Applicability analysis: elicitation of privacy risks through STPA(-Priv) in a selected IoT-scenario

dc.contributor.authorRiedel, Frederik
dc.date.accessioned2017-10-24T14:51:37Z
dc.date.available2017-10-24T14:51:37Z
dc.date.issued2017de
dc.description.abstractContext This bachelor’s thesis discusses the usage of System-Theoretic Process Analysis (STPA) for privacy engineering. STPA has been developed for safety engineering originally. I show how this methodology can be applied to privacy risk analysis by using the extension STPA-Priv. I explain why privacy is important and why privacy risk analysis can help improve systems regarding privacy. Objective The goal is to apply the privacy extension of STPA to a real-world Internet of Things scenario to determine the applicability and possible problems with this methodology. Method STPA considers safety a system property. I think that privacy is a system property as well and therefore STPA can be applied to privacy risk analysis. Most changes from STPA to STPA-Priv have been made in its terminology, the process itself remains the same. This brings many of the advantages of systems theory to the field of privacy engineering, such as the top-down nature of STPA that helps handle complex socio-technical systems. Results I found out that STPA-Priv is a good approach to elicit privacy risks and requirements. I was able to elicit many privacy risks from our scenario using STPA-Priv which shows that the methodology works in general. Conclusions After all, I can recommend using STPA-Priv to evaluate projects for privacy risks. Nevertheless, there are still changes and improvements necessary. However, the overall methodology would not be affected by those changes. STPA-Priv is very straight-forward for people that are already familiar with STPA.en
dc.identifier.other496065785
dc.identifier.urihttp://nbn-resolving.de/urn:nbn:de:bsz:93-opus-ds-93156de
dc.identifier.urihttp://elib.uni-stuttgart.de/handle/11682/9315
dc.identifier.urihttp://dx.doi.org/10.18419/opus-9298
dc.language.isoende
dc.rightsinfo:eu-repo/semantics/openAccessde
dc.subject.ddc004de
dc.titleApplicability analysis: elicitation of privacy risks through STPA(-Priv) in a selected IoT-scenarioen
dc.typebachelorThesisde
ubs.fakultaetInformatik, Elektrotechnik und Informationstechnikde
ubs.institutInstitut für Softwaretechnologiede
ubs.publikation.seiten81de
ubs.publikation.typAbschlussarbeit (Bachelor)de

Files

Original bundle

Now showing 1 - 1 of 1
Thumbnail Image
Name:
Bachelorarbeit.pdf
Size:
7.53 MB
Format:
Adobe Portable Document Format
Description:

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
3.39 KB
Format:
Item-specific license agreed upon to submission
Description: