<mods:mods xmlns:mods="http://www.loc.gov/mods/v3" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.loc.gov/mods/v3 http://www.loc.gov/standards/mods/v3/mods-3-7.xsd">

<mods:titleInfo>
<mods:title>A GDPR-Ready Cybersecurity and Privacy Plan for B2B SaaS Startups</mods:title>
</mods:titleInfo>

<mods:abstract>
B2B SaaS startups struggle to comply with regulatory requirements. There are many evolving standards that require documentation and controls. These requirements overwhelm startups, to the extent that they do not even attempt to comply. In fact, however, the practices of these startups often do follow best practices in security. The difficulties are in closing the gaps between requirements and practices and in creating the documentation to support the startups’ decisions. The paper investigates whether template plan and practice documents can be constructed for use by B2B SaaS startups to complete their alignment and gain GDPR compliance.
</mods:abstract>

<mods:name>
<mods:namePart>Siegel, Jonathan</mods:namePart>
<mods:role>
<mods:roleTerm authority="marcrelator" authorityURI="http://id.loc.gov/vocabulary/relators" valueURI="http://id.loc.gov/vocabulary/relators/cre">Creator</mods:roleTerm>
</mods:role>
</mods:name>

<mods:name type="personal">
<mods:namePart>Hurley, Deborah</mods:namePart>
<mods:role>
<mods:roleTerm type="text">Advisor</mods:roleTerm>
</mods:role>
</mods:name>


<mods:name type="corporate">
<mods:namePart>
Brown University. School of Professional Studies. Department of Computer Science
</mods:namePart>
<mods:role>
<mods:roleTerm type="text">Sponsor</mods:roleTerm>
</mods:role>
</mods:name>

<mods:originInfo>
<mods:copyrightDate>2019</mods:copyrightDate>
</mods:originInfo>

<mods:physicalDescription>
<mods:extent>18 p.</mods:extent>
<mods:digitalOrigin>born digital</mods:digitalOrigin>
</mods:physicalDescription>
<mods:note type="Capstone">Capstone (EMCS)--Brown University, 2019</mods:note>

<mods:subject authority="fast" authorityURI="http://id.worldcat.org/fast/872484" valueURI="http://id.worldcat.org/fast/1033711">
<mods:topic>Computer security</mods:topic>
</mods:subject>

<mods:subject authority="local">
<mods:topic> Software as a Service (SaaS)</mods:topic>
</mods:subject>

<mods:subject authority="local">
<mods:topic>General Data Protection Regulation (GDPR)</mods:topic>
</mods:subject>



<mods:typeOfResource>text</mods:typeOfResource>

<mods:genre>Critical Challenge Project</mods:genre>

<mods:accessCondition type="rights statement" xlink:href="http://rightsstatements.org/vocab/InC/1.0/">In Copyright</mods:accessCondition>
<mods:accessCondition type="restriction on access">All rights reserved. Collection is open for research.</mods:accessCondition>

<mods:language>
<mods:languageTerm authority="iso639-2b">English</mods:languageTerm>
</mods:language>

<mods:recordInfo>
<mods:recordContentSource authority="marcorg">RPB</mods:recordContentSource>
<mods:recordCreationDate encoding="iso8601">20100429</mods:recordCreationDate>
</mods:recordInfo>




<mods:identifier type="doi">10.26300/8b2q-wk84</mods:identifier></mods:mods>