness of the Miltgen and Peyrat-Guillard model in explaining the information privacy behavior of social network site users using a large-N sample from the European Union (EU). Results from the factor-based partial least squares - structural equation modeling (PLS-SEM) analysis provide partial support to this model. We elaborate on enhancements and discuss possible extensions to the model.
Today, more than ever, companies collect their customers’ Personally Identifiable Information (PII) over the Internet. The alarming rate of PII misuse drives the need for improving companies’ privacy practices. We thoroughly study privacy policies of 600 companies (10% of all listings on NYSE, Nasdaq, and AMEX stock markets) across industries and investigate 10 different privacy pertinent factors in them. The study reveals interesting trends: for example, more than 30% of the companies still lack privacy policies, and the rest tend to collect users’ information but claim to use it only for the intended purpose. Furthermore, almost one out of every two companies provides the collected information to law enforcement without asking for a warrant or subpoena. We found that the majority of the companies do not collect children’s PII, one out of every three companies lets users correct their PII but does not allow complete deletion, and the majority post new policies online and expect the user to check the privacy policy frequently. The findings of this study can help companies improve their privacy policies, enable lawmakers to create better regulations and evaluate their effectiveness, and finally educate users with respect to the current state of privacy practices in an industry.
Digital space continues to be a popular venue for meeting new people. However, little is known about who uses mobile context-aware social networking apps to initiate new relationships. This study investigates the roles of individual core traits and surface characteristics in the adoption of social discovery features on WeChat, a mobile social networking app in China. Analysis of survey data collected from 213 WeChat users finds the core traits of agreeableness and neuroticism to be negatively related to the use of these social discovery features. The surface characteristic of sensation seeking is positively related to the use of social discovery features, while the surface characteristic of loneliness is not. Based on the findings, directions for future research and implications for app developers and marketers are suggested.
While smart meters offer an innovative way to solve energy problems, they have also brought concerns regarding consumer privacy. In this study, we develop an instrument to measure the consumers' concerns for information privacy (CFIP) in adopting smart meters, and propose a conceptual model to examine the relationship between privacy concerns, trusting beliefs, risk beliefs, and intention to adopt smart meters. Using both focus group study and survey methods, we show that CFIP can be measured by three dimensions: collection, secondary use, and improper access, and that the effect of CFIP on behavioral intention is fully mediated by risk beliefs.