Gritzalis Dimitris, Kokolakis Spyros
Dept. of Informatics, Athens University of Economics & Business, Athens, Greece.
Stud Health Technol Inform. 2003;96:105-10.
In this paper the issue of security policy development for health information systems is addressed. Security policy development involves the definition of the policy content, the analysis of the social, organisational, and technical contexts, as well as the organisation of the policy development process. We present the structure of security policies, analyse the characteristics of the HIS context, and analyse the different categories of methodologies, which can be used towards this end.
本文探讨了健康信息系统安全策略制定的问题。安全策略制定涉及策略内容的定义、社会、组织和技术背景的分析,以及策略制定过程的组织。我们介绍了安全策略的结构,分析了健康信息系统背景的特点,并分析了可用于此目的的不同方法类别。