Cloud Native Privacy Engineering through DevPrivOps
arXiv:2108.00927 · doi:10.1007/978-3-030-99100-5_10
Abstract
Cloud native information systems engineering enables scalable and resilient service infrastructures for all major online offerings. These are built following agile development practices. At the same time, a growing demand for privacy-friendly services is articulated by societal norms and policy through effective legislative frameworks. In this paper, we identify the conceptual dimensions of cloud native privacy engineering and propose an integrative approach to be addressed in practice to overcome the shortcomings of existing privacy enhancing technologies. Furthermore, we propose a reference software development lifecycle called DevPrivOps to enhance established agile development methods with respect to privacy. Altogether, we show that cloud native privacy engineering advances the state of the art of privacy by design and by default using latest technologies.
preprint version (2021-12-01), accepted for the Post-Proceedings at the 16th IFIP Summer School on Privacy and Identity Management 2021
References in corpus (5)
- Engineering Privacy by Design: Are engineers ready to live up to the challenge?
- TILT: A GDPR-Aligned Transparency Information Language and Toolkit for Practical Privacy Engineering
- Privacy Engineering Meets Software Engineering. On the Challenges of Engineering Privacy ByDesign
- Configurable Per-Query Data Minimization for Privacy-Compliant Web APIs
- RedCASTLE: Practically Applicable -Anonymity for IoT Streaming Data at the Edge in Node-RED