The main aim of this report is to identify and analyse the most relevant ethical, legal, societal and economic issues implicated by the development of big data technologies. With this purpose in mind, each distinctive perspective approaches the technological innovation brought about by big data technologies from a different angle.
[Zusammenfassung ...] Deutschland gehort zu den innovationsstarksten Landern der Welt und belegt unverandert Rang vier im Innovationsindikator - allerdings erreicht das deutsche Innovationssystem in keinem der Teilbereiche Wirtschaft, Wissenschaft, Bildung, Staat und Gesellschaft eine Topplatzierung. [...] Gemessen am Digitalisierungsindikator, der fur diese Ausgabe des Innovationsindikators erstellt wurde, liegt Deutschland deutlich hinter anderen Industrienationen zuruck (Rang 17). Das gilt besonders fur die Bereiche Forschung/Technologie (Rang 16), Bildung (Rang 17) und Infrastruktur/Staat (Rang 19).
The rise of big data promises a plethora of opportunities for a data-driven economy, including accelerated innovation and growth, and increased productivity and competitiveness. However, there are still many legal, technological, societal and economic barriers that inhibit the use and reuse of data. It’s not enough to have large volumes of data to capitalize on the benefits of big data. Data, for instance, must also be accessible, reliable and up-to-date, and there must be clarity about the provenience of data and the right business model. Companies can collect data themselves, but with respect to many use cases, it seems to be more reasonable to reuse existing data, which was collected by third-parties, at least to some extent. However, this is only happening to a very limited extent. This paper presents and discusses conditions that are prerequisites to realize the full potential of data reuse. The viability of data reuse depends on (1) compliance with legislation, (2) technical possibilities, (3) public acceptance, and (4) business cases that yield added value. Data reuse and a thriving data economy rely on these conditions. Solutions are offered to policy makers and company leaders to facilitate data reuse and to advance the data economy.
Although reports on big data success stories have been accumulating in the media, most organizations dealing with high-volume, high-velocity and high-variety information assets still face challenges. Only a thorough understanding of these challenges puts organizations into a position in which they can make an informed decision for or against big data, and, if the decision is positive, overcome the challenges smoothly. The combination of a series of interviews with leading experts from enterprises, associations and research institutions, and focused literature reviews allowed not only identifying and describing eight key challenges but also characterizing their impact, outlining potential responses to them and proposing directions for future research. The challenges faced were found to be not only technological in nature. Organizational and people-related matters as well as the legislative framework are also relevant. For large enterprises and startups specialized in big data, it is typically easier to overcome the challenges than it is for other enterprises and public administration bodies.
Allowing members of organizations to use their personally-owned computing devices as well as applications and services primarily tailored to the consumer market for work-related purposes is a phenomenon commonly referred to as `bring your own technology' or BYOT. Both allowing BYOT and engaging in IT outsourcing arrangements imply higher permeability of organizational boundaries as the IT department delegates the continuous responsibility for the provision of specific IT functions to third-party vendor organizations in the case of IT outsourcing and to IT users within the organization in the case of BYOT, respectively. While there is a considerable amount of research on determinants of successful IT outsourcing, comparatively little work has been undertaken on BYOT so far. Based on commonalities between IT outsourcing and BYOT, and building upon the existing IT outsourcing literature, this paper proposes a theoretical framework that outlines potential determinants of successful BYOT initiatives. The framework covers determinants associated with contractual governance, relationship characteristics, organizational capabilities and characteristics, member capabilities, and decision characteristics.
Allowing members of organizations to use their personally-owned computing devices as well as applications and services primarily tailored to the consumer market for work-related purposes is a phenomenon commonly referred to as 'bring your own technology' or BYOT. Both allowing BYOT and engaging in IT outsourcing arrangements imply higher permeability of organizational boundaries as the IT department delegates the continuous responsibility for the provision of specific IT functions to third-party vendor organizations in the case of IT outsourcing and to IT users within the organization in the case of BYOT, respectively. While there is a considerable amount of research on determinants of successful IT outsourcing, comparatively little work has been undertaken on BYOT so far. Based on commonalities between IT outsourcing and BYOT, and building upon the existing IT outsourcing literature, this paper proposes a theoretical framework that outlines potential determinants of successful BYOT initiatives. The framework covers determinants associated with contractual governance, relationship characteristics, organizational capabilities and characteristics, member capabilities, and decision characteristics.
Complex IT outsourcing arrangements promise numerous benefits such as increased cost predictability and reduced costs, higher flexibility and scalability upon demand. Organizations trying to realize these benefits, however, face several security and compliance challenges. In this article, we investigate the pressure to take action with respect to such challenges and discuss avenues toward promising responses. We collected perceptions on security and compliance challenges from multiple stakeholders by means of a series of interviews and an online survey, first, to analyze the current and future relevance of the challenges as well as potential adverse effects on organizational performance and, second, to discuss the nature and scope of potential responses. The survey participants confirmed the current and future relevance of the six challenges auditing clouds, managing heterogeneity of services, coordinating involved parties, managing relationships between clients and vendors, localizing and migrating data and coping with lack of security awareness. Additionally, they perceived these challenges as affecting organizational performance adversely in case they are not properly addressed. Responses in form of organizational measures were considered more promising than technical ones concerning all challenges except localizing and migrating data, for which the opposite was true. Balancing relational and contractual governance as well as employing specific client and vendor capabilities is essential for the success of IT outsourcing arrangements, yet do not seem sufficient to overcome the investigated challenges. Innovations connecting the technical perspective of utility software with the business perspective of application software relevant for security and compliance management, however, nourish the hope that the benefits associated with complex IT outsourcing arrangements can be realized in the foreseeable future whilst addressing the security and compliance challenges.
Purpose– The purpose of this paper is to shed light on the particular information needs of external auditors performing information technology (IT) audits at service providers in cross-organizational settings and to promote a software-based approach towards their satisfaction. The approach is intended to supplement the manual approaches currently adopted by auditors to procure information in such settings.Design/methodology/approach– The authors analyzed data collected by means of a series of 16 interviews and four think-aloud sessions with experienced professionals.Findings– Information procurement is perceived as tedious by auditors and largely relies on repeat interviews and perusal of documents. Given the growing complexity of cross-organizational settings, manual approaches to information procurement are reaching their limits. A considerable portion of the information required is often stored by service providers using software that is inaccessible to auditors. The authors argue that a software-based approach providing an interface for auditors to access relevant information held by such software presents an avenue worth exploring.Practical implications– The authors outline how the information stored by service providers using software can be made accessible with reasonable effort. Complementing manual approaches to information procurement with an audit interface would reduce workload and increase quality.Originality/value– The concept of an audit interface represents a novel and promising approach to meeting the information needs of auditors performing IT audits in cross-organizational settings more effectively. Both auditors and service providers would benefit from its implementation.
Seit einigen Jahren wird erwartet, dass die automatisierte Auswertung der kontinuierlich wachsenden offentlichen und privaten Datenbestande nicht nur den Markt fur Informationstechnologie (IT), sondern die Gesellschaft insgesamt hin zu einer digitalen Okonomie nachhaltig verandert. Big Data steht dabei fur Ansatze zur Analyse besonders groser, heterogener Datenmengen, wahrend Cloud Computing die bedarfsgerechte Bereitstellung von IT-Ressourcen uber ein Netzwerk beschreibt. Die Kombination dieser beiden Ansatze wird als besonders relevant angesehen, da sie auch kleinen und mittleren Unternehmen, Verwaltungen oder Nichtregierungsorganisationen Zugang zu Big-Data-Analysen eroffnen kann. Einerseits werden grose Potenziale beispielsweis in der Medizin, der Logistik und der Verkehrslenkung, der Energieproduktion oder im Katastrophenschutz gesehen, andererseits werden auch grose Herausforderungen insbesondere fur den Datenschutz thematisiert. Die Vorstudie zeigt, dass Cloud Computing zunehmend an okonomischer Bedeutung gewinnt. Hingegen befindet sich der Markt fur Big-Data-Analysen, auch aufgrund der schwierigen Abgrenzung zu schon existierenden Technologien, noch in seinen Anfangen. Der Uberblick zu den Anwendungspotenzialen in den Bedarfsfeldern der Hightech-Strategie belegt die Moglichkeiten in den Bereichen Produktivitat, Effizienz und Innovation sowie fur Wachstum und Beschaftigung. Herausforderungen werden auser im Datenschutz sowie bei den geistigen Eigentumsrechten auch bei den Geschaftsmodellen deutlich. Abschliesend werden Bereiche identifiziert, die einen Handlungs- und Forschungsbedarf aufzeigen. Hierzu gehoren Fragen der notigen Infrastrukturen, der technischen und rechtlichen Sicherheit, der Ausbildung sowie der okonomischen Wettbewerbsfahigkeit.
Service providers expected to see a simplification regarding security and compliance management as standards and best practice were applied to complex information technology (IT) outsourcing arrangements. However, security and compliance management became even more complex and is presenting greater challenges to service providers than ever before. In this article, we focus on the work practices of service providers dealing with complex and transitory security requirements and distributed IT infrastructures. Based on the results of semi-structured interviews followed by a think-aloud study, we first describe specific requirements to be met by software supporting security and compliance management in complex IT outsourcing arrangements, and discuss the extent to which existing software already meets them. We show that existing software, which is primarily designed for in-house settings, fails to meet requirements of complex IT outsourcing arrangements such as (1) the use of standardized and formal descriptions of security requirements and configurations, (2) the definition of a interface allowing to exchange messages and to delegate tasks, (3) the provision of mechanisms for designing and implementing a configuration for specific security requirements across organizational boundaries, (4) the provision of mechanisms for verifying and approving the enforcement of these security requirements, and (5) the provision of mechanisms for searching and browsing security requirements, configurations and links between them. We then propose a software architecture that claims to be capable of meeting those requirements and outline how this claim was evaluated by means of another think-aloud study in which potential end users were asked to perform a series of tasks using a prototypical implementation of the architecture. The results of the evaluation confirm that the software meets the described requirements and suggests that it facilitates the management of security and compliance in complex IT outsourcing arrangements.
Cloud Computing and Social Network Services (SNS) are some of the most controversially discussed IT developments in recent years. Huge expectations exist for Cloud Computing, providing lower costs of computing while increasing employment. However, Cloud Computing as well as Social Network Services may come with a substantial risk of losing data privacy. The project conducted on Cloud Computing Services and Social Network Sites addressed the potential and impacts of these technologies. The project report showed that (1) adequate data security and privacy are critical but difficult to achieve, that (2) more consumer protection is needed and that (3) the market for Cloud Computing is not growing as fast as initially forecast, resulting in a lower than expected increase of employment and lower contribution to GDP growth. The study was carried out between 2012 and 2013 on behalf of the European Parliament’s Science and Technology Options Assessment Panel (STOA) by the Danish Board of Technology (DBT), the Fraunhofer Institute for Systems and Innovation Research (ISI), the Institute of Technology Assessment of the Austrian Academy of Sciences (ITA), the Irish Centre for Cloud Computing and Commerce at Dublin City University (DCU/IC4), and ITAS. In this article, we highlight findings from interviews, literature reviews, and case studies. In addition, selected contributions from a project workshop under the auspices of the 5th European Innovation Summit are presented, conclusions drawn, and finally key policy options presented.
A context of use analysis is an important step in every software engineering project. Comprising the identification of the key system users as well as an analysis of the system environment and the activities supported, this engineering step is crucial for the successful development of information systems. Clarity with respect to the users’ demand for system support and their participation in the activities supported by the system is considered particularly important for systems which are critical for organizational continuity and which are used across organizational boundaries. Systems supporting policy and security configuration management in networks of IT service providers, their customers and auditors meet both of these criteria. Within the scope of this article, the context of use of such a system supporting policy and security configuration management is investigated by means of a user-oriented approach. The focus lies on a specific setting being investigated within the scope of an on-going research project. The investigation which was based on a series of qualitative interviews as well as desk research resulted in a comprehensive description of the participation of a set of key system users in activities related to policy and security configuration management as well as their demand for system support. Also the key users and the activities to be supported are discussed within the scope of this article.
The challenges of managing security have increased substantially with the advent of outsourcing and cloud computing. Service providers need to ensure that security controls correctly address the complex sets of requirements demanded by their clients. Auditors find it difficult to check whether service providers are compliant with standard security guidelines as well as organization-specific security requirements. This paper reports research-in-progress of a design science project that addresses security management in cross-organizational settings. Based on a sequence of empirical studies involving interviews and an online survey, we analyze critical activities associated with security management in cross-organizational settings from the perspective of service providers and auditors and discuss the support provided by software. The paper also lays out our plans for developing design artifacts and the theoretical framework for their evaluation.
The threat of information security (IS) breaches is omnipresent. Large organizations such as Sony or Lockheed Martin were recently attacked and lost confidential customer information. Besides targeted attacks, virus and malware infections, lost or stolen laptops and mobile devices, or the abuse of the organizational IT through employees, to name but a few, also put the security of assets in jeopardy. To defend against IS threats, organizations invest in IS countermeasures preventing, or, at least, reducing the probability and the impact of IS breaches. As IS budgets are constrained and the number of assets to be protected is large, IS investments need to be deliberately evaluated. Several approaches for the evaluation of IS investments are presented in the literature. In this chapter, we identify, compare, and evaluate such approaches using the example of a policy and security configuration management tool. Such a tool is expected to reduce the costs of organizational policy and security configuration management and to increase the trustworthiness of organizations. It was found that none of the analyzed approaches can be used without reservation for the assessment of the economic viability of the policy and security configuration management tool used as an example. We see, however, considerable potential for new approaches combining different elements of existing approaches.
Many organizations hoping for cost savings and higher flexibility consider consuming services from service providers or combining such services with services offered organization-internally. Organizations, however, often renounce from the expected advantages due to security and compliance concerns. The key challenges leading to these security and compliance concerns in cross-organizational settings have not yet been discussed elaborately in scholarly literature. However, a thorough understanding of the underlying challenges is necessary in order to find ways to compensate them and, in consequence, tap into the full potential of the cloud computing model. This paper discusses challenges gathered by means of guideline-based interviews. The identified challenges comprise managing heterogeneity, auditing clouds, coordinating the parties involved in cross-organizational settings, managing their relationships, coping with the lack of security awareness, and localizing and migrating data. Potential research avenues are discussed for each challenge.
The ever greater reliance on complex information technology environments together with dynamically changing threat scenarios and increasing compliance requirements make an efficient and effective management of information security controls a key concern for most organizations. Good practice collections such as COBIT and ITIL as well as related standards such as the ones belonging to the ISO/IEC 27000 family provide useful starting points for control management. However, neither good practice collections and standards nor scholarly literature explain how the management of controls actually is performed in organizations or how the current state-of-practice can be improved. A series of interviews with information security professionals from European organizations was conducted in order to better understand how a coherent and comprehensive suite of controls is built and maintained in practice and to help organizations refine related work practices. The interviews focused on the activities of control management as well as on the roles and responsibilities of the individuals and groups involved in those activities. The results of a qualitative content analysis of the gathered data allowed an aggregate description of control management on the basis of a generic control management cycle ranging from the creation of a control design to its implementation and review.
Measuring IT security management performance is different and usually more difficult than other kinds of measurement. Quantifying IT security in general is difficult, additionally IT infrastructures differ strongly from each other, consist of heterogeneous components and change permanently. However, IT security needs the attention not only from specialized IT security staff, but also from general management. The critical point thus is the development of a set of suitable key performance indicators. This paper describes the creation of a set of performance indicators to be used in cross-organizational security settings on the basis of two qualitative empirical studies. Indicators were developed for organizations acting either as service providers or as service consumers.
Knowledge work is weakly structured, highly diverse and fast changing and thus needs flexible, personalised support by software. Situational applications are a new breed of software that is assumed to fit to the types of tasks and contextual requirements encountered in knowledge work settings. Furthermore, their application is supposed to result in shorter time-to-proficiency. The main goal of this paper is to discuss these assumptions taking the constructs of the task-technology fit model as well as the relationships among them into account. Based on the model, three propositions are developed and discussed.
Dieter A. Fensel合作论文数Department of Computer Science, University of Innsbruck1