Monitoring information security risks within health care

Monitoring information security risks within health care
复制标题

监控医疗保健中的信息安全风险

DOI:
10.1016/j.cose.2013.04.005
复制
发表时间:
2013
影响因子:
5.6
通讯作者:
Van Deursen N
Van Deursen N
中科院分区:
计算机科学3区
文献类型:
--
作者:
Van Deursen N

文献摘要

参考文献

被引文献

相似文献

本文概述了医疗保健数据安全可能面临的风险。这些风险是通过一种新颖的信息安全方法检测到的。它基于这样的理念:信息安全风险监控应包括人类和社会因素,组织和专家之间的协作对于获取有关潜在风险的知识至关重要。该方法采用混合方法,包括对历史安全事件数据进行定量分析以及通过德尔菲研究进行专家启发。其结果是专家小组预计在不久的将来在医疗保健组织中可能出现的社会技术风险的概述。这些风险包括(除其他外):工作人员将数据资产留在无人看管的场所,从而导致这些资产丢失;工作人员共享密码以访问患者数据;工作人员将包含患者个人数据的电子邮件发送给错误的收件人,从而将数据泄露给未经授权的人员。专家小组认识到当前讨论主题(例如外包)中存在的风险,但仍然认为这些风险比更传统的信息安全风险出现的频率要低。此外,专家组没有估计云计算或RFID等新技术引起的社会技术信息安全风险的高频率发生。
This paper presents an overview of possible risks to the security of health care data. These risks were detected with a novel approach to information security. It is based on the philosophy that information security risk monitoring should include human and societal factors, and that collaboration between organisations and experts is essential to gain knowledge about potential risks. The methodology uses a mixed methods approach including a quantitative analysis of historical security incident data and expert elicitation through a Delphi study. The result is an overview of the possible socio-technical risks that a panel of experts expect to materialise in health care organisations in the near future. These risks include (amongst others): staff leaving data assets unattended on the premises and these assets consequently go missing, staff sharing passwords to access patient data and staff sending email containing personal patient data to the wrong addressee thus disclosing data to unauthorised persons. The expert panel recognized risks from current discussion topics such as outsourcing, but these risks are still considered to appear less frequently than the more traditional information security risks. Furthermore, the panel did not estimate a high frequency of occurrence of socio-technical information security risks caused by new technologies such as cloud computing or RFID.
2008 年 HIMSS 分析报告:患者数据的安全性。
DOI: --
发表时间: 2008
期刊: Journal of healthcare protection management : publication of the International Association for Hospital Security
影响因子: --
作者:
Himss
通讯作者: Himss
信息安全管理:一个棘手的研究挑战
DOI: --
发表时间: 2009
期刊: Information Security Technical Report
影响因子: --
作者:
Lizzie Coles
通讯作者: Lizzie Coles
信息安全标准关注过程的存在,而不是其内容
DOI: --
发表时间: 2006
期刊: CACM
影响因子: --
作者:
M. Siponen
通讯作者: M. Siponen
DOI: --
发表时间: 2004
期刊:
影响因子: --
作者:
S.Mitchell Williams
通讯作者: S.Mitchell Williams
计算机安全事件的通用语言
DOI: --
发表时间: 1998
期刊:
影响因子: --
作者:
J. D. Howard;T. Longstaff
通讯作者: T. Longstaff