Impact of Cyber Maturity Level on Health Sector

Mert Özarar, Asuman Akansu, Burkay Hasbay
{"title":"Impact of Cyber Maturity Level on Health Sector","authors":"Mert Özarar, Asuman Akansu, Burkay Hasbay","doi":"10.1109/ISCTURKEY53027.2021.9654395","DOIUrl":null,"url":null,"abstract":"The development of technology has accelerated the digital transformation in the health sector. As a result of digitization, the increasing network connections of devices and the transport of health data between different environments can leave medical devices and data vulnerable to new cybersecurity vulnerabilities. As cyber attacks to be carried out using these vulnerabilities may cause consequences that may threaten human life, the implementation of an effective cyber security is of critical importance in the health sector, as in other sectors. The fact that the focus of the institutions / organizations in the health sector is on the treatment of patients causes the necessary investment in cyber security to not be provided. In this case, it is unclear what the information security / cyber security risks in health systems are, what can be done to reduce these risks, how health data should be protected or how it can affect the institution when exposed to a cyber attack, and how much the existing security measures will protect the institution / organization. For this reason, institutions/organizations should be aware of their cyber security levels and increase their resilience against these attacks in order to minimize the impact of cyber security attacks on their institutions. In this paper, the Cyber Maturity Level Determination Method, which is a method that institutions/organizations can apply to increase their cyber security resilience, is recommended. In accordance with this method, institutions/organizations should measure their current cyber maturity level and increase their maturity by taking effective security measures. The Cyber Maturity Level Determination Method offers a method by which each institution/organization can determine and increase their maturity with a unique configuration by considering all of them without focusing on any of the good practices.","PeriodicalId":383915,"journal":{"name":"2021 International Conference on Information Security and Cryptology (ISCTURKEY)","volume":"111 2 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-12-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Conference on Information Security and Cryptology (ISCTURKEY)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISCTURKEY53027.2021.9654395","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The development of technology has accelerated the digital transformation in the health sector. As a result of digitization, the increasing network connections of devices and the transport of health data between different environments can leave medical devices and data vulnerable to new cybersecurity vulnerabilities. As cyber attacks to be carried out using these vulnerabilities may cause consequences that may threaten human life, the implementation of an effective cyber security is of critical importance in the health sector, as in other sectors. The fact that the focus of the institutions / organizations in the health sector is on the treatment of patients causes the necessary investment in cyber security to not be provided. In this case, it is unclear what the information security / cyber security risks in health systems are, what can be done to reduce these risks, how health data should be protected or how it can affect the institution when exposed to a cyber attack, and how much the existing security measures will protect the institution / organization. For this reason, institutions/organizations should be aware of their cyber security levels and increase their resilience against these attacks in order to minimize the impact of cyber security attacks on their institutions. In this paper, the Cyber Maturity Level Determination Method, which is a method that institutions/organizations can apply to increase their cyber security resilience, is recommended. In accordance with this method, institutions/organizations should measure their current cyber maturity level and increase their maturity by taking effective security measures. The Cyber Maturity Level Determination Method offers a method by which each institution/organization can determine and increase their maturity with a unique configuration by considering all of them without focusing on any of the good practices.
网络成熟度水平对卫生部门的影响
技术的发展加速了卫生部门的数字化转型。数字化的结果是,设备网络连接的增加以及不同环境之间健康数据的传输可能使医疗设备和数据容易受到新的网络安全漏洞的影响。由于利用这些漏洞进行的网络攻击可能造成可能威胁人类生命的后果,因此,与其他部门一样,在卫生部门实施有效的网络安全至关重要。卫生部门的机构/组织将重点放在患者的治疗上,这一事实导致无法提供必要的网络安全投资。在这种情况下,尚不清楚卫生系统中的信息安全/网络安全风险是什么,可以采取什么措施来降低这些风险,应如何保护卫生数据,或者在遭受网络攻击时如何影响机构,以及现有安全措施将在多大程度上保护机构/组织。因此,机构/组织应该意识到他们的网络安全水平,并提高他们对这些攻击的弹性,以尽量减少网络安全攻击对其机构的影响。本文推荐了网络成熟度水平确定方法,这是机构/组织可以应用的一种方法,以提高其网络安全弹性。根据该方法,机构/组织应测量其当前的网络成熟度水平,并通过采取有效的安全措施来提高其成熟度。网络成熟度水平确定方法提供了一种方法,通过该方法,每个机构/组织都可以通过考虑所有这些因素而不关注任何良好实践,以独特的配置来确定和提高其成熟度。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信