课题基金 / 基金详情

CT: Collaborative Research: Experience-Based Access Management (EBAM) for Hospital Information Technology

CT: Collaborative Research: Experience-Based Access Management (EBAM) for Hospital Information Technology
CT:协作研究:医院信息技术的基于经验的访问管理 (EBAM)
批准号:
0964063
负责人:
Bradley Malin
金额:
$39.5万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2010
资助国家:
美国
项目状态:
已结题
起止时间:
2010-04-01 至 2015-03-31

项目摘要

项目成果

Bradley Malin的其他基金

相似基金

相关文献

中文摘要
翻译
企业身份和准入管理(IAM)作为一个需要在不断变化和演变的情况下持续开展的进程,没有得到足够的重视。特别是,对于IAM如何利用企业随着时间的推移收集的经验,几乎没有正式的支持。该项目正在开发一种名为基于经验的访问管理(EBAM)的IAM生命周期模型,它提供了一套模型、技术和工具,以协调高级企业、专业和法律标准所判断的“理想”访问模型与特定于可操作的IAM系统的“强制”访问控制之间的差异。EBAM支持系统的主要组成部分是一个“预期”访问模型,该模型用于根据从访问日志和其他业务信息收集的信息来表示理想模型和强制模型之间的差异。该项目正在开发和验证一种基于使用概率信息为访问规则的设计提供信息的预期模型的方法。该项目将重点放在用于医院信息系统的EBAM上,因为这是一类特别重要的企业系统,提出了各种有趣的挑战,但也为其他类型的企业IAM系统中的类似问题提供了潜在的见解。该团队由网络安全、生物医学信息学方面的专家和一名在一家大型医院系统中担任首席医疗信息官的医生组成。该项目将演示临床经验分析如何解决具有代表性的医院中理想和强制访问控制模型之间的差距。
英文摘要
Insufficient attention has been given to enterprise Identity and Access Management (IAM) as a process that needs to be carried out on a continuing basis in the presence of change and evolution. In particular, there is little formal support for how IAM can exploit experience the enterprise collects over time. This project is developing a lifecycle model of IAM called Experience Based Access Management (EBAM) that provides a set of models, techniques, and tools to reconcile differences between the "ideal" access model, as judged by high-level enterprise, professional, and legal standards, and the "enforced" access control, specific to the operational IAM system. The principal component of an EBAM support system is an "expected" access model that is used to represent differences between the ideal and enforced models based on information collected from access logs and other operational information. The project is developing and validating an approach to the expected model based on using probabilistic information to inform the design of access rules. The project focuses on EBAM for hospital information systems since these are an especially important class of enterprise systems that present diverse and interesting challenges but also provide potential insight into similar issues in other types of enterprise IAM systems. The team consists of specialists in cyber security, biomedical informatics, and a physician who serves as chief medical information officer within a major hospital system. The project will demonstrate how analysis of clinical experience can address gaps between ideal and enforced access control models in a representative hospital.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: Workshop to Develop a Roadmap for Greater Public Use of Privacy-Sensitive Government Data
RAPID: Collaborative: A Privacy Risk Assessment Framework for Person-Level Data Sharing During Pandemics
SCH: INT: Collaborative Research: High-throughput Phenotyping on Electronic Health Records using Multi-Tensor Factorization
海外基金