{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T20:34:06Z","timestamp":1783024446980,"version":"3.54.6"},"reference-count":34,"publisher":"SAGE Publications","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JHS"],"published-print":{"date-parts":[[2024,5,10]]},"abstract":"<jats:p>Since 2018, the enactment of the General Data Protection Regulation (GDPR) has bestowed distinct privileges upon each person while imposing protocols to safeguard personal information. The GDPR effectively tackles an evident requirement within our interconnected, social media-driven society. However, its compliance poses a considerable challenge, particularly for small and medium-sized businesses. This work aims to identify and select the proper countermeasures in order to comply with GDPR, by using standard security controls. Thus, we designed a tool to handle some phases of the compliance process in an almost semi-automated way. The proposed approach relies on standard security control frameworks (namely NIST SP-800-53) and can be easily adapted to different frameworks. The proposed technique was validated using our university as a case study, through a simple demonstrator, although the solution can be transparently applied to different contexts.<\/jats:p>","DOI":"10.3233\/jhs-230080","type":"journal-article","created":{"date-parts":[[2024,2,16]],"date-time":"2024-02-16T10:43:48Z","timestamp":1708080228000},"page":"147-174","source":"Crossref","is-referenced-by-count":8,"title":["GDPR compliance through standard security controls: An automated approach"],"prefix":"10.1177","volume":"30","author":[{"given":"Daniele","family":"Granata","sequence":"first","affiliation":[{"name":"Department of Engeenering, University of Campania Luigi Vanvitelli, Aversa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michele","family":"Mastroianni","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Salerno, Fisciano, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Massimiliano","family":"Rak","sequence":"additional","affiliation":[{"name":"Department of Engeenering, University of Campania Luigi Vanvitelli, Aversa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pasquale","family":"Cantiello","sequence":"additional","affiliation":[{"name":"Osservatorio Vesuviano, Istituto Nazionale di Geofisica e Vulcanologia, Napoli, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giovanni","family":"Salzillo","sequence":"additional","affiliation":[{"name":"Department of Engeenering, University of Campania Luigi Vanvitelli, Aversa, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"179","reference":[{"key":"10.3233\/JHS-230080_ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40512-4_5"},{"key":"10.3233\/JHS-230080_ref2","doi-asserted-by":"crossref","unstructured":"A.S.\u00a0Ahmadian and J.\u00a0Jurjens, Supporting model-based privacy analysis by exploiting privacy level agreements, in: Conference of 8th IEEE International Conference on Cloud Computing Technology and Science, CloudCom 2016, 12 December 2016 Through 15 December 2016, IEEE Computer Society, 2016, pp.\u00a0360\u2013365. Conference Code: 126112. ISSN 23302194. ISBN 9781509014453.","DOI":"10.1109\/CloudCom.2016.0063"},{"key":"10.3233\/JHS-230080_ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3167132.3167288"},{"key":"10.3233\/JHS-230080_ref4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TSC.2020.2999559","article-title":"Tracking GDPR compliance in cloud-based service delivery","author":"Barati","year":"2020","journal-title":"IEEE Transactions on Services Computing"},{"key":"10.3233\/JHS-230080_ref5","doi-asserted-by":"publisher","first-page":"119697","DOI":"10.1109\/ACCESS.2020.3005509","article-title":"GDPR compliance verification in Internet of things","volume":"8","author":"Barati","year":"2020","journal-title":"IEEE Access"},{"key":"10.3233\/JHS-230080_ref6","doi-asserted-by":"publisher","first-page":"243","DOI":"10.1007\/s41125-019-00042-z","article-title":"A framework for GDPR compliance for Small- and Medium-Sized Enterprises","volume":"4","author":"Brodin","year":"2019","journal-title":"European Journal for Security Research"},{"key":"10.3233\/JHS-230080_ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87010-2_5"},{"key":"10.3233\/JHS-230080_ref13","doi-asserted-by":"publisher","DOI":"10.1109\/IC2E.2015.72"},{"key":"10.3233\/JHS-230080_ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22354-0_78"},{"key":"10.3233\/JHS-230080_ref15","first-page":"1","article-title":"An assessment of privacy preservation in crowdsourcing approaches: Towards GDPR compliance","author":"Diamantopoulou","year":"2018","journal-title":"IEEE Computer Society"},{"key":"10.3233\/JHS-230080_ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-42048-2_16"},{"issue":"4","key":"10.3233\/JHS-230080_ref18","doi-asserted-by":"publisher","first-page":"1013","DOI":"10.1177\/1073110518822003","article-title":"The EU general data protection regulation: Implications for international scientific research in the digital era","volume":"46","author":"Dove","year":"2018","journal-title":"The Journal of Law, Medicine & Ethics"},{"key":"10.3233\/JHS-230080_ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SERVICES.2018.00036"},{"key":"10.3233\/JHS-230080_ref20","doi-asserted-by":"publisher","DOI":"10.1109\/BigData.2018.8622236"},{"key":"10.3233\/JHS-230080_ref21","doi-asserted-by":"publisher","DOI":"10.2861\/17421"},{"key":"10.3233\/JHS-230080_ref22","doi-asserted-by":"publisher","DOI":"10.5220\/0010455200870098"},{"key":"10.3233\/JHS-230080_ref23","doi-asserted-by":"publisher","DOI":"10.1007\/s11219-023-09634-4"},{"key":"10.3233\/JHS-230080_ref24","doi-asserted-by":"publisher","first-page":"129788","DOI":"10.1109\/ACCESS.2023.3333209","article-title":"Automated generation of 5G fine-grained threat models: A systematic approach","volume":"11","author":"Granata","year":"2023","journal-title":"IEEE Access"},{"key":"10.3233\/JHS-230080_ref25","doi-asserted-by":"publisher","DOI":"10.1080\/09540091.2023.2284645"},{"key":"10.3233\/JHS-230080_ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-21637-4_3"},{"key":"10.3233\/JHS-230080_ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3544463"},{"key":"10.3233\/JHS-230080_ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3462757.3466081"},{"key":"10.3233\/JHS-230080_ref31","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-53r5"},{"key":"10.3233\/JHS-230080_ref32","doi-asserted-by":"publisher","DOI":"10.1109\/BigDataSecurity-HPSC-IDS49724.2020.00026"},{"key":"10.3233\/JHS-230080_ref33","doi-asserted-by":"publisher","DOI":"10.3390\/s21237994"},{"issue":"2","key":"10.3233\/JHS-230080_ref34","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1016\/j.clsr.2018.01.002","article-title":"Are \u2018pseudonymised\u2019 data always personal data? Implications of the GDPR for administrative data research in the UK","volume":"34","author":"Mourby","year":"2018","journal-title":"Computer Law & Security Review"},{"key":"10.3233\/JHS-230080_ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.csl.2021.101299"},{"key":"10.3233\/JHS-230080_ref37","unstructured":"M.\u00a0Palmirani and G.\u00a0Governatori, Modelling legal knowledge for GDPR compliance checking, in: JURIX, Vol.\u00a0313, 2018, pp.\u00a0101\u2013110."},{"key":"10.3233\/JHS-230080_ref38","doi-asserted-by":"crossref","unstructured":"M.\u00a0Palmirani, M.\u00a0Martoni, A.\u00a0Rossi, C.\u00a0Bartolini and L.\u00a0Robaldo, PrOnto: Privacy ontology for legal reasoning, in: Electronic Government and the Information Systems Perspective, A.\u00a0K\u0151 and E.\u00a0Francesconi, eds, Springer International Publishing, Cham, 2018, pp.\u00a0139\u2013152. ISBN 978-3-319-98349-3.","DOI":"10.1007\/978-3-319-98349-3_11"},{"key":"10.3233\/JHS-230080_ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-08812-4_44"},{"key":"10.3233\/JHS-230080_ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66284-8_30"},{"key":"10.3233\/JHS-230080_ref41","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.102896"},{"issue":"3","key":"10.3233\/JHS-230080_ref42","doi-asserted-by":"publisher","first-page":"213","DOI":"10.1049\/iet-sen.2018.5293","article-title":"Service level agreement-based GDPR compliance and security assurance in (multi)cloud-based systems","volume":"13","author":"Rios","year":"2019","journal-title":"IET Software"},{"key":"10.3233\/JHS-230080_ref43","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1016\/j.ejca.2018.09.032","article-title":"Observational health research in Europe: Understanding the general data protection regulation and underlying debate","volume":"104","author":"van Veen","year":"2018","journal-title":"European Journal of Cancer"}],"container-title":["Journal of High Speed Networks"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/JHS-230080","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T08:44:37Z","timestamp":1777452277000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/JHS-230080"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,10]]},"references-count":34,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.3233\/jhs-230080","relation":{},"ISSN":["1875-8940","0926-6801"],"issn-type":[{"value":"1875-8940","type":"electronic"},{"value":"0926-6801","type":"print"}],"subject":[],"published":{"date-parts":[[2024,5,10]]}}}