题名 |
整合ISO 27001與ISO 27799應用於護理資訊之探討 |
作者 |
林宜隆;陳珮菁;陳高宏;李正元;劉世詳;謝宗翰;羅尹伶 |
关键词 |
ISMS管理安全措施 ; 護理資訊 ; ISO 27001 ; ISO 27799 ; ISMS management security measures ; Nursing Informatics |
期刊名称 |
電腦稽核 |
卷期/出版年月 |
30期(2014 / 07 / 01) |
页次 |
1 - 11 |
内容语文 |
繁體中文 |
中文摘要 |
依據台灣醫院協會(2012)一項「醫院因應個人資料保護法問卷調查」統計,已完成因應措施之醫療機構,僅占調查總家數之4.73%,其主要原因為對法律了解不足(72.78%)及員工對個資保護意識不足(70.41%)所致。健保局為因應電子化政府的推動,建置健保IC卡及電子病歷交換等技術,並培訓醫院資訊安全種子,提供ISO 27001:2005資訊安全管理國際標準驗證服務,至2013年2月8日全國已有93家通過驗證。本文以ISMS:ISO 27001:2005為基礎,並彙整出ISO 27001管理要項(133項)與為醫療照顧產業的特殊屬性制定的ISO 27799:2008,運用P-D-C-A循環流程及林宜隆教授所提出之PLSE Model四大構面,建立ISMS管理安全措施工作要項於護理資訊。 |
英文摘要 |
A survey on "Hospital Response to the Personal Information Protection Act" conducted by Taiwan Hospital Association shows that only 4.73% of the surveyed hospitals have implemented measures to comply with the Act. Those which have not complied with the Act were mainly constrained by unfamiliarity with the law (72.78%) and lack of awareness of personal information protection among employees (70.41%). In line with the government's promotion of e-government services, Bureau of National Health Insurance has implemented numerous measures, including use of Health Insurance IC Card, electronic medical history exchange, training of seed hospital specialists in charge of information security, and certification of ISO 27001:2005. As of Feb 8, 2013, 93 hospitals islandwide have passed the certification. Based on ISMS:ISO 27001:2005, this study first obtained key criteria in ISO 27001 (133 items in total) and ISO 27799:2008 established to specifically regulate health informatics. this study applie d P-D-C-A cycle and PLSE Model introduced by Dr. I-Long Lin to build key tasks of personal information protection for nursing institutions. |
主题分类 |
基礎與應用科學 >
資訊科學 |
参考文献 |
|
被引用次数 |
|