Risk analysis of information security in a mobile instant messaging and presence system for healthcare

被引:39
作者
Bones, Erlend
Hasuold, Per
Henriksen, Eua
Strandences, Thomas
机构
[1] Univ Hosp N Norway, Norwegian Ctr Telemed, NO-9038 Tromso, Norway
[2] Well Diagnost AS, NO-9294 Tromso, Norway
关键词
instant messaging; mobility; healthcare; information security; risk analysis;
D O I
10.1016/j.ijmedinf.2006.06.002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Introduction: Instant messaging (IM) is suited for immediate communication because messages are delivered almost in real time. Results from studies of IM use in enterprise work settings make us believe that IM based services may prove useful also within the healthcare sector. However, today's public instant messaging services do not have the level of information security required for adoption of IM in healthcare. We proposed MedlMob, our own architecture for a secure enterprise IM service for use in healthcare. MedlMob supports IM clients on mobile devices in addition to desktop based clients. Methods: Security threats were identified in a risk analysis of the MedIMob architecture. The risk analysis process consists of context identification, threat identification, analysis of consequences and likelihood, risk evaluation, and proposals for risk treatment. Results: The risk analysis revealed a number of potential threats to the information security of a service like this. Many of the identified threats are general when dealing with mobile devices and sensitive data; others are threats which are more specific to our service and architecture. Individual threats identified in the risks analysis are discussed and possible counter measures presented. Discussion: The risk analysis showed that most of the proposed risk treatment measures must be implemented to obtain an acceptable risk level; among others blocking much of the additional functionality of the smartphone. To conclude on the usefulness of this IM service, it will be evaluated in a trial study of the human-computer interaction. Further work also includes an improved design of the proposed MedIMob architecture.(c) 2006 Elsevier Ireland Ltd. All rights reserved.
引用
收藏
页码:677 / 687
页数:11
相关论文
共 19 条
[1]  
[Anonymous], 2004, EXTENSIBLE MESSAGING
[2]  
[Anonymous], OVERVIEW MOBILE DEVI
[3]  
BARDRAM JE, 2003, ECSCW 2003 EUR C COM
[4]  
BEARDMORE BD, PROCESS DRIVEN WIREL
[5]   Collaboration - a new IT-service in the next generation of regional health care networks [J].
Bruun-Rasmussen, M ;
Bernstein, K ;
Chronaki, C .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2003, 70 (2-3) :205-214
[6]   Information security concepts and practices: the case of a provincial multi-specialty hospital [J].
Cavalli, E ;
Mattasoglio, A ;
Pinciroli, F ;
Spaggiari, P .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2004, 73 (03) :297-303
[7]  
HOFTE HT, 2003, ECSCW 2003 EUR C COM
[8]  
*IMLOG, 2005, TOP 5 SEC RISKS INST
[9]  
ISAACS E, 2002, CSCW 2002 P 2002 ACM
[10]  
*ISO IEC, 2005, 17799 ISO IEC