OASIS Privacy Management Reference Model (PMRM) TC

 View Only
  • 1.  PMRM simplifications

    Posted 08-25-2011 14:34
    Below is a summary of our recent dialogs on simplifying the PMRM structure. Abbreviated/informal definitions for the Services are given. These definitions would be (re)formalized.   Core Policy Services:         Agreement: determine and/or arbitrate PI permissions       Usage: manage permissions, policies, use of PI       Security: provide data protection   Privacy Assurance Services        Validation: check PI for accuracy      Certification: check and confirm credentials      Enforcement: audit for and react to exception conditions   Presentation and Life Cycle Services         Interaction: inter/intra communications; actor persona       Access: allow subject to view and suggest corrections to PI held by other Actors   Each Service is composed of a set of Functions drawn from Function categories:      - Configure    - Input    - Process    - Output   Configure could also be called: Setup or Initialize     Below this Function level, Mechanisms are employed to achieve those functions.   The definitions of Actor, Touch Point, and System are still wobbly.     Michael