ENV 13608-1-2000 en Health Informatics - Security for Healthcare Communication - Part 1 Concepts and Terminology《健康信息学 保健通讯安全性 第1部分 概念和术语》.pdf
《ENV 13608-1-2000 en Health Informatics - Security for Healthcare Communication - Part 1 Concepts and Terminology《健康信息学 保健通讯安全性 第1部分 概念和术语》.pdf》由会员分享,可在线阅读,更多相关《ENV 13608-1-2000 en Health Informatics - Security for Healthcare Communication - Part 1 Concepts and Terminology《健康信息学 保健通讯安全性 第1部分 概念和术语》.pdf(70页珍藏版)》请在麦多课文档分享上搜索。
1、DRAFT FOR DEVELOPMENT Health informatics - Security for Healthcare communication - Part 1: Concepts and terminology ICs 01.040.35; 36.240.80 NO COPYING WITIIouT BSI PERMISSION EXCEPT AS PERMITTED BY COPYRIGHT LAW DD ENV 1360 35.040; 35.240.80 English version Health informatics - Security for healthc
2、are communication - Part 1 : Concepts and terminology This European Prestandard (ENV) was approved by CEN on 29 July 1999 as a prospective standard for provisional application. The period of validity of this ENV is limited initially to three years. Ater two years the members of CEN will be requested
3、 to submit their comments, particularly on the question whether the ENV can be converted into a European Standard. CEN members are required to announce the existence of this ENV in the same way as for an EN and to make the ENV available promptly at national level in an appropriate form. It is permis
4、sible to keep conflicting national standards in force (in parallel to the ENV) until the final decision about the possible conversion of the ENV into an EN is reached. CEN members are the national standards bodies of Austria, Belgium, Czech Republic, Denmark, Finland, France, Germany, Greece, Icelan
5、d, Ireland, Italy, Luxembourg, Netherlands, Norway, Portugal, Spain, Sweden, Switzerland and United Kingdom. EUROPEAN COMMITTEE FOR STANDARDIZATION COMITE EUROPEEN DE NORMALISATION EUROPISCHES KOMITEE FR NORMUNG Central Secretariat: rue de Stassar, 36 8-1050 Brussels Q 2000 CEN All rights of exploit
6、ation in any form and by any means reserved worldwide for CEN national Members. Ref. No. ENV 13608-1 2000 E - STD.BSI DD ENV L3608-L-ENGL 2000 D Lb24hh9 0858821 034 Page 2 ENV 13608-1:2000 Contents Foreword “ 3 Introductio. . 3 1 Scope . 6 2 Normative references . 7 3 Definitions . 8 4 Symbols and A
7、bbreviations 16 5 6 Healthcare Communication Protection Profile Concepts . 17 Architecture of the Policy Bridging Model (PBM) . 26 Annex A (informative): Communication Protection Profile examples and refinements . 34 Annex B (informative): SEC-COM Part 2 Secure Healthcare Data Objects u . 40 Annex C
8、 (informative): SEC-COM Part 3: Secure Data Channels 42 Annex D (informative): ISO/OSI 7498-2 Information processing systems . Open Systems Interconnection . Basic Reference Model . Part2: Security Architecture 44 Annex E (informative): ITU/CCT X.435 Message Handling System: Electronic Data Intercha
9、nge Messaging System (Recommendation X.435) and IT/CCITT F.435 Message Handling Services: Electronic Data Interchange Message Service (Recommendation F.435) . 46 Annex F (informative): IS0 9735 EDIFACT Application levei syntax nes Electronic data interchange for administration. commerce and trpo rt:
10、 . 49 Annex G (informative) ENV 12924:1997: Medical Informatics . Security Categohtion and Protection for Healthcare Information Sys terns . , 51 Annex H (informative): Distribution Rules (CENTC25yWGl N98-32 PTOB) 53 Annex I (informative): HL7 . (, 55 Annex J (informative): CORBA . 57 Annex K (infor
11、mative): Common Criteria 59 Annex L (informative): Introduction to cryptography . “ 61 Bibliography “ STD=BSI DD ENV 13608-1-ENGL 2000 I 1624669 0858822 T70 Page 3 ENV 13608-1:2000 Foreword This European Prestandard has been prepared by Technical Committee CENfC 251 “Health informatics“, the secreta
12、riat of which is held by SIS. According to the CENKENELEC Internal Regulations, the national standards organizations of the following countries are bound to announce this European Prestandard: Austria, Belgium, Czech Republic, Denmark, Finland, France, Germany, Greece, Iceland, Ireland, Italy, Luxem
13、bourg, Netherlands, Norway, Portugal, Spain, Sweden, Switzerland and the United Kingdom. This multipart standard consists of the following parts, under the general title Security for Healthcare Communication (SEC- COM): - - - Part 1: Concepts and Terminology Part 2: Secure Data Objects Part 3: Secur
14、e Data Channels This standard is designed to meet the demands of the Technical Report CEN/TC25l/N98-110 Health Informatics - Framework for security protection of health care communication. This standard was drafted using the conventions of the ISODEC directive Part 3. All annexes are informative. In
15、troduction This SEC-COM standard series on Security for healthcare communication can be applied to a wide range of communication protocols and information system applications relevant to healthcare, though they are neither complete nor exhaustive in that respect. Part 1 - Concepts and Terminology -
16、reflects a user-requirements driven approach that provides a methodology for the analysis of the relation between 1) user needs and 2) a technological solution. It begins with a standardised way of expressing user needs, continues through technology-oriented successive refinements of the correspondi
17、ng required security solutions and ends with a standard-oriented map of the corresponding recommended security solutions. Such a method can be utilised in many ways, out of which two important usages are: 1. 2. as a common tool for breaking down user needs into technological solutions, through a pro
18、cess/journey of close collaboration between users and security experts, and through using this common method in the standardization process, establishing a link between a defined set of user needs and a technological standard, a link that carries an a priori assurance on the effectiveness of the tec
19、hnological standards in terms of complying with the user needs. Such an a priori assurance will be of special value for the user that do not want to exercise the method in detail on his own, but merely want to benejit from an established link between a set of user needs that helshe can recognise, an
20、d the existence of an implementation standard. Readers without a background in communications security are referred to Annex L. The methodology is organised by means of a matrix, and the path through this matrix from the user needs to a technological solution may be viewed as the standard for the sp
21、ecification of a Communication Protection Profile (CPP), according to CENfC25 1/N98-110. It is of paramount importance for the understanding of this methodology to recognise that it comprises a journey from user needs to detailed technological specifications, and that several distinct perspectives a
22、nd contexts are undertaken along this journey. In particular, it is important to recognise that commonly used (already existing, e.g. ISO) standards are comparable to only a subset of the total number of contexts defined by the method. E.g. it has been necessary to introduce the concept of auditabil
23、ity for the user need context, because the more commonly used notion of accountability is perceived to have a more limited and technical constitution. Diferent user views will imply different patterns of use of the matrix. For standardization purposes (to constitute a valid CPP), the matrix must be
24、filled out in detail (however only in those parts that are applicable for a selection of STD-BSI DD ENV L3bOB-L-ENGL 2000 Lb24bb9 0856823 907 W Page 4 user needs). This process provides some level of assurance that the actual technological solution i an deetive representation of the user needs defin
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
10000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ENV1360812000ENHEALTHINFORMATICSSECURITYFORHEALTHCARECOMMUNICATIONPART1CONCEPTSANDTERMINOLOGY 健康 信息学

链接地址:http://www.mydoc123.com/p-727340.html