【24h】

Infringo Ergo Sum

机译:折扣你

获取原文

摘要

Once upon a time a professor of computing and a father was complaining at a radiology ward. A CD with the X-rays of his son's chest had garbled images. Unfortunately, the CD burning process has been outsourced and, in compliance with e-health security policies, technicians could not see the images on the system. Only doctors could. The nurse had a decision to make: sidestep the father (send him away with empty hands to the pneumology ward) or sidestep the system (give the technician the doctor's password and thus the ability to access all images and not just this one). As a father he was happy of her decision. As a professor, this knowledge was of meager and unsatisfactory kind. Any human decision maker who experienced the need of a local IT infringement in order to achieve her business goals knows that she is offered only the choice between strict compliance (and failure of business goals) or global violation (and failure of security goals). Software engineers do not simply know how to deal with infringements. I believe that a different alternative should be possible. The goal of this paper is to sketch the challenges of such unexplored scientific alternative. Access Control, Infringement management, Human Factors, Requirements, Security, Socio-Technical Systems
机译:曾几何时,一位计算教授和父亲在抱怨辐射病房。与他儿子的胸部的X射线的CD有乱码的图像。不幸的是,CD燃烧过程已经外包,并遵守电子健康安全政策,技术人员看不到系统上的图像。只有医生可以。护士决定了:父亲(用空手而归地送他的气球病房)或索引系统(给技术人员的密码,从而能够访问所有图像而不是这个)。作为父亲,他对她的决定感到高兴。作为教授,这种知识是微薄和不满意的。任何经历本地IT侵权行为的人类决策者,以实现其业务目标的人知道,她只提供了严格的合规性(以及业务目标失败)或全球违规(以及安全目标未能)之间的选择。软件工程师不仅仅知道如何处理侵权。我相信应该有不同的替代方案。本文的目标是绘制如此未开发的科学替代品的挑战。访问控制,侵权管理,人为因素,要求,安全,社会技术系统

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号