|
Abstract: . . . http://aspe.hhs.gov/datacncl/eudirect.htm [8] Industry Canada, Privacy and the Information Highway, Regulatory Options for Canada, chapter 6, retrieved Sept. 5, 2003 from: http://strategis.ic.gc.ca/SSG/ca00257e.html#6 [9] S. Kenny and L. Korba, Adapting Digital Rights Management to Privacy Rights Management, Computers & Security, Vol. 21, No. 7, November 2002, 648-664. [10] D.K.W. Chiu et al, A Three-Layer Architecture for E-Contract Enforcement in an E-Service Envronment, Proceedings of the 36 th Hawaii International . . . . . . 2003. [13] I. Kao and R. Chow, Enforcing Complex Security Policies for Commercial Applications, Proceedings of the Nineteenth Annual International Computer Software and Applications Conference, 1995. [14] J. Burns et al, Automatic Management of Network Security Policy, Proceedings of the DARPA Information Survivability Conference & Exposition II (DISCEX '01), Volume 2, 2001. [15] W3C, A P3P Preference Exchange Language 1.0 (APPEL 1.0), retrieved April 22, 2004 at: http://www.w3.org/TR/P3P-preferences/ 1 . . . . . . privacy policies since privacy is more personal and people are more inclined to verify compliance personally. 4 Conclusions and Future Work We began by examining representative privacy legislation to derive requirements for privacy policy compliance systems. This ensured that the resulting requirements are core to any PPCS. We then presented an architecture that satisfies the requirements and discussed its strengths and weaknesses. Web services can only succeed if consumers are confident that their . . . . . . Enforcing Complex Security Policies for Commercial Applications, Proceedings of the Nineteenth Annual International Computer Software and Applications Conference, 1995. [14] J. Burns et al, Automatic Management of Network Security Policy, Proceedings of the DARPA Information Survivability Conference & Exposition II (DISCEX '01), Volume 2, 2001. [15] W3C, A P3P Preference Exchange Language 1.0 (APPEL 1.0), retrieved April 22, 2004 at: http://www.w3.org/TR/P3P-preferences/ 1 NRC Paper Number: NRC 46566 . . . . . . Conference, Philadelphia, Pennsylvania, May 18-21, 2003. [3] G. Yee, L. Korba, Semi-Automated Derivation of Personal Privacy Policies, Proceedings, 15th IRMA International Conference, New Orleans, Louisiana, May 23- 26, 2004. [4] M. ONeill et al, Web Services Security, McGraw-Hill/Osborne, 2003. [5] Department of Justice, Privacy Provisions Highlights, http://canada.justice.gc.ca/en/news/nr/1998/attb ack2.html [6] Canadian Standards Association, Model Code for the Protection of Personal Information, . . . --3000,5,300,3387,35425
|