Securing Electronic Health Records on Mobile Devices NIST SP 1800-1 Draft: Approach, Architecture, and Security Characteristics
暫譯: 在行動裝置上保護電子健康紀錄 NIST SP 1800-1 草案:方法、架構與安全特性

National Instituteof Standards

  • 出版商: CreateSpace Independ
  • 出版日期: 2017-06-01
  • 售價: $1,220
  • 貴賓價: 9.5$1,159
  • 語言: 英文
  • 頁數: 174
  • 裝訂: Paperback
  • ISBN: 1547102926
  • ISBN-13: 9781547102921
  • 相關分類: 資訊安全
  • 無法訂購

商品描述

Date Draft Released by NIST: July 2015 Health care providers increasingly use mobile devices to receive, store, process, and transmit patient clinical information. According to our own risk analysis, discussed here, and in the experience of many health care providers, mobile devices can present vulnerabilities in a health care organization’s networks. At the 2012 Health and Human Services Mobile Devices Roundtable, participants stressed that mobile devices are being used by many providers for health care delivery before they have implemented safeguards for privacy and security. This NIST Cybersecurity Practice Guide provides a modular, open, end-to-end reference design that can be tailored and implemented by health care organizations of varying sizes and information technology sophistication. Specifically, the guide shows how health care providers, using open source and commercially available tools and technologies that are consistent with cybersecurity standards, can more securely share patient information among caregivers using mobile devices. The scenario considered is that of a hypothetical primary care physician using her mobile device to perform reoccurring activities such as sending a referral (e.g., clinical information) to another physician, or sending an electronic prescription to a pharmacy. Instead, it presents the characteristics and capabilities that an organization’s security experts can use to identify similar standards-based products that can be integrated quickly and cost-effectively with a health care provider’s existing tools and infrastructure.

This public domain material was printed by 4th Watch Cyber Books. 4th Watch is not affiliated with the National Institute of Standards. 4th Watch books use high-quality 8 ½ by 11 inch paper, and are tightly bound. Most are printed in full color, that’s why they cost so much.

For more NIST titles, visit: cybah webplus net Partial list below:


NIST SP 800-12 Rev 1 An Introduction to Information Security

NIST SP 800-18 Developing Security Plans for Federal Information Systems

NIST SP 800-30 Guide for Conducting Risk Assessments

NIST SP 800-32 Public Key Technology and the Federal PKI Infrastructure

NIST SP 800-34 Contingency Planning Guide for Federal Information Systems

NIST SP 800-37 Applying Risk Management Framework to Federal Information

NIST SP 800-39 Managing Information Security Risk

NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations

NIST SP 800-53A R4 Assessing Security and Privacy Controls

NIST SP 800-57 Recommendation for Key Management

NIST SP 800-61 Computer Security Incident Handling Guide

NIST SP 800-82r2 Guide to Industrial Control Systems (ICS) Security

NIST SP 800-95 Guide to Secure Web Services

NIST SP 800-121 Guide to Bluetooth Security

NIST SP 800-137 Information Security Continuous Monitoring (ISCM)

NIST SP 800-160 Systems Security Engineering

NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Systems

NIST SP 800-177 Trustworthy Email

NIST SP 800-184 Guide for Cybersecurity Event Recovery

NIST SP 800-190 Application Container Security Guide

NIST SP 800-193 Platform Firmware Resiliency Guidelines

NIST SP 1800-1 Securing Electronic Health Records on Mobile Devices

NIST SP 1800-2 Identity and Access Management for Electric Utilities

NIST SP 1800-5 IT Asset Management: Financial Services

NIST SP 1800-6 Domain Name Systems-Based Electronic Mail Security

NIST SP 1800-7 Situational Awareness for Electric Utilities

NIST SP 1800-8: Securing Wireless Infusion Pumps

NISTIR 8011 Automation Support for Security Control Assessments

商品描述(中文翻譯)

日期草稿由NIST發布:2015年7月

醫療保健提供者越來越多地使用移動設備來接收、存儲、處理和傳輸病人的臨床信息。根據我們自己的風險分析(在此討論)以及許多醫療保健提供者的經驗,移動設備可能會在醫療保健組織的網絡中帶來漏洞。在2012年健康與人類服務部的移動設備圓桌會議上,與會者強調,許多提供者在尚未實施隱私和安全保障措施之前,就已經在使用移動設備進行醫療服務。這本NIST網絡安全實踐指南提供了一個模組化、開放的端到端參考設計,可以根據不同規模和信息技術成熟度的醫療保健組織進行調整和實施。具體而言,該指南展示了醫療保健提供者如何使用與網絡安全標準一致的開源和商業可用工具和技術,更安全地在護理人員之間共享病人信息。考慮的場景是一位假設的初級保健醫生使用她的移動設備執行重複性活動,例如將轉診(例如臨床信息)發送給另一位醫生,或將電子處方發送給藥房。相反,它展示了組織的安全專家可以用來識別類似標準產品的特徵和能力,這些產品可以快速且具成本效益地與醫療保健提供者現有的工具和基礎設施集成。

這些公共領域材料由4th Watch Cyber Books印刷。4th Watch與國家標準技術研究所無關。4th Watch的書籍使用高品質的8½ x 11英寸紙張,並且裝訂緊密。大多數書籍以全彩印刷,因此價格較高。

欲了解更多NIST書籍,請訪問:cybah webplus net 部分書單如下:

NIST SP 800-12 Rev 1 信息安全簡介

NIST SP 800-18 為聯邦信息系統制定安全計劃

NIST SP 800-30 風險評估指南

NIST SP 800-32 公鑰技術與聯邦PKI基礎設施

NIST SP 800-34 聯邦信息系統應急計劃指南

NIST SP 800-37 將風險管理框架應用於聯邦信息

NIST SP 800-39 管理信息安全風險

NIST SP 800-53 Rev 4 聯邦信息系統和組織的安全與隱私控制

NIST SP 800-53A R4 評估安全與隱私控制

NIST SP 800-57 密鑰管理建議

NIST SP 800-61 計算機安全事件處理指南

NIST SP 800-82r2 工業控制系統(ICS)安全指南

NIST SP 800-95 安全網絡服務指南

NIST SP 800-121 藍牙安全指南

NIST SP 800-137 信息安全持續監控(ISCM)

NIST SP 800-160 系統安全工程

NIST SP 800-171 在非聯邦系統中保護受控未分類信息

NIST SP 800-177 可信電子郵件

NIST SP 800-184 網絡安全事件恢復指南

NIST SP 800-190 應用容器安全指南

NIST SP 800-193 平台固件韌性指南

NIST SP 1800-1 在移動設備上保護電子健康記錄

NIST SP 1800-2 電力公用事業的身份和訪問管理

NIST SP 1800-5 IT資產管理:金融服務

NIST SP 1800-6 基於域名系統的電子郵件安全

NIST SP 1800-7 電力公用事業的情境意識

NIST SP 1800-8:保護無線輸液泵

NISTIR 8011 安全控制評估的自動化支持

最後瀏覽商品 (20)