標題: | Study on applying ISO/DIS 27799 to medical industry's ISMS |
作者: | Farn, Kwo-Jean Hwang, Jiann-Ming Lin, Shu-Kuo 資訊管理與財務金融系 註:原資管所+財金所 Department of Information Management and Finance |
關鍵字: | CNS;HIPAA;HISPP/GD;risk appetite;information governance;health information security;information security management system (ISMS) |
公開日期: | 2007 |
摘要: | At present, as medical care sites use more and more IT system, information systems have come to play an important role in the business operation of medical organizations. It is an important goal for management at medical organization in Taiwan to keep the security of medical informatics. HIPAA had been run about ten years in USA, thought its efficiency has still remained to be seen, HIPAA has become the benchmark of the information governance in the information security of medical industry. The Department of Health of Taiwan had adapted from HIPAA and issued the HISPP/GD that included 9 principles and 12 articles altogether. This text will probe into the ISO/DIS 27799, the feasibility of applying it to the management of domestic medical organization and the corresponding detail of ISMS. By this way, we hope that Taiwan's medical organization can build a medical information system and manageable environment that according with the security requirements of confidentiality, integrality and availability. |
URI: | http://hdl.handle.net/11536/9988 |
ISBN: | 978-960-8457-66-9 |
ISSN: | 1790-5117 |
期刊: | Proceedings of the 6th WSEAS International Conference on Applied Computer Science |
起始頁: | 630 |
結束頁: | 635 |
顯示於類別: | 會議論文 |