www.oasis-open.org Privacy Management Reference Model (PMRM) A formal reference model for data privacy
Privacy Management Reference Model Increased cross-border and cross-policy domain data flows, networked information processing, federated systems and cloud computing bring significant challenges to privacy management No availability of a standards-based technical privacy framework which enable development and implementation of privacy and associated security requirements Privacy requirements frequently expressed as broad policy objectives (fair information practices and principles) are far from the requirements needed by system analysts, architects and developers 2
What is it we do? Objectives: Privacy Management Reference Model: define a set of operationally-focused privacy management Services Can serve as a reference for design and implementation of privacy controls Define a formal methodology for expressing use cases Define Use Cases utilizing PMRM Profiles of the PMRM applied to selected specific environments such as Cloud Computing, Health and SmartGrid 3
Current Status First meeting September 2010 Methodology for expressing Use Cases is ready in draft Selecting appropriate Use Cases Seek liaison relationships to test the Reference Model against use cases and privacy scenarios Coordinate as much as possible with other standards efforts Charter includes specific reference to international standards bodies such as ITU and ISO 4
Resources OASIS Technical Committee Homepage http://www.oasis-open.org/committees/pmrm/ Gershon.Janssen@gmail.com www.gershonjanssen.com 5