ISO TR 11633-2-2009 Health informatics - Information security management for remote maintenance of medical devices and medical information systems - Part 2 Impl.pdf
《ISO TR 11633-2-2009 Health informatics - Information security management for remote maintenance of medical devices and medical information systems - Part 2 Impl.pdf》由会员分享,可在线阅读,更多相关《ISO TR 11633-2-2009 Health informatics - Information security management for remote maintenance of medical devices and medical information systems - Part 2 Impl.pdf(74页珍藏版)》请在麦多课文档分享上搜索。
1、 Reference number ISO/TR 11633-2:2009(E) ISO 2009TECHNICAL REPORT ISO/TR 11633-2 First edition 2009-11-15 Health informatics Information security management for remote maintenance of medical devices and medical information systems Part 2: Implementation of an information security management system (
2、ISMS) Informatique de sant Management de la scurit de linformation pour la maintenance distance des dispositifs mdicaux et des systmes dinformation mdicale Partie 2: Mise en oeuvre dun systme de management de la scurit de linformation (ISMS) ISO/TR 11633-2:2009(E) PDF disclaimer This PDF file may co
3、ntain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsi
4、bility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation p
5、arameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO 2009 All
6、 rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs member body in the country o
7、f the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyrightiso.org Web www.iso.org Published in Switzerland ii ISO 2009 All rights reservedISO/TR 11633-2:2009(E) ISO 2009 All rights reserved iiiContents Page Foreword iv Introd
8、uction.v 1 Scope1 2 Terms and definitions .1 3 Abbreviated terms.3 4 Application of ISMS to remote maintenance services.3 4.1 Overview.3 4.2 Compliance scope.5 4.3 Security policy.6 4.4 Assessing risks .6 4.5 Risks to be managed.7 4.6 Identification of risks that are not described in this part of IS
9、O/TR 11633 .8 4.7 Treating risks .8 5 Security management measures for remote maintenance services9 6 Approving residual risks 9 7 Security audit.10 7.1 Security audit of remote maintenance services.10 7.2 Recommendation of security audit by third parties 10 Annex A (informative) Example of risk ass
10、essment in remote maintenance services .11 Bibliography66 ISO/TR 11633-2:2009(E) iv ISO 2009 All rights reservedForeword ISO (the International Organization for Standardization) is a worldwide federation of national standards bodies (ISO member bodies). The work of preparing International Standards
11、is normally carried out through ISO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that committee. International organizations, governmental and non-governmental, in liaison with ISO, also take pa
12、rt in the work. ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of technical committees is to
13、prepare International Standards. Draft International Standards adopted by the technical committees are circulated to the member bodies for voting. Publication as an International Standard requires approval by at least 75 % of the member bodies casting a vote. In exceptional circumstances, when a tec
14、hnical committee has collected data of a different kind from that which is normally published as an International Standard (“state of the art”, for example), it may decide by a simple majority vote of its participating members to publish a Technical Report. A Technical Report is entirely informative
15、 in nature and does not have to be reviewed until the data it provides are considered to be no longer valid or useful. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO shall not be held responsible for identifying any or all su
16、ch patent rights. ISO/TR 11633-2 was prepared by Technical Committee ISO/TC 215, Health informatics. ISO/TR 11633 consists of the following parts, under the general title Health informatics Information security management for remote maintenance of medical devices and medical information systems: Par
17、t 1: Requirements and risk analysis Part 2: Implementation of an information security management system (ISMS) ISO/TR 11633-2:2009(E) ISO 2009 All rights reserved vIntroduction Progress and spread of technology in information and communication fields and well-arranged infrastructure based on them ha
18、ve brought various changes into modern society. In the healthcare field, information systems formerly closed in each healthcare facility are now connected by networks, and they are coming to the point of being able to facilitate mutual use of health information accumulated in each information system
19、. Such information and communication networks are spreading, not only amongst healthcare facilities but also amongst healthcare facilities and vendors of medical devices or healthcare information systems. By practicing so-called “remote maintenance services” (RMS), it becomes possible to reduce down
20、-time and lower costs. However, such connections with external organizations have come to bring healthcare facilities and vendors not only benefits but also risks regarding confidentiality, integrity and availability of information and systems, risks which previously received scant consideration. Ba
21、sed on the information offered by this part of ISO/TR 11633, healthcare facilities and RMS providers will be able to perform the following activities: clarify risks originating from using the RMS, where environmental conditions of the requesting vendor site (RSC) and maintenance target healthcare fa
22、cility site (HCF) can be selected from the catalogue in Annex A; grasp the essentials of selecting and implementing both technical and non-technical “controls” to be applied in their own facility against the risks described in this part of ISO/TR 11633; request concrete countermeasures from business
23、 partners, as this document can identify the relevant security risks; clarify the boundary of responsibility between the healthcare facility owner and the RMS provider; plan a programme for risk retention or transfer as residual risks are clarified when selecting the appropriate “controls”. By imple
24、menting the risk assessment and employing “controls” referencing this part of ISO/TR 11633, healthcare facilities owners and RMS providers will be able to obtain the following benefits: it will only be necessary to do the risk assessment for those organizational areas where this part of ISO/TR 11633
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ISOTR1163322009HEALTHINFORMATICSINFORMATIONSECURITYMANAGEMENTFORREMOTEMAINTENANCEOFMEDICALDEVICESANDMEDICALINFORMATIONSYSTEMSPART2IMPLPDF

链接地址:http://www.mydoc123.com/p-1257563.html