首页> 美国卫生研究院文献>Environmental Health and Preventive Medicine >Strategic approach to information security and assurance in health research
【2h】

Strategic approach to information security and assurance in health research

机译:卫生研究中信息安全和保证的战略方法

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Information security and assurance are an increasingly critical issue in health research. Whether health research be in genetics, new drugs, disease outbreaks, biochemistry, or effects of radiation, it deals with information that is highly sensitive and which could be targeted by rogue individuals or groups, corporations, national intelligence agencies, or terrorists, looking for financial, social, or political gains. The advents of the Internet and advances in recent information technologies have also dramatically increased opportunities for attackers to exploit sensitive and valuable information.Government agencies have deployed legislative measures to protect the privacy of health information and developed information security guidelines for epidemiological studies. However, risks are grossly underestimated and little effort has been made to strategically and comprehensively protect health research information by institutions, governments and international communities.There is a need to enforce a set of proactive measures to protect health research information locally and globally. Such measures should be deployed at all levels but will be successful only if research communities collaborate actively, governments enforce appropriate legislative measures at national level, and the international community develops quality standards, concluding treaties if necessary, at the global level.Proactive measures for the best information security and assurance would be achieved through rigorous management process with a cycle of “plan, do, check, and act”. Each health research entity, such as hospitals, universities, institutions, or laboratories, should implement this cycle and establish an authoritative security and assurance organization, program and plan coordinated by a designatedChief Security Officer who will ensure implementation of the above process, putting appropriate security controls in place, with key focus areas such aspolicies and best practices, enforcement and certification, risk assessment and audit, monitoring and incident response, awareness and training, and modern protection method and architecture. Governments should enforce a comprehensive scheme, and international health research communities should adopt standardized innovative methods and approaches.
机译:信息安全和保证是健康研究中日益重要的问题。不管健康研究是在遗传学,新药,疾病暴发,生物化学或辐射影响方面,它都处理高度敏感的信息,这些信息可能被流氓个人或团体,公司,国家情报机构或恐怖分子所针对。经济,社会或政治利益。互联网的出现和最新信息技术的发展也极大地增加了攻击者利用敏感和有价值信息的机会。政府机构已采取立法措施保护健康信息的隐私,并制定了用于流行病学研究的信息安全准则。然而,风险被严重低估了,机构,政府和国际社会在战略和全面保护卫生研究信息方面所做的工作很少。有必要采取一系列积极措施来保护本地和全球卫生研究信息。此类措施应在所有级别上部署,但只有在研究界积极合作,政府在国家层面上实施适当的立法措施,国际社会在全球范围内制定质量标准,必要时缔结条约的情况下才能成功。通过严格的管理流程以及“计划,执行,检查和采取行动”循环,可以实现最佳的信息安全性和保证。每个健康研究实体,例如医院,大学,机构或实验室,都应执行此周期,并建立一个由指定的首席安全官协调的权威性安全与保证组织,计划和计划,该官员将确保上述过程的实施,并采取适当的安全措施控制措施到位,重点关注领域,例如政策和最佳实践,执法和认证,风险评估和审计,监视和事件响应,意识和培训以及现代保护方法和体系结构。各国政府应执行一项全面计划,国际卫生研究界应采用标准化的创新方法和方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号