UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

NEN - NPR-CR 14302

Health informatics - Framework for security requirements for intermittently connected devices

active, Most Current
Organization: NEN
Publication Date: 1 February 2002
Status: active
Page Count: 34
ICS Code (IT applications in health care technology): 35.240.80
scope:

This CEN Report is aimed at providing a basis for a planned European Standard on the same subject, work item Security Requirements for Intermittently Connected Devices. The reason for processing this document as a formal CEN Report is that it has been requested as immediate guidance to the current work of CEN TC224/WG12 in its preparation of standards specifying the mechanisms for implementing security requirements in systems using machine readable cards in health care. The scope of this report is also to serve as guidance, without being normative, to the many large projects using cards in health care for both patients, professionals and other persons working in the health care sector, presently under development in Europe. This report defines a framework of security requirements in systems with intermittently connected devices and discusses requirements for the following security services for ICD-systems: Data Integrity protection Data Origin and Entity Authentication Access Control Confidentiality protection The report defines security requirements on the ICD-interchange interface between an application system and an ICD-System. However, the overall security requirements can only be met if certain requirements on the devices themselves are also followed. Requirements for establishment of secure sessions with various types of ICDs as well as object related security services are defined. The report particularly defines how access to different types of data on intermittently connected devices could be restricted to different classes of health care persons (professionals and other types of personnel) or to the patients, especially when multinational access should be allowed. The rights to read, add, change and delete must be defined separately.

Document History

NPR-CR 14302
February 1, 2002
Health informatics - Framework for security requirements for intermittently connected devices
This CEN Report is aimed at providing a basis for a planned European Standard on the same subject, work item Security Requirements for Intermittently Connected Devices. The reason for processing this...
Advertisement