MétaCan
Menu
Retour à la cohorte
Enregistrement W267594391

GAPP Targets Privacy Risks: Principles Provide a Comprehensive, Scalable Framework for Managing Compliance and Reputation Threats

2011· article· en· W267594391 sur OpenAlexaboutno aff
Dan Schroeder, Nancy A. Cohen

Notice bibliographique

RevueJournal of accountancy online/Journal of accountancy · 2011
Typearticle
Langueen
DomaineSocial Sciences
ThématiquePrivacy, Security, and Data Protection
Établissements canadiensnon disponible
Organismes subventionnairesnon disponible
Mots-clésBusinessHealth Insurance Portability and Accountability ActInformation privacyPrivacy lawPersonally identifiable informationLegislationPrivacy policyEnforcementData Protection Act 1998Internet privacyPrivacy by DesignComputer securityConfidentialityLawComputer sciencePolitical science
DOInon disponible

Résumé

récupéré en direct d'OpenAlex

EXECUTIVE SUMMARY * State, federal and foreign governments are expanding privacy compliance regulations. * Businesses need to regularly assess privacy risks and deploy effective controls. Good security practices do not by themselves represent effective privacy risk management. * Businesses should prepare flowcharts and have other documentation that show how and when they capture personal information; how it is processed, stored and distributed; and who can access it at any time. * Generally Accepted Privacy Principles (GAPP) provide a comprehensive and scalable approach to managing privacy risks. * Practitioners can leverage GAPP to provide advisory and attestation services. ********** [ILLUSTRATION OMITTED] As of early 2011, 46 states had enacted some form of privacy regulation. In particular, those enacted by Massachusetts and Nevada in 2010 significantly raised the bar in terms of business requirements. Even organizations that have no facilities or personnel in Massachusetts may be subject to the state's regulations if they maintain personal information about any Massachusetts resident. The Nevada law applies only to an organization doing business in Nevada. It requires the use of encryption when data storage devices containing personal information are moved beyond the physical or logical controls of the organization or when data is transferred electronically (other than by fax) outside the secure system of an organization. Beyond the expanding U.S. federal legislation and tougher and more pervasive state legislation, other factors increasing privacy-related risks include expansion and enforcement of the Health Insurance Portability and Accountability Act (HIPAA) and international standards. Particularly noteworthy within international standards is the European Union (EU) Data Protection Directive (also known as Directive 95/46/EC). It requires member states (countries) to enact laws prohibiting the transfer of personal information to those countries outside the EU that fail to ensure an adequate level of privacy protection (the U.S. and the EU have established a safe harbor program to meet this concern). Further, the consequences of failing to protect personal information include potential damage to the organization's reputation, brand or business relationships; the possibility of legal liability and industry or regulatory sanctions; possible charges of deceptive business practices; customer or employee distrust; and, in some extreme cases, possible exposure to criminal charges. Such was the case in March 2011 when Google Inc. agreed, without admitting or denying Federal Trade Commission (FTC) charges, to a settlement with the FTC related to alleged deceptive representations and violation of Google's own privacy policy when it launched its social network, Google Buzz, in 2010. The groundbreaking proposed settlement, a first in the history of FTC settlement orders, required Google to implement a comprehensive privacy program to protect consumers' personal information. It also called for regular, independent privacy audits for the next 20 years. This article provides a brief overview of current and emerging privacy-related risks-from regulation and reputation damage- and then demonstrates how businesses can address these risks by leveraging the AICPA/Canadian Institute of Chartered Accountants' (CICA) Generally Accepted Privacy Principles (GAPP) framework. HOW GAPP CAN HELP GAPP brings together international privacy regulatory requirements and best practices in one framework based on privacy principles (see sidebar, 10 Generally Accepted Privacy Principles). The overall objective of the application of GAPP is as follows: * Personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice and with criteria set forth in Generally Accepted Privacy Principles issued by the AICPA and CICA. …

Récupéré en direct depuis OpenAlex et désinversé. Les résumés ne sont pas conservés dans cette base de données : les index inversés représentent 8,6 Go des 9,3 Go de texte de la base, et le serveur dispose de 13 Go libres.

Comment cette classification a été obtenuedéplier

Prédiction distillée sur la base complète

Imitation des enseignants

Ni prévalence calibrée, ni vérité terrain. Validation humaine à venir. Apprise à partir de 10 348 étiquettes directes de Codex et de 10 348 étiquettes directes de Gemma. Le mode candidate est l'union des têtes enseignantes seuillées; le consensus est leur intersection. Ces sorties portent le statut machine_predicted_unvalidated et ne sont ni des étiquettes humaines ni des étiquettes directes de modèles de pointe.

score de la tête « metaresearch » (Codex)0,002
score de la tête « metaresearch » (Gemma)0,002
Version: codex-gemma-dda1882f352aStatut de validation: machine_predicted_unvalidated
Catégories candidatesMéta-épidémiologie (sens strict)
Catégories consensuellesaucune
DomaineSignal candidat: aucune · Signal consensuel: aucune
Devis d'étudeSignal candidat: Théorique ou conceptuel · Signal consensuel: aucune
GenreSignal candidat: Empirique · Signal consensuel: Empirique
Score de désaccord entre enseignants0,644
Score d'incertitude au seuil1,000

Scores Codex et Gemma par catégorie

CatégorieCodexGemma
Métarecherche0,0020,002
Méta-épidémiologie (sens strict)0,0000,000
Méta-épidémiologie (sens large)0,0010,000
Bibliométrie0,0010,001
Études des sciences et des technologies0,0010,000
Communication savante0,0000,005
Science ouverte0,0010,000
Intégrité de la recherche0,0000,001
Charge utile insuffisante (le modèle a refusé de juger)0,0000,000

Scores machine (provisoires)

Les deux têtes enseignantes du modèle étudiant, lues sur ce travail. Un score ordonne la base pour la relecture; il n'affirme jamais une catégorie, et le statut de validation accompagne chaque rangée tel quel.

Scores de référence d'un modèle non mature (critères de maturité non atteints, 7 itérations). Un score ordonne; il n'affirme jamais une catégorie.

Tête enseignante Opus0,177
Tête enseignante GPT0,390
Écart entre enseignants0,213 · la distance entre les deux têtes enseignantes sur ce seul travail
Statut de validationscore_only:v0-immature-baseline · tel quel depuis la passe de notation : score_only signifie que le nombre peut ordonner les travaux, et qu'aucune étiquette de catégorie n'en découle

Classification

machine, non validée

Prédiction automatique; un appel candidat d’une seule tête enseignante, pas un consensus.

Devis d'étudeThéorique ou conceptuel
Domainenon disponible
GenreEmpirique

Le détail, modèle par modèle et score par score, se trouve en fin de page sous « Comment cette classification a été obtenue ».

En bref

Citations0
Publié2011
Routes d'admission1
Résumé présentoui

Explorer davantage

Même revueJournal of accountancy online/Journal of accountancyMême sujetPrivacy, Security, and Data ProtectionTravaux en français237 207