Electronic Information Security Documentation
نویسندگان
چکیده
Effective security management depends upon good risk management, which is itself based upon a reliable risk assessment, involving data collection of all the facets influencing system risk. Such data collection is often an extremely onerous task, particularly if a substantial proportion of the required information is not adequately documented. Hence comprehensive, updated information security documentation is a keystone of good information security management. Whilst the recently emerging information security management standards provide some implicit guidance on the development of documentation; there is relatively little support available for security officers attempting to develop and maintain such documentation. Traditionally textual security documents are not necessarily the most appropriate format for describing the security of large complex, networked systems, subject to frequent updates. It has been suggested [1], [2] that a security officer’s workstation, with a database and GUIs, may present a more effective form of security documentation. However, such a tool requires a welldeveloped model of the information system and, as discussed in this paper, a standardised means of representing security entities. This paper proposes an information security model to facilitate the development of electronic security documentation. A proposed security entity classification scheme is first described. Such a classification scheme and the use of object identifiers to identify security entities greatly facilitates the development of a security officer’s workstation. The potential of the model for risk assessment and security design is described. A prototype model was developed in Visual Basic to test the concepts proposed, and a Java based model is currently under development at the City University of Hong Kong.
منابع مشابه
Nursing Care and Documentation Assistant with an Electronic Nursing Management System in Neonatal Intensive Care Unit
Background: All nursing cares require decision-making, and the ability to make the best decisions impact upon the quality of nursing care. Moreover, authenticity and accuracy of the best cares may be questioned if not recorded and reported properly and in a standard manner. We aimed to design and implement an electronic nursing managementsystem and then evaluate satisfaction of nurses with the ...
متن کاملInformation Security Requirements for Implementing Electronic Health Records in Iran
Background and Goal: ICT development in recent years has created excellent developments in human social and economic life. One of the most important opportunities to use information technology is in the medical field, that the result would be electronic health record (EHR).The purpose of this research is to investigate the effects information securi...
متن کاملInformation Security Requirements for Implementing Electronic Health Records in Iran
Background and Goal: ICT development in recent years has created excellent developments in human social and economic life. One of the most important opportunities to use information technology is in the medical field, that the result would be electronic health record (EHR).The purpose of this research is to investigate the effects information securi...
متن کاملManaging the Security of Nursing Data in the Electronic Health Record
BACKGROUND The Electronic Health Record (EHR) is a patient care information resource for clinicians and nursing documentation is an essential part of comprehensive patient care. Ensuring privacy and the security of health information is a key component to building the trust required to realize the potential benefits of electronic health information exchange. This study was aimed to manage nursi...
متن کاملEvaluation of Outpatient Electronic Prescription System Capabilities from the Perspective of Physicians in Specialized Polyclinics of Urmia Social Security Organization
Background and Aim: Electronic prescription systems can improve patient safety and the quality of health care services. These systems must provide the capabilities required to reduce medical errors and enhance the performance of health care providers. The purpose of this study is to evaluate the capabilities of the e-prescription system from the perspective of physicians in the polyclinics of t...
متن کامل