Towards GDPR-compliant data processing in modern SIEM systems

Menges, Florian and Latzo, Tobias and Vielberth, Manfred and Sobola, Sabine and Poehls, Henrich C. and Taubmann, Benjamin and Koestler, Johannes and Puchta, Alexander and Freiling, Felix and Reiser, Hans P. and Pernul, Guenther (2021) Towards GDPR-compliant data processing in modern SIEM systems. COMPUTERS & SECURITY, 103: 102165. ISSN 0167-4048, 1872-6208

Full text not available from this repository. (Request a copy)

Abstract

The introduction of the General Data Protection Regulation (GDPR) in Europe raises a whole series of issues and implications on the handling of corporate data. We consider the case of security-relevant data analyses in companies, such as those carried out by Security Information and Event Management (SIEM) systems. It is often argued that the processing of personal data is necessary to achieve service quality. However, at present existing systems arguably are in conflict with the GDPR since they often process personal data without taking data protection principles into account. In this work, we first examine the GDPR regarding the resulting requirements for SIEM systems. On this basis, we propose a SIEM architecture that meets the privacy requirements of the GDPR and show the effects of pseudonymization on the detectability of incidents. (c) 2020 Elsevier Ltd. All rights reserved.

Item Type: Article
Uncontrolled Keywords: Security information and event; management; SIEM; GDPR; Threat intelligence; DINGfest
Subjects: 300 Social sciences > 330 Economics
Divisions: Business, Economics and Information Systems > Institut für Wirtschaftsinformatik > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Informatics and Data Science > Lehrstuhl für Wirtschaftsinformatik I - Informationssysteme (Prof. Dr. Günther Pernul)
Depositing User: Dr. Gernot Deinzer
Date Deposited: 10 Aug 2022 09:47
Last Modified: 10 Aug 2022 09:47
URI: https://pred.uni-regensburg.de/id/eprint/46322

Actions (login required)

View Item View Item