论文标题

野外隐私工程:了解从业者的心态,组织方面和当前实践

Privacy Engineering in the Wild: Understanding the Practitioners' Mindset, Organisational Aspects, and Current Practices

论文作者

Iwaya, Leonardo Horn, Babar, Muhammad Ali, Rashid, Awais

论文摘要

隐私工程作为新兴领域的研究和实践领域,包括在工作系统中实施,部署和操作隐私功能和控制所需的技术功能和管理流程。为此,软件实践者和软件公司的其他利益相关者需要合作地建立保护隐私的业务和工程解决方案。已经进行了重大研究,以了解软件从业人员对信息隐私的看法,但是应该更加重视混凝土隐私工程组件的吸收。这项研究深入研究了软件从业者的观点和思维方式,组织方面以及有关隐私及其工程过程的当前实践。采访了来自九个国家和背景的30名从业者,分享了他们的经验,并就广泛的隐私主题发表了意见。采用主题分析方法来定性地对访谈数据进行编码,并构建一个富裕而细微的主题框架。结果,我们确定了三个关键的互连主题,这些主题构成了“野外”的隐私工程框架:(1)个人隐私心态和立场,分为从业者的隐私知识,态度和行为; (2)组织隐私方面,例如决策能力以及隐私气候的积极和负面例子; (3)隐私工程实践,例如在行业中使用的程序和控制。在主要发现中,这项研究提供了有关隐私工程实践实践的许多见解,这表明隐私法(例如欧盟一般数据保护法规)对从业者的行为和组织文化产生了积极影响。组织隐私文化和气候等方面也得到了证实[...]。

Privacy engineering, as an emerging field of research and practice, comprises the technical capabilities and management processes needed to implement, deploy, and operate privacy features and controls in working systems. For that, software practitioners and other stakeholders in software companies need to work cooperatively toward building privacy-preserving businesses and engineering solutions. Significant research has been done to understand the software practitioners' perceptions of information privacy, but more emphasis should be given to the uptake of concrete privacy engineering components. This research delves into the software practitioners' perspectives and mindset, organisational aspects, and current practices on privacy and its engineering processes. A total of 30 practitioners from nine countries and backgrounds were interviewed, sharing their experiences and voicing their opinions on a broad range of privacy topics. The thematic analysis methodology was adopted to code the interview data qualitatively and construct a rich and nuanced thematic framework. As a result, we identified three critical interconnected themes that compose our thematic framework for privacy engineering "in the wild": (1) personal privacy mindset and stance, categorised into practitioners' privacy knowledge, attitudes and behaviours; (2) organisational privacy aspects, such as decision-power and positive and negative examples of privacy climate; and, (3) privacy engineering practices, such as procedures and controls concretely used in the industry. Among the main findings, this study provides many insights about the state-of-the-practice of privacy engineering, pointing to a positive influence of privacy laws (e.g., EU General Data Protection Regulation) on practitioners' behaviours and organisations' cultures. Aspects such as organisational privacy culture and climate were also confirmed to have [...].

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源