Developing and Validating a Healthcare Information Security Governance Framework

被引:0
|
作者
Mahncke, Rachel [1 ]
Williams, Patricia [1 ]
机构
[1] Edith Cowan Univ, Sch Comp & Secur Sci, EHlth Res Grp, Perth, WA, Australia
来源
关键词
Information Security Governance; General Practice; Action Research; Focus Group Interviews; ISO/IEC 27014: 2013; RACGP CISS (2013);
D O I
暂无
中图分类号
R-058 [];
学科分类号
摘要
General medical practices' in Australia are vulnerable to information security threats and insecure practices. It is well accepted in the healthcare environment that information security is both a technical and a human endeavour, and that the human behaviours, particularly around integration with healthcare workflow, are key barriers to good information security practice. The Royal Australian College of General Practitioner's (RACGP) Computer and Information Security Standards (CISS) 2013 are the best practice standards for general practices, against which information security is assessed during practice accreditation. With the release of ISO/IEC 27014: 2013 Information technology - Security techniques - Governance of information security in May 2013, it is this governance component of information security that is insufficiently addressed within General Practice at present. This paper documents the development and validation of an information security governance framework for use within general medical practice. The aim of the proposed Information Security Governance Framework is to extend current best practice information security management to include information security governance.
引用
收藏
页数:13
相关论文
共 50 条
  • [1] Information security governance framework
    Faculty of Informatics, Kogakuin University, Japan
    不详
    不详
    不详
    不详
    不详
    [J]. Proc ACM Conf Computer Commun Secur, (1-5):
  • [2] An information security governance framework
    Da Veiga, A.
    Eloff, J. H. P.
    [J]. INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 361 - 372
  • [3] A framework for the governance of information security
    Posthumus, S
    von Solms, R
    [J]. COMPUTERS & SECURITY, 2004, 23 (08) : 638 - 646
  • [4] Developing and Validating Instrument for Data Integration Governance Framework
    Hassan, Noor Hasliza Mohd
    Ahmad, Kamsuriah
    Salehuddin, Hasimi
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (02) : 157 - 162
  • [5] A Framework for Information Security Governance and Management
    Carcary, Marian
    Renaud, Karen
    McLaughlin, Stephen
    O'Brien, Conor
    [J]. IT PROFESSIONAL, 2016, 18 (02) : 22 - 30
  • [6] A Model for Information Security Governance in Developing Countries
    Coertze, Jacques
    von Solms, Rossouw
    [J]. E-INFRASTRUCTURE AND E-SERVICES FOR DEVELOPING COUNTRIES, 2013, 119 : 279 - 288
  • [7] Urgent Need for Developing a Framework for the Governance of AI in Healthcare
    Baig, Mansoor Ali
    Almuhaizea, Mohamad A.
    Alshehri, Jumanah
    Bazarbashi, Mohammad Shouki
    Al-Shagathrh, Fahad
    [J]. IMPORTANCE OF HEALTH INFORMATICS IN PUBLIC HEALTH DURING A PANDEMIC, 2020, 272 : 253 - 256
  • [8] Towards a Framework for Strategic Security Context in Information Security Governance
    Maynard, Sean B.
    Tan, Terrence
    Ahmad, Atif
    Ruighaver, Tobias
    [J]. PACIFIC ASIA JOURNAL OF THE ASSOCIATION FOR INFORMATION SYSTEMS, 2018, 10 (04): : 65 - 88
  • [9] Towards a holistic Information Security Governance Framework for SOA
    Coetzee, Marijke
    [J]. 2012 SEVENTH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES), 2012, : 155 - 160
  • [10] A framework for the governance of information security: Can it be used in an organization
    Antoniou, George S.
    [J]. IEEE SOUTHEASTCON 2018, 2018,