An approach for developing comparative security metrics for healthcare organizations

Said Jafari, F. Mtenzi, Ronan Fitzpatrick, B. O'Shea
{"title":"An approach for developing comparative security metrics for healthcare organizations","authors":"Said Jafari, F. Mtenzi, Ronan Fitzpatrick, B. O'Shea","doi":"10.1109/ICITST.2009.5402504","DOIUrl":null,"url":null,"abstract":"Information sharing among different healthcare organizations is critical for efficient and cost effective healthcare service delivery. Isolated information systems need to be interconnected to ensure information exchange. Interconnectivity increases exposure to risk of damage, loss and fraud. Security and privacy of patients' information are concerns of all healthcare organizations. These concerns hinder the willingness to share data across different organizations. An objective assessment of organizational security posture is required in order to build trust among interconnected systems. Security metrics are a collection of several measurements taken at different points in time, compared against baselines and interpreted to reveal an understanding. They provide insight, improve performance and accountability, and can reveal the overall security posture of organization. The current security assessment practices focus either on measuring security programme effectiveness, auditing or assessment of individual information systems components like networks and software. These practices are not sufficient to reveal the overall security posture of organization. Also, their assessment results are not meaningfully comparable among different organizations. In this paper we propose an approach for developing security metrics to be used for assessing security posture of healthcare organizations. The metrics for this approach shall not be tailored to any specific organization to ensure comparable results.","PeriodicalId":251169,"journal":{"name":"2009 International Conference for Internet Technology and Secured Transactions, (ICITST)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-11-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 International Conference for Internet Technology and Secured Transactions, (ICITST)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITST.2009.5402504","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

Information sharing among different healthcare organizations is critical for efficient and cost effective healthcare service delivery. Isolated information systems need to be interconnected to ensure information exchange. Interconnectivity increases exposure to risk of damage, loss and fraud. Security and privacy of patients' information are concerns of all healthcare organizations. These concerns hinder the willingness to share data across different organizations. An objective assessment of organizational security posture is required in order to build trust among interconnected systems. Security metrics are a collection of several measurements taken at different points in time, compared against baselines and interpreted to reveal an understanding. They provide insight, improve performance and accountability, and can reveal the overall security posture of organization. The current security assessment practices focus either on measuring security programme effectiveness, auditing or assessment of individual information systems components like networks and software. These practices are not sufficient to reveal the overall security posture of organization. Also, their assessment results are not meaningfully comparable among different organizations. In this paper we propose an approach for developing security metrics to be used for assessing security posture of healthcare organizations. The metrics for this approach shall not be tailored to any specific organization to ensure comparable results.
为医疗保健组织开发比较安全度量的方法
不同医疗保健组织之间的信息共享对于高效且具有成本效益的医疗保健服务交付至关重要。孤立的信息系统需要相互连接,以确保信息交换。互联性增加了遭受损害、损失和欺诈的风险。患者信息的安全和隐私是所有医疗保健组织关注的问题。这些担忧阻碍了在不同组织之间共享数据的意愿。为了在相互连接的系统之间建立信任,需要对组织安全状态进行客观评估。安全度量是在不同时间点进行的几个度量的集合,与基线进行比较并进行解释以揭示理解。它们提供洞察力,改进性能和责任,并且可以揭示组织的整体安全状态。目前的安全评估实践侧重于衡量安全方案的有效性,审计或评估单个信息系统组件,如网络和软件。这些实践不足以揭示组织的整体安全状态。此外,他们的评估结果在不同的组织之间没有意义的可比性。在本文中,我们提出了一种开发用于评估医疗保健组织安全状态的安全度量的方法。该方法的度量标准不应针对任何特定的组织进行定制,以确保可比较的结果。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信