Installing an appropriate information security policy

被引:23
作者
Gaunt, N [1 ]
机构
[1] Plymouth Hosp NHS Trust, Publ Hlth Lab, Plymouth PL6 8DH, Devon, England
关键词
information security; security policy; soft systems methodology; security awareness; data protection;
D O I
10.1016/S1386-5056(98)00022-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Security of personal health care is of concern to patients, health care staff and informaticians alike. Nevertheless, their awareness of the appropriate measures for protection of such data have been found wanting. The development and implementation of an information and security policy in the health care environment must therefore lake into account the attitudes of staff and their educational needs. The approach adopted in one large District General Hospital was to combine risk analysis with surveys of users attitudes to proposed measures and a participational approach to development of security procedures using an adaption of the ETHICS soft systems methodology. As a result of several years of effort, a 'security culture' has begun to emerge in the organization. However, this can only be sustained by continual promotion of the policy and a willingness to adapt procedures to suit the operating environment. (C) 1998 Elsevier Science Ireland Ltd. All rights reserved.
引用
收藏
页码:131 / 134
页数:4
相关论文
共 4 条
[1]  
*BRIT STAND I, 1996, BS7799
[2]  
FRANCE FHR, 1994, INT J BIOMED COMPUT, V35, P189
[3]   Assessing staff attitudes towards information security in a European healthcare establishment [J].
Furnell, SM ;
Gaunt, PN ;
Holben, RF ;
Sanders, PW ;
Stockel, CT ;
Warren, MJ .
MEDICAL INFORMATICS, 1996, 21 (02) :105-112
[4]  
WARREN MJ, 1994, INT J BIOMED COMPUT, V35, P269