【24h】

Towards a Healthcare Cybersecurity Certification Scheme

机译:迈向医疗保健网络安全认证计划

获取原文

摘要

The EU Cybersecurity Act introduces cybersecurity certification framework for ICT products, services and processes. Following ENISA’s EUCC (the Common Criteria based European candidate cybersecurity certification scheme), we provide the Security Problem and identify Security Requirements of a healthcare specific product through a Protection Profile. We consult ENISA’s reports to identify the most impactful assets in healthcare that should be prioritized for certification. We select a sub-category system of Clinical Information Systems, such as Picture Archiving and Communication System (PACS) for Protection Profile. Based on five use-cases of PACS, we define the Security Problem (assumptions, organizational security policies, threats) and we elaborate the Security Objectives. We, further, conduct a sector specific analysis of challenges and threats in healthcare sector to supplement the PACS specific threats. We detail Security Objectives from the Cybersecurity Act, and we offer a combination of these two elements, the broader scope of threats and objectives, as a baseline for future Protection Profiles of healthcare specific products. We further provide PACS specific Security Functional Requirements, and we conclude with a guideline for selecting suitable Security Assurance Requirements.
机译:欧盟网络安全法介绍了ICT产品,服务和流程的网络安全认证框架。遵循ENISA的EUCC(基于常见的欧洲候选网络安全认证计划),我们提供安全问题,并通过保护概况确定医疗保健特定产品的安全要求。我们咨询ENISA的报告,以确定应优先认证的医疗保健中最有影响力的资产。我们选择一个用于保护概况的临床信息系统的子类别系统,例如图像存档和通信系统(PACS)。根据PACS的五个使用情况,我们定义了安全问题(假设,组织安全政策,威胁),我们详细说明了安全目标。此外,我们进一步开展了对医疗部门的挑战和威胁进行了特定的分析,以补充PACS特定威胁。我们从网络安全法中详细介绍了安全目标,我们提供了这两个要素的组合,威胁和目标的更广泛的范围,作为医疗保健特定产品的未来保护概况的基准。我们进一步提供了PACS特定的安全功能要求,我们通过指导结束了选择适当的安全保障要求。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号