DEVELOPMENT OF A RISK-ADAPTIVE GDPR-COMPLIANT CYBER-SECURITY FRAMEWORK BASED ON HYBRID ACCESS CONTROL MODELS
Keywords:
Data protection, GDPR, Access control model, Risk adaptive security, NIST, COBITAbstract
An access control-oriented cybersecurity approach aims at securing company information and systems from any possible attacks through restricting specific users' access to specific resources only as per user access policy. With constant evolution of the digital technologies, cloud and connected systems, cyber risks are also on the rise. Access control is the most important aspects in the field of information security. This study analyses how the models of mandatory access control, discretionary access control, role-based access control and attribute-based access control can encourage cybersecurity and privacy governance and the data protection regulation in the General Data Protection Regulation (GDPR). While the NIST Cybersecurity Framework, ISO/IEC 27001, and COBIT incorporate some cyber security elements technically, they pay little attention to the legal responsibilities for privacy. In this study, the goal is to develop an integrated GDPR-compliant cyber security control framework (IGCCF). In this context, it’s acceptable to develop a new model of access control that can integrate with the legal and hybrid security domains. This method considers governance and security requirements, and monitors and audits access control for increased levels of accountability, confidentiality, integrity and compliance. With this, the prototype of the framework was developed for the web & system users such as HR, CEO, users etc. The results show that the flexible access control mechanism constructed by employing different roles of user has a positive effect on the system's security aspects, lowers the probability of unauthorized usage of the system, and fulfills the guidelines pertaining to unlawful entry. Access control is an integral part of the strategy in cyber security and not simply a technical procedure. In the context of integrated access control governance frameworks, the access control can provide enhanced a security in the modern digital business environment.












