Nasiri Somayeh, Sadoughi Farahnaz, Tadayon Mohammad Hesam, Dehnad Afsaneh
Department of Health Information Management, School of Health Management and Information Sciences, Iran University of Medical Sciences, Tehran.
Health Management and Economics Research Center, School of Health Management and Information Sciences, Iran University of Medical Sciences, Tehran, Iran.
Acta Inform Med. 2019 Dec;27(4):253-258. doi: 10.5455/aim.2019.27.253-258.
Internet of Things (IoT), which provides smart services and remote monitoring across healthcare systems according to a set of interconnected networks and devices, is a revolutionary technology in this domain. Due to its nature to sensitive and confidential information of patients, ensuring security is a critical issue in the development of IoT-based healthcare system.
Our purpose was to identify the features and concepts associated with security requirements of IoT in healthcare system.
A survey study on security requirements of IoT in healthcare system was conducted. Four digital databases (Web of Science, Scopus, PubMed and IEEE) were searched from 2005 to September 2019. Moreover, we followed international standards and accredited guidelines containing security requirements in cyber space.
We identified two main groups of security requirements including cyber security and cyber resiliency. Cyber security requirements are divided into two parts: CIA Triad (three features) and non-CIA (seven features). Six major features for cyber resiliency requirements including reliability, safety, maintainability, survivability, performability and information security (cover CIA triad such as availability, confidentiality and integrity) were identified.
Both conventional (cyber security) and novel (cyber resiliency) requirements should be taken into consideration in order to achieve the trustworthiness level in IoT-based healthcare system.
物联网(IoT)通过一组互联的网络和设备在医疗系统中提供智能服务和远程监控,是该领域的一项革命性技术。由于其涉及患者敏感和机密信息的性质,确保安全性是基于物联网的医疗系统开发中的一个关键问题。
我们的目的是确定医疗系统中物联网安全要求相关的特征和概念。
对医疗系统中物联网的安全要求进行了一项调查研究。检索了2005年至2019年9月的四个数字数据库(科学网、Scopus、PubMed和IEEE)。此外,我们遵循了包含网络空间安全要求的国际标准和认可指南。
我们确定了安全要求的两个主要类别,包括网络安全和网络弹性。网络安全要求分为两部分:CIA三元组(三个特征)和非CIA(七个特征)。确定了网络弹性要求的六个主要特征,包括可靠性、安全性、可维护性、生存能力、性能和信息安全(涵盖诸如可用性、保密性和完整性等CIA三元组)。
为了在基于物联网的医疗系统中达到可信赖程度,应同时考虑传统的(网络安全)和新颖的(网络弹性)要求。