首页> 外文会议>International Conference on Cyber Security and Protection of Digital Services >Adapting STPA-sec for Socio-technical Cyber Security Challenges in Emerging Nations: A Case Study in Risk Management for Rwandan Health Care
【24h】

Adapting STPA-sec for Socio-technical Cyber Security Challenges in Emerging Nations: A Case Study in Risk Management for Rwandan Health Care

机译:使STPA-sec适应新兴国家的社会技术网络安全挑战:卢旺达医疗保健风险管理案例研究

获取原文

摘要

Healthcare is increasingly dependent on digital systems. In emerging nations, it can be particularly hard for hospital administrators to maximize the benefits of these advances and at the same time mitigate the potential cyber security risks associated with healthcare information systems. This paper argues that limited resources, rising demand and rapidly evolving organizational structures create a pressing need for holistic approaches to address socio-technical security challenges in healthcare. We do not underestimate the technological challenges of cyber security in these countries; equally technical solutions are unlikely to be effective unless supported by holistic risk assessment. We address these problems by the use of STAMP (Systems Theoretic Accident Model and Processes) for cyber security analysis, STPA-sec. Our results show that this open-ended analytical technique requires additional methodological structure in countries where there are significant shortages of trained analysts; to guide the application of STPA-sec and also to provide common reference when individual analysts must justify their findings. It is for this reason that we explicitly integrate the US National Institute of Science and Technology (NIST) controls into STPA-sec. This provided our stakeholders with a starting point for the application of socio-technical analysis and enhanced the mainstream cyber security and risk management to provide a better fit within healthcare from emerging nations; further studies are required to determine whether such support becomes superfluous as analysts become familiar with socio-technical methods. Our arguments have been validated through extensive observation, interviews and document reviews with healthcare providers in Rwanda. In particular, we focus on an initiative to improve the cyber security of a hospital Picture Archiving and Communication System (PACS). It is our hope that the lessons learned in one country might inform cyber security risk management for healthcare across other emerging nations who face limited resources, significant public demand and an increasing range of threats.
机译:医疗保健越来越依赖于数字系统。在新兴国家,医院管理人员要最大限度地利用这些进步的收益,同时减轻与医疗保健信息系统相关的潜在网络安全风险,可能尤其困难。本文认为,有限的资源,不断增长的需求和快速发展的组织结构导致迫切需要采用整体方法来应对医疗保健中的社会技术安全挑战。我们不会低估这些国家/地区的网络安全技术挑战;同样,除非得到整体风险评估的支持,否则技术解决方案不太可能有效。我们通过使用STAMP(系统理论事故模型和流程)进行网络安全分析来解决这些问题,即STPA-sec。我们的结果表明,在缺乏训练有素的分析师的国家中,这种开放式分析技术需要额外的方法结构。指导STPA-sec的应用,并在个别分析师必须证明其发现合理性时提供共同参考。出于这个原因,我们将美国国家科学技术研究院(NIST)的控件明确集成到STPA-sec中。这为我们的利益相关者提供了应用社会技术分析的起点,并增强了主流网络安全和风险管理,以更好地适应新兴国家的医疗保健;随着分析师对社会技术方法的熟悉,需要进一步研究以确定这种支持是否变得多余。通过与卢旺达的医疗服务提供者进行广泛的观察,访谈和文件审查,我们的论点得到了证实。特别是,我们专注于一项举措,以提高医院图片存档和通信系统(PACS)的网络安全性。我们希望,在一个国家中汲取的教训可以为面临资源有限,公共需求巨大和威胁范围日益扩大的其他新兴国家的医疗保健网络安全风险管理提供信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号