【24h】

Safe Teleradiology: Information Assurance as Project Planning Methodology

机译:安全远程放射学:作为项目规划方法的信息保证

获取原文
获取原文并翻译 | 示例

摘要

This project demonstrates use of OCTAVE~(sm), an information security risk assessment method, as an approach to the safe design and planning of a teleradiology system. By adopting this approach to project planning, we intended to provide evidence that including information security as an intrinsic component of project planning improves information assurance and that using information assurance as a planning tool produces and improves the general system management plan. Several considerations justify this approach to planning a safe teleradiology system. First, because OCTAVE?was designed as a method for retrospectively assessing and proposing enhancements for the security of existing information management systems, it should function well as a guide to prospectively designing and deploying a secure information system such as teleradiology. Second, because OCTAVE~(sm) provides assessment and planning tools for use primarily by interdisciplinary teams from user organizations, not consultants, it should enhance the ability of such teams at the local level to plan safe information systems. Third, from the perspective of sociological theory, OCTAVE~(sm) explicitly attempts to enhance organizational conditions identified as necessary to safely manage complex technologies. Approaching information system design from the perspective of information security risk management proactively integrates health information assurance into a project's core. This contrasts with typical approaches that perceive "security" as a secondary attribute to be "added" after designing the system and with approaches that identify information assurance only with security devices and user training. The perspective of health information assurance embraces so many dimensions of a computerized health information system's design that one may successfully deploy a method for retrospectively assessing information security risk as a prospective planning tool. From a sociological perspective, this approach enhances the general conditions as well as establishes specific policies and procedures for reliable performance of health information assurance.
机译:该项目演示了将OCTAVE〜(sm)这种信息安全风险评估方法用作远程放射线系统安全设计和规划的一种方法。通过将这种方法用于项目计划,我们打算提供证据,证明将信息安全作为项目计划的内在组成部分可以改善信息保证,并且将信息保证作为计划工具可以产生并改善总体系统管理计划。有几种考虑因素证明了这种方法来规划安全的远程放射线系统。首先,由于OCTAVE?被设计为用于回顾性评估和提出增强现有信息管理系统安全性的方法,因此它应能很好地用作前瞻性设计和部署安全信息系统(如远程放射学)的指南。其次,由于OCTAVE〜(sm)提供的评估和计划工具主要供用户组织的跨学科团队使用,而不是由顾问使用,因此OCTAVE〜(sm)应该增强此类团队在本地计划安全信息系统的能力。第三,从社会学理论的角度来看,OCTAVE〜(sm)明确试图增强已确定的安全管理复杂技术所必需的组织条件。从信息安全风险管理的角度进行信息系统设计可以将健康信息保证主动地集成到项目的核心。这与在设计系统后将“安全”视为要添加的次要属性的典型方法以及仅通过安全设备和用户培训来识别信息保证的方法形成鲜明对比。健康信息保证的观点涵盖了计算机化健康信息系统设计的众多方面,以至于人们可以成功地部署一种用于回顾性评估信息安全风险的方法作为一种前瞻性计划工具。从社会学的角度来看,这种方法增强了一般条件,并建立了可靠的健康信息保证性能的特定政策和程序。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号