{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:44:43Z","timestamp":1781106283015,"version":"3.54.1"},"reference-count":24,"publisher":"IGI Global Scientific Publishing","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2009,4,1]]},"abstract":"<p>The growth of the Internet has been accompanied by the growth of Web services (e.g., e-commerce, e-health, etc.), leading to important provisions put in place to protect the privacy of Web service users. However, it is also important to be able to estimate the privacy protection capability of a Web service provider. Such estimates would benefit both users and providers. Users would benefit from being able to choose (assuming that such estimates were made public) the service that has the greatest ability to protect their privacy (this would in turn encourage Web service providers to pay more attention to privacy). Web service providers would benefit by being able to adjust their provisions for protecting privacy until certain target capability levels of privacy protection are reached. This article presents an approach for estimating the privacy protection capability of a Web service provider and illustrates the approach with an example.<\/p>","DOI":"10.4018\/jwsr.2009092202","type":"journal-article","created":{"date-parts":[[2010,4,16]],"date-time":"2010-04-16T11:47:45Z","timestamp":1271418465000},"page":"20-41","source":"Crossref","is-referenced-by-count":4,"title":["Estimating the Privacy Protection Capability of a Web Service Provider"],"prefix":"10.4018","volume":"6","author":[{"given":"George O.M.","family":"Yee","sequence":"first","affiliation":[{"name":"Institute for Information Technology, National Research Council, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"10.4018\/jwsr.2009092202-0","unstructured":"W3C. (2002, April 15). A P3P preference exchange language 1.0 (APPEL1.0) (W3C Working Draft). Retrieved November 9, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.w3.org\/TR\/P3P-preferences\/"},{"key":"10.4018\/jwsr.2009092202-1","unstructured":"W3C. (n.d.). Platform for privacy preferences (P3P) project. Retrieved November 9, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.w3.org\/P3P\/"},{"key":"10.4018\/jwsr.2009092202-2","unstructured":"Adams, C., & Barbieri, K. (2006). Privacy enforcement in e-services environments. In G. Yee (Ed.), Privacy protection for e-services. Hershey, PA: Idea Group, Inc."},{"key":"10.4018\/jwsr.2009092202-3","unstructured":"Bauer, M. (2002). Practical threat analysis and risk management. Linux Journal, 2002(93), 9. Retrieved November 7, 2008, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.linuxjournal.com\/article\/5567"},{"key":"10.4018\/jwsr.2009092202-4","unstructured":"Carnegie Mellon Software Engineering Institute. (n.d.). Welcome to the CMMI Website. Retrieved November 9, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.sei.cmu.edu\/cmmi\/cmmi.html"},{"key":"10.4018\/jwsr.2009092202-5","unstructured":"Enright, K. P. (n.d.). Privacy audit checklist. Retrieved May 6, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/cyber.law.harvard.edu\/clinical\/privacyaudit.html"},{"key":"10.4018\/jwsr.2009092202-6","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1109\/CMPCON.1997.584680","article-title":"Privacy-enhancing technologies for the Internet. In","volume":"97","author":"I.Goldberg","year":"1997","journal-title":"Proceedings of the IEEE COMPCON"},{"key":"10.4018\/jwsr.2009092202-7","unstructured":"IBM. (2003, June 12). The enterprise privacy authorization language (EPAL 1.1). Retrieved June 2, 2007, https:\/\/2.zoppoz.workers.dev:443\/http\/www.zurich.ibm.com\/security\/enterprise-privacy\/epal\/"},{"key":"10.4018\/jwsr.2009092202-8","unstructured":"International Organization for Standardization. (n.d.). Selection and use of the ISO 9000:2000family of standards. Retrieved January 28, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.iso.org\/iso\/en\/iso9000-14000\/understand\/selection_use\/selection_use.html"},{"key":"10.4018\/jwsr.2009092202-9","doi-asserted-by":"crossref","unstructured":"Iyengar, V. S. (2002). Transforming data to satisfy privacy constraints. In Proceedings of the SIGKDD\u201902, Edmonton, Alberta (pp. 279-288).","DOI":"10.1145\/775047.775089"},{"key":"10.4018\/jwsr.2009092202-10","doi-asserted-by":"crossref","unstructured":"Karger, P. A. (2006, July). Privacy and security threat analysis of the federal employee personal identity verification (PIV) program. In Proceedings of the Second Symposium on Usable Privacy and Security, Pittsburgh, Pennsylvania (pp. 114-121).","DOI":"10.1145\/1143120.1143135"},{"key":"10.4018\/jwsr.2009092202-11","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(02)01117-3"},{"key":"10.4018\/jwsr.2009092202-12","doi-asserted-by":"publisher","DOI":"10.1145\/767193.767196"},{"key":"10.4018\/jwsr.2009092202-13","unstructured":"Lategan, F., & Olivier, M. (n.d.). PrivGuard: A model to protect private information based on its usage. Retrieved December 14, 2005, from https:\/\/2.zoppoz.workers.dev:443\/http\/mo.co.za\/open\/privgrd.pdf"},{"key":"10.4018\/jwsr.2009092202-14","unstructured":"O\u2019Neill, M., Hallam-Baker, P., MacCann, S., Shema, M., Simon, E., Watters, P. A., et al. (2003). Web services security. McGraw-Hill\/Osborne."},{"key":"10.4018\/jwsr.2009092202-15","doi-asserted-by":"crossref","unstructured":"Rippon, W. J. (2006, April). Threat assessment of IP based voice systems. In Proceedings of the 1st IEEE Workshop on VoIP Management and Security 2006, Vancouver, B.C., Canada (pp. 19-28).","DOI":"10.1109\/VOIPMS.2006.1638118"},{"key":"10.4018\/jwsr.2009092202-16","doi-asserted-by":"crossref","unstructured":"Salter, C., Saydjari, O. S., Schneier, B., & Wallner, J. (1998, September). Towards a secure system engineering methodology. In Proceedings of New Security Paradigms Workshop (pp. 2-10).","DOI":"10.1145\/310889.310900"},{"key":"10.4018\/jwsr.2009092202-17","doi-asserted-by":"crossref","unstructured":"Song, R., Korba, L., & Yee, G. (2006). Pseudonym technology for e-services. In G. Yee (Ed.), Privacy protection for e-services. Hershey, PA: Idea Group, Inc. Treasury Board of Canada. (n.d.). The privacy impact assessment guidelines: A framework to manage privacy risk. Retrieved May 6, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.tbs-sct.gc.ca\/pgol-pged\/piatp-pfefvp\/course1\/mod2\/mod2-5_e.asp","DOI":"10.4018\/978-1-59140-914-4.ch006"},{"key":"10.4018\/jwsr.2009092202-18","unstructured":"U.S. Government. (n.d.). General overview of standards for privacy of individually identifiable health information. Retrieved October 19, 2006, from https:\/\/2.zoppoz.workers.dev:443\/http\/www.hhs.gov\/ocr\/hipaa\/guidelines\/overview.pdf"},{"key":"10.4018\/jwsr.2009092202-19","doi-asserted-by":"crossref","unstructured":"Yee, G. (2006, September 18-22). Measuring privacy protection in Web services. In Proceedings of the 2006 IEEE International Conference on Web Services (ICWS 2006), Chicago (pp. 647-654).","DOI":"10.1109\/ICWS.2006.87"},{"key":"10.4018\/jwsr.2009092202-20","unstructured":"Yee, G., & Korba, L. (2003a, May 18-21). The negotiation of privacy policies in distance education. Paper presented at the 14th IRMA International Conference, Philadelphia."},{"key":"10.4018\/jwsr.2009092202-21","doi-asserted-by":"crossref","unstructured":"Yee, G., & Korba, L. (2003b, January 27-31). Bilateral e-services negotiation under uncertainty. In Proceedings of the 2003 International Symposium on Applications and the Internet (SAINT2003), Orlando, Florida (pp. 352-355).","DOI":"10.1109\/SAINT.2003.1183071"},{"key":"10.4018\/jwsr.2009092202-22","doi-asserted-by":"crossref","unstructured":"Yee, G., & Korba, L. (2004, July 6-9). Privacy policy compliance for Web services. In Proceedings of the 2004 IEEE International Conference on Web Services (ICWS 2004), San Diego (pp. 158-165).","DOI":"10.1109\/ICWS.2004.1314735"},{"issue":"1","key":"10.4018\/jwsr.2009092202-23","doi-asserted-by":"crossref","first-page":"54","DOI":"10.4018\/jebr.2005010104","article-title":"Semi-automatic derivation and use of personal privacy policies in e-business.","volume":"1","author":"G.Yee","year":"2005","journal-title":"International Journal of E-Business Research"}],"container-title":["International Journal of Web Services Research"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/www.igi-global.com\/viewtitle.aspx?TitleId=4102","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,19]],"date-time":"2025-02-19T20:29:00Z","timestamp":1739996940000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jwsr.2009092202"}},"subtitle":[""],"short-title":[],"issued":{"date-parts":[[2009,4,1]]},"references-count":24,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2009,4]]}},"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.4018\/jwsr.2009092202","relation":{},"ISSN":["1545-7362","1546-5004"],"issn-type":[{"value":"1545-7362","type":"print"},{"value":"1546-5004","type":"electronic"}],"subject":[],"published":{"date-parts":[[2009,4,1]]}}}