首页> 外文学位 >An Examination of an Information Security Framework Implementation Based on Agile Values to Achieve Health Insurance Portability and Accountability Act Security Rule Compliance in an Academic Medical Center: The Thomas Jefferson University Case Study.
【24h】

An Examination of an Information Security Framework Implementation Based on Agile Values to Achieve Health Insurance Portability and Accountability Act Security Rule Compliance in an Academic Medical Center: The Thomas Jefferson University Case Study.

机译:在学术医疗中心中基于敏捷价值实现健康保险可移植性和责任制法案安全规则合规性的信息安全框架实施的检验:托马斯·杰斐逊大学案例研究。

获取原文
获取原文并翻译 | 示例

摘要

Agile project management is most often examined in relation to software development, while information security frameworks are often examined with respect to certain risk management capabilities rather than in terms of successful implementation approaches. This dissertation extended the study of both Agile project management and information security frameworks by examining the efficacy of implementing a security framework using a nontraditional project management approach. Such an investigation is significant because of the high rate of failed IT projects, gaps in the current security framework implementation literature, and increased regulatory pressure on Health Insurance Portability and Accountability (HIPAA)-covered entities to become compliant with the HIPAA Security Rule.;HIPAA-covered entities have struggled to achieve HIPAA compliance since the Act's enforcement date. Specifically, academic medical centers have struggled to achieve and authoritatively document their compliance with the HIPAA Security Rule. To aid HIPAA-covered entities in confirming and documenting their HIPAA Security Rule compliance, the HITRUST Alliance has published the Common Security Framework. Thomas Jefferson University selected the Common Security Framework to help them assess and document their HIPAA Security Rule compliance. However, there is a documented gap in the literature on successful methods for implementing information security-related projects, particularly HIPAA compliance.;In this single-case case study, the author examined the implementation of an Information Security Framework based on Agile values. Specifically examined were the values of (a) individuals and interactions over processes and tools; (b) working software over comprehensive documentation; (c) customer collaboration over contract negotiation; and (d) responding to change over following a plan. The results of this investigation indicated that an information security framework implementation based on Agile values is a viable approach for successfully implementing the Common Security Framework at an academic medical center.
机译:敏捷项目管理通常是与软件开发相关的,而信息安全框架通常是针对某些风险管理能力的,而不是针对成功实施方法的。本文通过研究使用非传统项目管理方法实施安全框架的有效性,扩展了对敏捷项目管理和信息安全框架的研究。由于IT项目失败率很高,当前安全框架实施文献中的空白以及健康保险可移植性和问责制(HIPAA)覆盖的实体越来越多的监管压力以使其符合HIPAA安全规则,因此这种调查意义重大。自该法实施以来,受HIPAA约束的实体一直难以达到HIPAA的要求。具体来说,学术医学中心一直在努力实现并权威地记录其对HIPAA安全规则的遵守情况。为了帮助HIPAA涵盖的实体确认并记录其HIPAA安全规则合规性,HITRUST联盟发布了通用安全框架。托马斯·杰斐逊大学选择了通用安全框架来帮助他们评估和记录其HIPAA安全规则合规性。但是,文献中关于成功实施信息安全相关项目(尤其是HIPAA遵从性)的方法的文献中存在文献记载的空白。具体检查的是(a)个人的价值以及流程和工具之间的相互作用; (b)工作软件超过综合文件; (c)客户在合同谈判方面的合作; (d)响应遵循计划的变更。这项调查的结果表明,基于敏捷价值观的信息安全框架实施是在学术医疗中心成功实施通用安全框架的可行方法。

著录项

  • 作者

    Reis, David W.;

  • 作者单位

    Nova Southeastern University.;

  • 授予单位 Nova Southeastern University.;
  • 学科 Information Technology.;Health Sciences Health Care Management.
  • 学位 Ph.D.
  • 年度 2012
  • 页码 172 p.
  • 总页数 172
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号