Cloud native information systems engineering enables scalable and resilient service infrastructures for all major online offerings. These are built following agile development practices. At the same time, a growing demand for privacy-friendly services is articulated by societal norms and policy through effective legislative frameworks. In this paper, we identify the conceptual dimensions of cloud native privacy engineering and propose an integrative approach to be addressed in practice to overcome the shortcomings of existing privacy enhancing technologies. Furthermore, we propose a reference software development lifecycle called DevPrivOps to enhance established agile development methods with respect to privacy. Altogether, we show that cloud native privacy engineering advances the state of the art of privacy by design and by default using latest technologies.
翻译:云层本地信息系统工程为所有主要的在线服务提供提供了可扩展和具有复原力的服务基础设施,这些基础设施是按照灵活发展做法建造的。与此同时,社会规范和政策通过有效的立法框架阐明了对方便隐私服务日益增长的需求。在本文件中,我们确定了云层本地隐私工程的概念层面,并提议了一种综合方法,以便在实践中克服现有增强隐私技术的缺陷。此外,我们提议了一个称为DevPrivOps的参考软件开发生命周期,以加强在隐私方面既定的灵活开发方法。总的来说,我们表明云层本地隐私工程通过设计和默认使用最新技术,提高了隐私的状态。