1,720,981 research outputs found
Artifact-driven Process Monitoring: Dynamically Binding Real-world Objects to Running Processes
Monitoring inter-organizational business processes requires explicit knowledge about when activities start and complete. This is a challenge because no single system controls the process, activities might not be directly recorded, and the overall course of execution might only be determined at runtime. In this paper, we address these problems by integrating process monitoring with sensor data from real-world objects. We formalize our approach using the E-GSM artifact-centric language. Since the association between real-world objects and process instances is often only determined at runtime, our approach also caters for dynamic binding and unbinding at runtime
A Prototype to Analyze Role- and Attribute-Based Access Control Models
Käesoleva lõputöö eesmärgiks on luua juurdepääsu kontrolli võrdlemise platvorm või tööriist, mille abil kasutajad saavad eksperimenteerida ning luua turvaanalüüse ja -mudeleid. Lõputöö jaguneb kahte ossa: teoreetiline ja praktiline. Teoreetilises osas uuritakse, kuidas turvalisusmudelid, nagu näiteks kasutajapõhine juurdepääs ja atribuudipõhine juurdepääs töötavad, defineeritakse metamudeleid ja selgitatakse turvalisuse voogu. Seejärel võrreldakse kahte mudelit, fikseerides võrdluskriteeriumid, mida hiljem kasutatakse platvormil. Praktilises osas kasutatakse teoreetilise osa põhipunkte ning defineeritakse vajadused ja kasutuslahendid, et anda kasutajatele maksimaalne arusaam rakenduse sees toimuvast kasutajaliidesega suheldes.The goal of this thesis is to create an access control comparison prototype, where people will do experiments with security models and analyse reports based on their actions. The thesis is split into two parts: theoretical and practical. In the theoretical part, we studied how security models like, Role-Based Access and Attribute-Based Access work, defined the meta models and explained the security flows. After that, we did the theoretical comparison between these models and defined the comparison criteria, which later was used in the prototype. Meanwhile, in practical part, we put main points of the theoretical part and defined requirements and use cases in order to give maximum experience to the users about what is going underneath the application during the interaction through graphical user interface
Security Risk Management for the IoT systems
Alates 2012. aastast on ülemaailmne infastruktuuri üksuste arv (The Internet of Things) jõudsalt kasvanud üle kahe korra. Koos selle numbriga on ka kasvanud ka võimalikud riskid ning ohud, mis mõjutavad süsteemi turvalisust. Tulemuseks on suur hulk isiklikke andmeid kas varastatud või kahjustatud. Vastavalt allikatele "Third Quarter, 2016 State of the Internet / Security Report" ja "Akamai Intelligent Platform", on DdoS Q3 rünnakute arv suurenenud 2016 aastal 71% võrreldes aastaga 2015. Kõige suurem DdoS fikseeritud rünnakutest oli 623 Gbps rünnak. Kõik need faktid tõestavad, et Iot süsteemis on veel siiamaani probleeme isikuandmete turvalisusega. Isklikud andmed on ohtude suhtes haavatavad. Käesolev töö ühendab Iot raamastikus turvalisuse riskijuhtimine teadmised olemasoleva praktikaga. Raamastiku eesmärgiks on tugevdada Iot süsteemi nõrku osi ning kaitsta isiklikke andmeid. Pakume välja esialgse igakülgse võrdlusmudeli juhtkontrolli turvariskideks IoT süsteemides hallatavate ja kontrollitavate info- ja andmevarade jaoks. Infosüsteemide turvalisuse riskijuhtimise valdkonna domeeni mudeli põhjal uurime, kuidas avatud veebirakenduse turvalisuse projektis määratletud turvaauke ja nende vastumeetmeid võiks vaadelda IoT kontekstis. Selleks, et illustreerida etalonmudeli rakendamist, katsetatakse raamistikku IoT-süsteemil. Sellesse süsteemi kuuluvad Raspberry Pi 3, sensorid ning kaugandmete ladustamine.Since 2012 the number of units in global infrastructure for the information society (The Internet of Things) has grown twice. With this number also has grown the number of possible threats and risks, which influence security on all levels of the system. As a result, a huge amount of users' data was stolen or damaged. According to Third Quarter, 2016 State of the Internet / Security Report based on data gathered from the Akamai Intelligent Platform the total number of DDoS attacks in Q3 2016 increased in 71\\% compared to Q3 2015. With 623 Gbps data transfer attack it was largest DDoS ever and this fact will only increase the number of future attack events. All these facts reveal a problem that a lot of IoT systems are still unsecured and users' data or personal information stay vulnerable to threats. The thesis combines knowledge of Security Risk Management with existing practice in securing in IoT into a framework, which aim is to cover vulnerabilities in IoT systems in order to protect users' data. We propose an initial comprehensive reference model to management security risks to the information and data assets managed and controlled in the IoT systems. Based on the domain model for the information systems security risk management, we explore how the vulnerabilities and their countermeasures defined in the open Web application security project could be considered in the IoT context. To illustrate the applicability of the reference model we test the framework on self-developed IoT system represented by Raspberry Pi 3 interconnected with sensors and remote data storage
Privacy Enhanced Secure Tropos: A Privacy Modeling Language for GDPR Compliance
Euroopa Liidu isikuandmete kaitse üldmäärusele (GDPR) vastavuse tagamine saab õiguslikult hädavajalikuks kõigis tarkvarasüsteemides, mis töötlevad ja haldavad isikuandmeid. Sellest tulenevalt tuleb GDPR vastavuse ja privaatsuse komponentidega arvestada arendusprotsessi varajastes etappides ning tarkvarainsenerid peaksid analüüsima mitte ainult süsteemi, vaid ka selle keskkonda. Käesolev uuring keskendub viimasel ajal tähepepanu pälvinud modelleerimiskeelele Privacy Enhanced Secure Tropos (PESTOS), mis põhineb Tropos metoodikal, hõlmates eesmärkide ja reeglite vaatenurka, mis aitab tarkvarainseneridel hinnata erinevaid Privacy-enhancing Technologies (PET-e) kandidaate, arendades samas privaatsustundlikke süsteeme, et need oleksid GDPR-iga kooskõlas.Kuigi GDPR artikli 5 lõikes 2 sätestatakse, et vastutuse põhimõtte kohaselt peavad organisatsioonid suutma näidata vastavust GDPR põhimõtetele (meie teadmiste kohaselt ei ole praegu veel ühtegi teist privaatsuse modelleerimise keelt, mis keskendub eelkõige GDPR nõuetele ja mis põhineb Security Risk-Aware Secure Tropos metoodikal), ei olnud saadaval ühtegi praktilist modelleerimise keelt, mis rahuldaks tööstus- ja ärivajadusi. See on Euroopa Liidu piirkonna avalikele asutustele ja erasektorile tõsine probleem, kuna GDPR toob vastutavatele ja volitatud töötlejatele kaasa väga tõsiseid trahve. Organisatsioonid ei oma piisavat kindlustunnet regulatsioonide täitmise osas ja tarkvarainseneridel puuduvad meetodid saamaks ülevaadet infosüsteemide muutmistaotlustest. Käesolevas lõputöös rakendatakse struktureeritud privaatsuse modelleerimise keelt, mida nimetatakse PESTOS-iks. Selle eesmärk on tagada kõrgetasemeline vastavus GDPR nõuetele kattes PET-e eesmärk-tegija-reegel perspektiivis hindamiseks ka lõimitud andmekaitse põhimõtted. GDPR 99-st artiklist 21 artiklit saab identifitseerida tehniliste nõudmistena, mile osas PESTOS suudab ettvõtetel aidata GDPR-ist tulenevaid kohustusi täita. Identiteedi- ja turvaekspertide seas läbiviidud uuring kinnitab, et kavandatud mudelil on piisav õigsus, täielikkus, tootlikkus ja kasutusmugavus.The European Union General Data Protection Regulation (GDPR) compliance is becoming a legal necessity for software systems that process and manage personal data. As a result of that fact, GDPR compliance and privacy components need to be considered from the early stages of the development process and software engineers should analyze not only the system but also its environment. Hereby with this study, Privacy Enhanced Secure Tropos (PESTOS) is emerging as a privacy modeling language based on Tropos methodology, which covers the goal and rule perspective, for helping software engineers by assessing candidate PETs, while designing privacy-aware systems, in order to make them compatible with GDPR. Although in Article 5(2) of the GDPR, the accountability principle requires organizations to show compliance with the principles of the GDPR, (To the best of our knowledge, currently there is no other privacy modeling language especially focuses on the GDPR compliance and enhanced based on Security Risk-Aware Secure Tropos methodology) there were not any practical social modeling languages supply the demand driven by industrial and commercial needs. This is a serious issue for public institutions and private sector in EU-zone because GDPR brings very serious charges for data controllers and data processors, therefore organizations do not feel themselves ready to face with those regulations and software engineers have a lack of methods for capturing change requests of the information systems. This paper applies a structured privacy modeling language that is called as PESTOS which has a goal-oriented solution domain that aims to bring a high compatibility with GDPR by covering Privacy by Design strategies for assessing proper privacy-enhancing technologies(PETs) in a respect of the goal-actor-rule perspective. Among the 99 articles of GDPR, 21 articles can be identified as technical level of requirements that PESTOS is able to transform them into GDPR goals needs to be fulfilled in order to support business assets. A survey conducted by identity and security experts validates that proposed model has a sufficient level of correctness, completeness, productivity and ease of use
Adapting a Stress Testing Framework to a Multi-module Security-oriented Spring Application
Programmeeritakse mitmekomponendilist süsteemi. Kolm põhikomponenti on järgmised: põhiserver (Spring rakendus), mobiilirakendused (iOS, Android), klienditeeninduse veebiportaalid. Kõige tähtsam süsteemi töös on põhiserver, kuna see on enamuse veebiportaalide ning mobiilirakenduste päringute sihtpunkt. See on mitmemooduliline projekt, kus kõik moodulid suhtlevad omavahel. Potentsiaalselt hakkab süsteemi kasutama sadu tuhandeid inimesi – kümneid tuhandeid paralleelseid sessioone. Seetõttu tuleb läbi viia süsteemi ulatuslik koormustestimine. Kahjuks on nii, et koormustestimise raamistikud oma originaalseisus ei sobi antud süsteemi testimiseks. Seega, koormustestimise raamistiku tuleb seadistada ning laiendada selleks, et see toetaks antud süsteemi spetsiifilisi protokolle ja võimaldaks testida kõiki komponente üheskoos. Hetkel on saadaval palju koormustestimise raamistikke. Mõned nendest on: Locust, Apache JMeter, Gatling Project. Need raamistikud erinevad üksteisest programmeerimiskeele, eriomaduste ning põhiloogika järgi. Kuna tegu on kommertsprojektiga, peab valitud koormustestimise raamistik vastama kliendi funktsionaalsete ja mittefunktsionaalsete nõuetele. Kuna koormustestimist viiakse läbi ainult põhiserveril, peab seadistama ja laiendama valitud raamistikku, et simuleerida teisi süsteemi komponente ja serveri protokolle. See töö annab kiire ülevaate varem mainitud koormustestimise raamistikest eriomaduste järgi, valib raamistiku, mida kohandatakse antud projekti raames koormustestimise läbi viimiseks ning kirjeldab kohandamise protsessi. Samuti toob see töö välja mõned koormustestimise raamistike piirangud ning kirjeldab meetodeid nende ületamiseks. Viimaks, süsteemi testitakse valitud raamistiku abil ning esitatakse ja valideeritakse tulemusi.A multi-component system is being build. Three main components are: backend server (Spring application), mobile applications (iOS, Android), customer service web portals. Our main concern is the backend server, because it is the destination of the majority of requests from customer service web portals and mobile applications. It is a multi-module project where all modules communicate to each other. The system is going to be used potentially by hundreds thousands of users with tens thousands of simultaneous usages. Therefore, extensive stress-testing must be conducted. Unfortunately, stress-testing frameworks in the original state are not suitable for the given system. Thus a stress-testing framework must be configured and extended to the point it supports the system’s specific protocols and can test all the system’s components together. There are numerous of stress-testing frameworks available. Some examples are: Locust, Apache JMeter, Gatling Project. These frameworks differ in terms of coding language, features and core logic. As it is a commercial project, the chosen stress-testing framework must also comply with client’s functional and non-functional requirements. Due to stress-testing being conducted only on the backend server component, the selected stress-testing framework must be configured/extended to simulate other components and the required server protocols. The thesis provides a brief comparison of the available stress-testing frameworks based on their features and written code language and define the one which is going to be adapted to conduct the stress-testing within the project and how the adaptation is done. The thesis also points out some of stress-testing frameworks’ limitations with techniques to overcome them. Finally, the system is tested using the selected testing framework and the results are presented and validated
A Reference Model for the Blockchain-Based Distributed Ledger Technology
Plokiahel on hajus, transaktsioonidel põhinev andmebaas, mis on jagatud kõigi kasutajate vahel. See on Bitcoin’i põhiline tehnoloogiline innovatsioon ning plokiahela roll on olla hajus pearaamat kõikidele transaktsioonidele. Igal kasutajal (sõlm, ingl.k. ’node’) on terve koopia kõige hilisemast ahelast, mis hoiab endas igat transaktsiooni, mis kunagi tehtud. Iga plokk sisaldab endas eelmise ploki räsiväärtust (ingl.k. ’hash’), mis seob kaks plokki omavahel. Ühendatud plokid moodustavadki plokiahela. Paraku sellisel tehnoloogial puudub standard ja ühtne arusaam. Selle põhjuseks on vähesed akadeemilised uurimustööd, mis käsitleksid seda tehnoloogiat ja kirjeldaksid standardiseeritud mudelit. Käesoleva lõputöö eesmärgiks on võrrelda nelja plokiahela tehnoloogiat ning keskenduda nende äritaseme atribuutidele - tehnoloogias osalejad ja nende rollid, teenused, äriprotsessid ja andmemudelid. Analüüsi ja võrdluse tulemusena valmib standardiseeritud mudel, mis võib potentsiaalselt abistada analüütikuid ja arendajaid plokiahela tehnoloogiaga töötamisel. Loodud mudeli täpsuse valideerimiseks võrreldakse seda erinevate plokiahela tehnoloogiatega. Lisaks, valideerime standardmudelit kasutades seda riskipõhise analüüsi teostamisel.Blockchain is a distributed, transactional database that is shared across all the nodes participating in the network. This is the main technical innovation of Bitcoin and it acts as a public ledger for the transactions. Every node in the system has a full copy of the current chain, which contains every transaction ever executed. Every block contains a hash of the previous block, linking these two together. The linked blocks become a blockchain. However, this technology lacks standardisation and uniform understanding. This is due to a few studies, that would provide a comprehensive model of the blockchain and the distributed ledger technology. In this thesis we compare four blockchain technology platforms and focus on their business level properties including actors and roles, services, processes and data model. Our comparison results in a reference model, which could potentially guide the business and system analysts and software developers when developing new blockchain platforms or their supported implementations. Accuracy of the proposed reference model is validated by considering it against selected blockchain platforms. The reference model is also validated via application, showing its usefulness for a risk-related blockchain security assessment
An Automated Methodology for Validating Web Related Cyber Threat Intelligence by Implementing a Honeyclient
Loodud töö panustab küberkaitse valdkonda pakkudes alternatiivse viisi, kuidas hoida ohuteadmus andmebaas uuendatuna. Veebilehti kasutatakse ära viisina toimetada pahatahtlik kood ohvrini. Peale veebilehe klassifitseerimist pahaloomuliseks lisatakse see ohuteadmus andmebaasi kui pahaloomulise indikaatorina. Lõppkokkuvõtteks muutuvad sellised andmebaasid mahukaks ja sisaldavad aegunud kirjeid. Lahendus on automatiseerida aegunud kirjete kontrollimist klient-meepott tarkvaraga ning kogu protsess on täielikult automatiseeritav eesmärgiga hoida kokku aega. Jahtides kontrollitud ja kinnitatud indikaatoreid aitab see vältida valedel alustel küberturbe intsidentide menetlemist.This paper is contributing to the open source cybersecurity community by providing an alternative methodology for analyzing web related cyber threat intelligence. Websites are used commonly as an attack vector to spread malicious content crafted by any malicious party. These websites become threat intelligence which can be stored and collected into corresponding databases. Eventually these cyber threat databases become obsolete and can lead to false positive investigations in cyber incident response. The solution is to keep the threat indicator entries valid by verifying their content and this process can be fully automated to keep the process less time consuming. The proposed technical solution is a low interaction honeyclient regularly tasked to verify the content of the web based threat indicators. Due to the huge amount of database entries, this way most of the web based threat indicators can be automatically validated with less time consumption and they can be kept relevant for monitoring purposes and eventually can lead to avoiding false positives in an incident response processes
Managing Security Risks Using Attack-Defense Trees
Nagu mujal valdkondades, kasvab tänapäeval vajadus turvalisuse järele, nii ka ärimaailmas. Käesolev magistritöö üritab seda probleemi lahendada kasutades riskianalüüsi diagrammi mudelit, mida inglise keeles nimetatakse Attack Tree.ISSRM (Information System Security Risk Managment) on mudel, mis käsitleb kõiki olulisi riskianalüüsi aspekte, on lihtsalt arusaadav ja annab olukorrast kiire ülevaate. Laiendustena on olemas mõned sellised riskianalüüsi diagrammid, kuid ükski neist pole võimeline käsitlema kõiki võimalikke ohuolukordi. See paneb diagrammi kasutamisele piirid, kuna ei arvesta võimalikke vastumeetmeid ohtudele, ega ohuallika profiili.Antud magistritöö pakub sellele probleemile kolmeosalist lahendust.1. luua sild riskianalüüsi puu osast, mis käsitleb kaitsetehnikaid (Attack Defence Tree), kuni ISSRM mudelini;2. arvestades minevikus ette tulnud riske, riskifaktorite tõenäolisuse ja nendega seotud kulutuste mõõteparameetrite väljatöötamine;3. tööriista kasutamine, mis on välja töötatud antud riskianalüüsipuu abil.Selliselt loodud sild aitab leida veel avastamata aspekte riskianalüüsi puus. Lisades sellise laienduse, on riskianalüüsi puu täielikum ja muudab ISSRM-i mudeli mitmekülgsemaks. Selleks, et riske paremini analüüsida, on kasulik arvestada ka minevikus ette tulnud ohte ning neid matemaatiliselt uurida tõenäolisuse aspektist, et minimeerida sarnaste ohuolukordade taastekkimise tõenäosust. Magistritöö tegemise käigus välja töötatud tööriist (Aligned Attack-Defense Tree or A-ADTree) on võimekam riski tõenäosusele hinnangu andmisel teistest juba olemasolevatest versioonidest. Antud tööriist annab riskianalüüsi hindajatele rohkem võimalusi võimalike ohuolukordade lahendamiseks ja ennetamiseks. Kuna siin kasutatud modelleerimiskeeled on juba sobitatud ISSRM mudeliga, võimaldab antud töös välja töötatud laiendus luua enam seoseid selle ning teiste modelleerimiskeelte (nt Secure BPMN, Misuse-case diagram, Secure TROPOS, and Mal-Activity diagram) vahel ka tulevikus.Nowadays there is an increasing demand for answering the security needs in systematic ways. The In this thesis, we have addressed risk management using Attack Tree.Information System Security Risk Management (ISSRM) is a model which covers all the important concepts in risk management. Also, attack trees are simple and efficient tools for showing the risks. There are few extensions of attack trees, but none of them covers all risk concepts. The said problem limited the usage of attack tree model since it does not consider important measures such as countermeasures, or threat agent’s profile.The contribution to resolve the problem in this thesis includes three steps. Obtaining an alignment from Attack-Defense trees to ISSRM. Measurement of the metrics of the nodes of tree using historical dataImplementation of a tool based on obtained tree.Using the alignment, we have detected the uncovered concepts in Attack-Defense tree. Then we tried to add these concepts to the current Attack-Defense tree. Therefore, the new Attack-Defense tree (called Aligned Attack-Defense tree or A-ADTree) covers most important concepts of ISSRM. In order to measure the risk, we have proposed a mathematical model to evaluate the probability of the nodes in the tree, based on historical data. Then, implemented tool helps to materialize the effect of threat agent’s profile, and countermeasures on the risks. The result of implemented tool shows, the obtained A-ADTree has more capabilities (in the evaluation of the probability of risk) in comparison to previous versions. This solution is capable of giving more hints for the project managers when they are deciding about possible solutions in industries. Additionally, this alignment helps to obtain another alignment between A-ADTree and the other modeling languages in future, since these modeling languages are already aligned to ISSRM
Analysis of Exploit-kit Incidents and Campaigns Through a Graph Database Framework
Tänapäeval peaaegu igas seadmes kasutatav veebilehitseja on soodsaim keskkond kurivara levitamiseks, kuna võimaldab ründeprogrammidel ekspluateerida hulgaliselt erinevaid vahendeid alates veeblihitseja üldisest ülesehitusest ja pluginatest kuni sellega seotud operatsioonisüsteemi eripäradeni. Seega on veebilehitsejates kasutatavad ründetarkvara komplektid üks levinumaid kurivara esinemisvorme ning seetõttu ka märkimisväärseks probleemiks nii digitaalse ekspertiisi spetsialistidele kui kurivara tõrje valdkonnas üldiselt.Kuigi salvestatud võrgupakettidest võib leida indikaatoreid, mis võimaldavad analüütikul tuvastada kurivara olemuse, pole need tihti piisavad süsteemi kompromiteerituse ulatuse määramiseks. Taoliste indikaatorite üksipulgi läbitöötamine on aeganõudev protsess ning intsidendi analüüs ja terviklik ülevaade sõltuvad sealjuures peamiselt kolmandate osapoolte kaudu saadud infost.Analüüsi käigus saab protsesse küll osaliselt automatiseerida kasutades avalikult kättesaadavaid programme nagu VirusTotal, WHOIS ja erinevad (IP, domeeni või veebilehe põhised) mustad nimekirjad. Seda osa protsessist tutvustab ka antud töö esimene pool.Graafiline modelleerimine aitab kaasa erinevatest allikatest pärineva info ja seoste koondamisel ühtsesse ja kergemini hoomatavasse vaatesse. Töö teine osa keskendubki viisidele, kuidas kasutada graafilise modelleerimise võimalusi nii üksikute intsidentide analüüsiks kui konkreetse ründetarkvara erinevate levitamisviiside kuvamiseks täpsema tervikpildi saamise eesmärgil.Töö viimane osa demonstreerib moodusi, kuidas antud lähenemine aitab välja tuua seosed ja seaduspärad, mille põhjal on võimalik teha pahavara tuvastamise ja tõrjumisega seonduvaid otsuseid ja järeldusi.In today’s threat landscape, the delivery of malware via browser exploit-kits poses specific challenges to the forensics analyst and from a defensive perspective in general. Web browsers offer a large surface of attack through their own implementation, the plugins they offer and the operating systems that they rely on.However, when looking at network traffic captures, they also leave specific traces that the analyst can identify but those still wouldn’t be enough to clearly determine if an infection was successful or not. Isolating these traces currently requires a lot of manual work and a complete analysis will also have to rely on third-party information in order to give a clear picture and understanding of the incident.A great deal of automation can be achieved here by using public APIs such as VirusTotal, whois databases, IP blacklists, etc during the analysis and a first part of our work is dedicated to that.From our perspective, we also see that the use of graph databases can be of a great help when putting together information from different sources that hold relationships with one another and a second part of our work will be to demonstrate that a graph database approach can be used to analyze single incidents as well as the delivery infrastructure of specific exploit-kits or malware campaigns that are spread by specific actors.We will then show that this approach reveals patterns and clusters from which decisions can be made from a defensive perspective
GDPR Implementation in an Airline Contact Center
Seoses GDPR kasutuselevõtmisega 2018. aasta mais, on paljudel ettevõtetel, kus kasutatakse tavapäraselt EL kodanike isikuandmeid, oht suurteks trahvideks. Lennufirmad on üks näide ärist, kus töödeldakse massiliselt isikuandmeid ja see toob teravalt esile lennuettevõtete vastavuse GDPR nõuetele. Suur osa neist andmetest töödeldakse kontaktkeskustes, mis toob vajaduse viia töötlemine vastavusse GDPR nõuetega. Lennufirmad, kus ei olda valmis kohaldama GDPR nõudeid, võivad silmitsi seista mainekahjudega, klientide usalduse kaotusega või pankrotiga suurte trahvide tõttu. Tänapäeval enamik lennufirmadest ostab kontaktkeskuse teenuseid sisse kolmandalt osapoolelt, mistõttu on keerukas andmetöötluse rolle ja vastutust jagada mõlema osapoole vahel. Pooled peavad jõudma kokkuleppele, et kanda võrdselt vastutust tänapäeva pingelises konkurentsis. Käesoleva magistritöö eesmärgiks on viia läbi Euroopa ühe suurima lennuettevõtja kontaktkeskuse juhtumianalüüs, analüüsida lendude broneerimise protsessi GDPR seisukohalt ja selgitada välja lüngad, mis võivad põhjustada nõuetele mittevastavust. Lõputöö keskendub vastavuse saavutamiseks lünkade täitmisele lennubroneerimise protsessis, tuues sisse uusi tegevusi, mida kinnitas ka lennufirma kontaktkeskuse juhtivtöötajate ekspertarvamus.With the introduction of GDPR in upcoming May 2018, many companies that used to handle personal data of EU citizens in a more casual manner, are now at risk of facing heavy fines. Airline industry is one such example of business entity that handles and processes personal data on massive scales, which puts the airline business in the spotlight of GDPR compliance. A fair amount of such data is processed in contact centers, which makes it vital to comply with GDPR. Airlines that are not ready to adapt GDPR may face loss of reputation, loss of customer’s trust and bankruptcy because of heavy fines. In today’s age, most of airlines have outsourced their contact center business to third parties, which makes it even more complicated to define the roles and responsibilities of data controller and data processor and both entities have to reach an agreement to share the burden of compliance, in order to survive in today’s competitive environment. The idea of this thesis is to study a running case scenario in one of the major European Airline’s contact center, analyze the flight booking process from GDPR’s perspective to find out the gaps that can cause non-compliance. The solution part of this thesis is focused on filling these gaps by means of activities introduced in the flight booking process to achieve compliance, validated by expert opinion from senior staff members of Airline’s contact center
- …
