The CORAS approach for model-based risk management applied to a telemedicine service

نویسندگان

  • Yannis Stamatiou
  • Eva Skipenes
  • Eva Henriksen
  • Nikos Stathiakis
  • Adamantios Sikianakis
  • Eliana Charalambous
  • Nikos Antonakis
  • Ketil Stølen
  • Folker den Braber
  • Mass Soldal Lund
  • Katerina Papadaki
  • George Valvis
چکیده

The CORAS risk management process is based on the Australian standard for risk management and aims at improved methodology for precise, unambiguous, and efficient risk assessment of security critical systems. CORAS addresses security critical systems in general, but places particular emphasis on IT security. For CORAS, a system is not just technology, but also the humans interacting with the technology and all relevant aspects of the surrounding organisation and society. The use of graphical models in CORAS furthers communication between the different stakeholders of a risk assessment, and makes it easier for non-technicians to take part. Telemedicine services and electronic applications used in the health sector have a high demand for security. The medical developers, providers and users of such services and systems are important contributors in the risk assessment of these services and systems. CORAS has successfully been used to involve medical professionals in the model-based risk assessment of a telemedicine system called Tele-cardiology in Crete. This paper presents the use of the CORAS framework to assess this telemedicine system giving some conclusions on the experience gained.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The coras approach for model-based risk management applied to e-commerce domain

The CORAS project develops a practical framework for model-based risk management of security critical systems by exploiting the synthesis of risk analysis methods with semiformal specification methods, supported by an adaptable tool-integration platform. The framework is also accompanied by the CORAS process, which is a systems development process based on the integration of RUP and a standardi...

متن کامل

CORAS methodology for model-based risk asessment

This report provides the final version of the CORAS methodology for model-based risk assessment (MBRA). The CORAS methodology for MBRA ispresented in terms of concrete recommendations and layered guidelines, aswell as templates and supportive descriptions. D2.4 also provides a refinedsub-specification for the CORAS Platform. Finally, the report includes andrefines the experi...

متن کامل

A Guided Tour of the CORAS Method

This chapter presents a guided tour of the CORAS method. As illustrated by Fig. 3.1, the CORAS method is divided into eight steps. The first four of these steps are introductory in the sense that we use them to establish a common understanding of the target of the analysis, and to make the target description that will serve as a basis for the subsequent risk identification. The introductory ste...

متن کامل

Model Based Risk Management of Security Critical Systems

This paper describes a novel framework for a risk management process involving a model-based approach, developed as the main objective of CORAS (IST-200

متن کامل

Optimal Placement of Substations Based on Economic and Technical Risk Management

Design and expansion of distribution systems seems inevitable in view of the need to satisfy the rise in energy consumption in a technical and economical way. Optimal location, sizing and determining the service area of substations is one of the principle problems in expansion of distribution systems. Also uncertainty is one of the important factors that increase risk of exact decision makings....

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Studies in health technology and informatics

دوره 95  شماره 

صفحات  -

تاریخ انتشار 2003