Security incident response: rethinking risk management

被引:0
|
作者
Alberts, C [1 ]
Dorofee, A [1 ]
机构
[1] Carnegie Mellon Univ, Inst Software Engn, Pittsburgh, PA 15213 USA
关键词
risk; risk management; risk assessment; HIPAA; security; incident response;
D O I
10.1016/j.ics.2004.03.135
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 establishes a standard of care for healthcare data security, outlining a set of technical, physical, and administrative security practices intended to protect electronic patient data. The regulation requires organizations to conduct information-security risk assessments to ensure that their security programs effectively mitigate their risks. Because the regulation does not mandate a specific technique, many variants of risk assessments have been employed to satisfy the requirement. This paper examines limitations in process-based risk assessments used by many healthcare organizations to comply with the HIPAA risk assessment requirement. It specifically focuses on the following three limitations: (1) lack of detailed operational context, (2) limited analysis of combinatorial effects of risk conditions, and (3) the tendency for local optimization of risk mitigation efforts. (C) 2004 CARS and Elsevier B.V. All rights reserved.
引用
收藏
页码:141 / 146
页数:6
相关论文
共 50 条
  • [21] Build a cyber security incident response plan
    Staggs, Kevin
    CONTROL ENGINEERING, 2009, 56 (12) : 56 - 56
  • [22] Aligning disaster recovery and security incident response
    Schultz, E
    COMPUTERS & SECURITY, 2005, 24 (07) : 505 - 506
  • [23] Using Incident Response Trees as a Tool for Risk Management of Online Financial Services
    Gorton, Dan
    RISK ANALYSIS, 2014, 34 (09) : 1763 - 1774
  • [24] Rethinking risk management in the federal government
    Cantor, R
    ANNALS OF THE AMERICAN ACADEMY OF POLITICAL AND SOCIAL SCIENCE, 1996, 545 : 135 - 143
  • [25] RETHINKING RISK MANAGEMENT FOR OFFSHORE SAFETY
    Torstad, Elisabeth H.
    OIL & GAS JOURNAL, 2012, : 3 - 3
  • [26] Rethinking management of neonates at risk of sepsis
    Lavoie, Pascal M.
    Popescu, Constantin R.
    Molyneux, Elizabeth M.
    Wynn, James L.
    Chiume, Msandeni
    Keitel, Kristina
    Lufesi, Norman
    Levine, Gillian A.
    Ansermino, J. Mark
    Kissoon, Niranjan
    LANCET, 2019, 394 (10195): : 279 - 281
  • [27] Security Incident Response Criteria: A Practitioner's Perspective
    Grispos, George
    Glisson, William Bradley
    Storer, Tim
    AMCIS 2015 PROCEEDINGS, 2015,
  • [28] Testing your computer security incident response plan
    Markey, Steve
    ISACA Journal, 2012, 2
  • [29] Towards the Definition of a Security Incident Response Modelling Language
    Athinaiou, Myrsini
    Mouratidis, Haralambos
    Fotis, Theo
    Pavlidis, Michalis
    Panaousis, Emmanouil
    TRUST, PRIVACY AND SECURITY IN DIGITAL BUSINESS, 2018, 11033 : 198 - 212
  • [30] Shared Situational Awareness in Information Security Incident Management
    Padayachee, Keshnee
    Worku, Elias
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 479 - 483