Sharing Cyber Threat Intelligence under the General Data Protection Regulation

dc.cclicenceN/Aen
dc.contributor.authorAlbakri, Adham
dc.contributor.authorBoiten, Eerke Albert
dc.contributor.authorDe Lemos, Rogerio
dc.date.acceptance2019-03-04
dc.date.accessioned2019-07-03T13:38:48Z
dc.date.available2019-07-03T13:38:48Z
dc.date.issued2019-06-13
dc.description.abstractSharing Cyber Threat Intelligence (CTI) is a key strategy for improving cyber defense, but there are risks of breaching regulations and laws regarding privacy. With regulations such as the General Data Protection Regulation (GDPR) that are designed to protect citizens’ data privacy, the managers of CTI datasets need clear guidance on how and when it is legal to share such information. This paper defines the impact that GDPR legal aspects may have on the sharing of CTI. In addition, we define adequate protection levels for sharing CTI to ensure compliance with the GDPR. We also present a model for evaluating the legal requirements for supporting decision making when sharing CTI, which also includes advice on the required protection level. Finally, we evaluate our model using use cases of sharing CTI datasets between entities.en
dc.funderEuropean Union (EU) Horizon 2020en
dc.identifier.citationAlbakri, A., Boiten, E., De Lemos, R. (2019) Sharing Cyber Threat Intelligence Under the General Data Protection Regulation. In: Naldi, M., Italian,o G., Rannenberg, K., Medina, M., Bourka, A. (Eds.) APF2019: Privacy Technologies and Policy, pp.28-41.en
dc.identifier.isbn9783030217518
dc.identifier.urihttps://www.dora.dmu.ac.uk/handle/2086/18173
dc.language.isoenen
dc.peerreviewedYesen
dc.projectid675320en
dc.publisherSpringeren
dc.relation.ispartofseriesPart of the Lecture Notes in Computer Science book series (LNCS, volume 11498);
dc.researchinstituteCyber Technology Institute (CTI)en
dc.subjectCyber Threat Intelligenceen
dc.subjectInformation sharingen
dc.subjectGeneral Data Protection Regulationen
dc.subjectGDPRen
dc.subjectLegal evaluationen
dc.titleSharing Cyber Threat Intelligence under the General Data Protection Regulationen
dc.typeConferenceen

Files

Original bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
APF_2019_paper_25.pdf
Size:
659.41 KB
Format:
Adobe Portable Document Format
Description:
Preprint
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
4.2 KB
Format:
Item-specific license agreed upon to submission
Description: