首页    期刊浏览 2024年07月19日 星期五
登录注册

文章基本信息

  • 标题:Medical Organization Information Security Management Based on ISO27001 Information Security Standard
  • 本地全文:下载
  • 作者:Liao, Kuo-Hsiung ; Chueh, Hao-En
  • 期刊名称:Journal of Software
  • 印刷版ISSN:1796-217X
  • 出版年度:2012
  • 卷号:7
  • 期号:4
  • 页码:792-797
  • DOI:10.4304/jsw.7.4.792-797
  • 语种:English
  • 出版社:Academy Publisher
  • 摘要:Most of the information security events in medical organizations are due to improper management. This is a clear indication that the security of information is an issue related to information and communication technology and a management issue as well. In a review of literature, most research on information security has focused on information and communication technology issues, such as network security and access control; rarely addressing issues at the management-level. The main purpose of this study is to construct a mechanism for the management of information with regard to security as it applies to medical organizations. This mechanism is based on the eleven control items and one hundred thirty-three control objectives of the ISO27001 information security management standard. This study analyzes and identifies the most common events related to information security in medical organizations and categorizes these events as high risk, transferable-risk, and controlled-risk to facilitate the management of such risk.
  • 关键词:Medical organizations;Information security;ISO27001;Risk management;Access control
国家哲学社会科学文献中心版权所有