Challenges of information security incident learning: An industrial case study in a Chinese healthcare organization.

نویسندگان

  • Ying He
  • Chris Johnson
چکیده

Security incidents can have negative impacts on healthcare organizations, and the security of medical records has become a primary concern of the public. However, previous studies showed that organizations had not effectively learned lessons from security incidents. Incident learning as an essential activity in the "follow-up" phase of security incident response lifecycle has long been addressed but not given enough attention. This paper conducted a case study in a healthcare organization in China to explore their current obstacles in the practice of incident learning. We interviewed both IT professionals and healthcare professionals. The results showed that the organization did not have a structured way to gather and redistribute incident knowledge. Incident response was ineffective in cycling incident knowledge back to inform security management. Incident reporting to multiple stakeholders faced a great challenge. In response to this case study, we suggest the security assurance modeling framework to address those obstacles.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

PROVIDE A MODEL FOR IDENTIFYING AND RANKING THE MANAGERIAL FACTORS AFFECTING INFORMATION SECURITY IN ORGANIZATION BY USING VIKOR METHOD; CASE STUDY: TEHRAN UNIVERSITY OF MEDICAL SCIENCES

<span style="color: #000000; font-family: Tahoma, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: -webkit-left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ba...

متن کامل

PROVIDE A MODEL FOR IDENTIFYING AND RANKING THE MANAGERIAL FACTORS AFFECTING INFORMATION SECURITY IN ORGANIZATION BY USING VIKOR METHOD; CASE STUDY: TEHRAN UNIVERSITY OF MEDICAL SCIENCES

<span style="color: #000000; font-family: Tahoma, sans-serif; font-size: 13px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: -webkit-left; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ba...

متن کامل

UNDERSTANDING INFORMATION SECURITY INCIDENT MANAGEMENT PRACTICES A CASE STUDY IN THE ELECTRIC POWER INDUSTRY UNDERSTANDING INFORMATION SECURITY INCIDENT MANAGEMENT PRACTICES A CASE STUDY IN THE ELECTRIC POWER INDUSTRY Thesis for the degree of philosophiae doctor MARIA BARTNES LINE

With the implementation of smarter electric power distribution grids follows new technologies, which lead to increased connectivity and complexity. Traditional IT components – hardware, firmware, software – replace proprietary solutions for industrial control systems. These technological changes introduce threats and vulnerabilities that make the systems more susceptible to both accidental and ...

متن کامل

Cultural Differences Encountered by a Novice Chinese Immersion Teacher in an American Kindergarten Immersion Classroom

The research objective of this study was to explore the cultural differences and challenges encountered by the Chinese Immersion Teacher (CIT) and how the CIT deal with the cultural differences in the immersion classroom. A qualitative case study approach was chosen for this research. The participant was a novice kindergarten immersion teacher who was born and educated in a Chinese-speaking cou...

متن کامل

Cultural Differences Encountered by a Novice Chinese Immersion Teacher in an American Kindergarten Immersion Classroom

The research objective of this study was to explore the cultural differences and challenges encountered by the Chinese Immersion Teacher (CIT) and how the CIT deal with the cultural differences in the immersion classroom. A qualitative case study approach was chosen for this research. The participant was a novice kindergarten immersion teacher who was born and educated in a Chinese-speaking cou...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • Informatics for health & social care

دوره 42 4  شماره 

صفحات  -

تاریخ انتشار 2017