2608004855
  • Open Access
  • Article

Privacy Risk Assessment Framework for Information System

  • Raisa Islam *,   
  • Dongwan Shin

Received: 21 Jul 2026 | Revised: 06 Aug 2026 | Accepted: 07 Aug 2026 | Published: 01 Sep 2026

Abstract

Privacy risk assessment is difficult due to uncertainty, incomplete information, and the evolving nature of modern information systems. Existing methods often rely on precise probabilities or stochastic models that do not adequately capture epistemic uncertainty or conflicting evidence. This paper presents a structured Privacy Risk Assessment framework based on the Evidential Reasoning Model and Dempster-Shafer belief theory. The framework decomposes a risk object into hierarchical components, assertions, and evidence, enabling extensible and fine-grained risk computation. Dempster–Shafer theory aggregates heterogeneous evidence while explicitly representing belief, disbelief, and uncertainty, and the model supports incremental updates without full recomputation. A case study using a smart grid environment implementing the Green Button Initiative demonstrates that the approach provides systematic, transparent, and computationally efficient privacy risk evaluation in complex data-sharing systems.

References 

  • 1.

    Cuijpers, C.; Koops, B.-J. Smart Metering and Privacy in Europe: Lessons from the Dutch Case. In European Data Protection; Gutwirth, S., Leenes, R., de Hert, P., et al., Eds.; Springer: Dordrecht, The Netherlands, 2012; pp. 269–293.

  • 2.

    Javaid, M.; Haleem, A.; Singh, R.P.; et al. Towards Insighting Cybersecurity for Healthcare Domains: A Comprehensive Review of Recent Practices and Trends. Cyber Secur. Appl. 2023, 1, 100016.

  • 3.

    Quinn, K. Why We Share: A Uses and Gratifications Approach to Privacy Regulation in Social Media Use. J. Broadcast. Electron. Media 2016, 60, 61–86.

  • 4.

    California Consumer Privacy Act of 2018. Available online: https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&part=4.&lawCode=CIV&title=1.81.5 (accessed on 5 April 2026).

  • 5.

    Children’s Online Privacy Protection Rule (“COPPA”). Available online: https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa (accessed on 5 April 2026).

  • 6.

    Federal Information Security Modernization Act of 2014. Available online: https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act (accessed on 5 April 2026).

  • 7.

    Health Insurance Portability and Accountability Act of 1996 (HIPAA). Available online: https://www.cdc.gov/phlp/php/resources/health-insurance-portability-and-accountability-act-of-1996-hipaa.html (accessed on 5 April 2026).

  • 8.

    Zhou, M.; Liu, X.B.; Yang, J.B.; et al. A Revised Evidential Reasoning Model Based on Interval Information. In Proceedings of the 2009 Sixth International Conference on Fuzzy Systems and Knowledge Discovery, Tianjin, China, 14–16 August 2009; Volume 4, pp. 239–243.

  • 9.

    Van der Bles, A.M.; van der Linden, S.; Freeman, A.L.J.; et al. Communicating Uncertainty About Facts, Numbers and Science. R. Soc. Open Sci. 2019, 6, 181870.

  • 10.

    Freund, J.; Jones, J. Measuring and Managing Information Risk: A FAIR Approach; Butterworth-Heinemann: Woburn, MA, USA, 2014.

  • 11.

    Cronk, R.J.; Shapiro, S.S. Quantitative Privacy Risk Analysis. In Proceedings of the 2021 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Vienna, Austria, 6–10 September 2021; pp. 340–350.

  • 12.

    De, S.; Metayer, D. PRIAM: A Privacy Risk Analysis Methodology. In Data Privacy Management and Security Assurance; Springer International Publishing: Cham, Switzerland, 2016; pp. 221–229.

  • 13.

    Yucel, G.; Cebi, S.; Hoege, B.; et al. A Fuzzy Risk Assessment Model for Hospital Information System Implementation. Expert Syst. Appl. 2012, 39, 1211–1218.

  • 14.

    Abdymanapov, S.A.; Muratbekov, M.; Altynbek, S.; et al. Fuzzy Expert System of Information Security Risk Assessment on the Example of Analysis Learning Management Systems. IEEE Access 2021, 9, 156556–156565.

  • 15.

    Pokoradi, L. Fuzzy Logic-Based Risk Assessment. Acad. Appl. Res. Mil. Sci. 2002, 1, 63–73.

  • 16.

    Al Sharif, R.; Pokharel, S. Risk Analysis with the Dempster-Shafer Theory for Smart City Planning: The Case of Qatar. Electronics 2021, 10, 3080.

  • 17.

    Tang, Y.; Wang, L.; Yang, L.; et al. Information Security Risk Assessment Method Based on Cloud Model. In Proceedings of the 25th IET Irish Signals & Systems Conference 2014 and 2014 China-Ireland International Conference on Information and Communications Technologies (ISSC 2014/CIICT 2014), Limerick, Ireland, 26–27 June 2014; pp. 258–262.

  • 18.

    Levy, M. A Novel Framework for Data Center Risk Assessment. In Proceedings of the 2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON), New York, NY, USA, 28–31 October 2020; pp. 0148–0154.

  • 19.

    Sion, L.; Van Landuyt, D.; Wuyts, K.; et al. Privacy Risk Assessment for Data Subject-Aware Threat Modeling. In Proceedings of the 2019 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, 19–23 May 2019; pp. 64–71.

  • 20.

    Haas, P.J. Monte Carlo Methods for Uncertain Data. In Encyclopedia of Database Systems; Liu, L., O¨ zsu, M.T., Eds.; Springer: New York, NY, USA, 2018; pp. 2299–2306.

  • 21.

    Wairimu, S.; Fritsch, L. Modelling Privacy Harms of Compromised Personal Medical Data—Beyond Data Breach. In Proceedings of the 17th International Conference on Availability, Reliability and Security, Vienna, Austria, 23–26 August 2022; pp. 1–9.

  • 22.

    Asif,W.; Ray, I.G.; Rajarajan, M. An Attack Tree Based Risk Evaluation Approach for the Internet of Things. In Proceedings of the 8th International Conference on the Internet of Things, Santa Barbara, CA, USA, 15–18 October 2018; pp. 1–8.

  • 23.

    Markovic, M.; Asif, W.; Corsar, D.; et al. Towards Automated Privacy Risk Assessments in IoT Systems. In Proceedings of the 5th Workshop on Middleware and Applications for the Internet of Things, Rennes, France, 10–11 December 2018; pp. 15–18.

  • 24.

    Wu, T.; Zhao, G. A New Security and Privacy Risk Assessment Model for Information System Considering Influence Relation of Risk Elements. In Proceedings of the 2014 Ninth International Conference on Broadband and Wireless Computing, Communication and Applications, Guangdong, China, 8–10 November 2014; pp. 233–238.

  • 25.

    Wang, L.; Wang, B.; Peng, Y. Research the Information Security Risk Assessment Technique Based on Bayesian Network. In Proceedings of the 2010 3rd International Conference on Advanced Computer Theory and Engineering (ICACTE), Chengdu, China, 20–22 August 2010; Volume 3, pp. V3-600–V3-604.

  • 26.

    Ke, C.; Wu, J.; Xiao, F.; et al. A Privacy Risk Assessment Scheme for Fog Nodes in Access Control System. IEEE Trans. Reliab. 2022, 71, 1513–1526.

  • 27.

    Pellungrini, R.; Pappalardo, L.; Simini, F.; et al. Modeling Adversarial Behavior Against Mobility Data Privacy. IEEE Trans. Intell. Transp. Syst. 2022, 23, 1145–1158.

  • 28.

    Wang, Y.; Aghasaryan, A.; Shrihari, A.; et al. Intelligent Reactive Access Control for Moving User Data. In Proceedings of the 2011 IEEE Third International Conference on Privacy, Security, Risk and Trust and 2011 IEEE Third International Conference on Social Computing, Boston, MA, USA, 9–11 October 2011; pp. 942–950.

  • 29.

    Sun, L.; Srivastava, R.; Mock, T. An Information Systems Security Risk Assessment Model Under Dempster-Shafer Theory of Belief Functions. J. Manage. Inf. Syst. 2006, 22, 109–142.

  • 30.

    Dempster, A.P. A Generalization of Bayesian Inference. J. R. Stat. Soc. Ser. B Methodol. 1968, 30, 205–232.

  • 31.

    Shafer, G. A Mathematical Theory of Evidence; Princeton University Press: Princeton, NJ, USA, 1976; Volume 42.

  • 32.

    Shenoy, P.P. On Distinct Belief Functions in the Dempster-Shafer Theory. In Proceedings of the Thirteenth International Symposium on Imprecise Probability: Theories and Applications, Oviedo, Spain, 11–14 July 2023; Volume 215,pp. 426–437.

  • 33.

    Islam, R.; Cerny, T.; Shin, D. Ontology-Based User Privacy Management in Smart Grid. In Proceedings of the 37th ACM/SIGAPP Symposium on Applied Computing, Online, 25–29 April 2022; pp. 174–182.

Share this article:
How to Cite
Islam, R.; Shin, D. Privacy Risk Assessment Framework for Information System . Pragmatic Cybersecurity 2026, 1 (3), 15. https://doi.org/10.53941/pc.2026.100015.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.