Information security concepts and practices: the case of a provincial multi-specialty hospital

被引:10
作者
Cavalli, E [1 ]
Mattasoglio, A
Pinciroli, F
Spaggiari, P
机构
[1] CILEA Interuniv Consortium Informat & Commun Tech, Informat Secur Syst Management Div, Milan, Italy
[2] Politecn Milan, Dipartimento Bioingn, Ist Ingn Biomed, Italian Natl Res Council, Milan, Italy
[3] E Morelli Publ Hosp, Sondalo Sondrio, Italy
关键词
information security; health care; multi-specialty hospital;
D O I
10.1016/j.ijmedinf.2003.12.008
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, major and widely accepted information security under-standings and achievements confirm that the problem is complex. They clarify that technologies are fundamental toots, but management processes have even bigger relevance, as also prestigious international magazines dossier clearly explained recently. Such a magazine attention outlines the wide impact that the subject has on watchful decision makers. ISO17799 is an emerging standard in information security. In principle there are no reasons for considering it not applicable to the health care sector. In practice, because of both the just conceptual level of the standard and the peculiarities of the health care data and institutions, a lot of analysis and design work need to be invested any time a health care institution decides to deal with the subject. CEN/ENV 12924 is another emerging standard certainly more on the spot of the health care. Nevertheless, it also asks for evident further investigation. The practical case of information security. design, implementation, management, and auditing inside a multi-specialty provincial Italian hospital will be described. (C) 2003 Elsevier Ireland Ltd. All rights reserved.
引用
收藏
页码:297 / 303
页数:7
相关论文
共 8 条
[1]   Law and standards [J].
Allaert, FA ;
Barber, B .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2000, 60 (02) :99-103
[2]   Security of the distributed electronic patient record: a case-based approach to identifying policy issues [J].
Anderson, JG .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2000, 60 (02) :111-118
[3]  
*BRIT STAND I, 2002, 77992 BS BRIT STAND
[4]  
*BSI, IT BAS PROT MAN
[5]  
*EUR COMM STAND, 12924 CENENV EUR COM
[6]  
*INT ORG STAND, 2000, 17799 ISO
[7]  
*ROYAL CAN MOUNT P, 1994, GUID THREAT RISK ASS
[8]  
2000, ECONOMIST 1026, P3