首页> 外文期刊>Journal of software >Medical Organization Information Security Management Based on ISO27001 Information Security Standard
【24h】

Medical Organization Information Security Management Based on ISO27001 Information Security Standard

机译:基于ISO27001信息安全标准的医疗机构信息安全管理

获取原文
           

摘要

Most of the information security events inmedical organizations are due to improper management.This is a clear indication that the security of information isan issue related to information and communicationtechnology and a management issue as well. In a review ofliterature, most research on information security hasfocused on information and communication technologyissues, such as network security and access control; rarelyaddressing issues at the management-level. The mainpurpose of this study is to construct a mechanism for themanagement of information with regard to security as itapplies to medical organizations. This mechanism is basedon the eleven control items and one hundred thirty-threecontrol objectives of the ISO27001 information securitymanagement standard. This study analyzes and identifiesthe most common events related to information security inmedical organizations and categorizes these events as highrisk,transferable-risk, and controlled-risk to facilitate themanagement of such risk.
机译:医疗组织中的大多数信息安全事件是由于管理不当造成的。这清楚地表明,信息安全既是与信息和通信技术相关的问题,也是管理问题。在文献综述中,大多数关于信息安全的研究都集中在信息和通信技术问题上,例如网络安全和访问控制。在管理层很少解决问题。这项研究的主要目的是构建一种适用于医疗组织的安全性信息管理机制。该机制基于ISO27001信息安全管理标准的11个控制项和133个控制目标。本研究分析并确定了与信息安全医疗组织有关的最常见事件,并将这些事件分为高风险,可转移风险和可控制风险,以促进此类风险的管理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号