Generic security cases for information system security in healthcare systems

Y. He, C. W. Johnson

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

16 Citations (Scopus)

Abstract

Numerous data breach incidents have been reported in recent years and there is a continuing requirement to protect patient and clinician confidentiality. However, the diversity of security products, tools and techniques in the market place make it very hard for management to ensure that they have implemented coherent countermeasures to meet organisations higher-level objectives. This paper focuses on the problems that arise in implementing and maintaining cyber-security policies in large, complex healthcare organisations. We address these problems by the use of graphical argumentation techniques. In particular, we show how the Goal Structuring Notations (GSN) can be extended from applications in safety-critical systems. Security arguments presented with GSN can help managers to reason about cyber-security policies and procedures by bringing together claims and the evidence that supports them in a structured and coherent way. A further objective of this paper is to show how GSN can be used to construct security arguments that are informed by the analysis of previous security incidents in healthcare organisations. In particular, we present two generic security cases that embody the recommendations from incidents involving the United States' Veterans' Affairs (VA) administration and Shenzhen Hospital in China. These case studies were deliberately chosen to show how lessons learned in one country might inform security management in other healthcare systems. We also show that security cases can be created at a level of abstraction that support reuses and at the same time capture detailed recommendations from security incidents.

Original languageEnglish
Title of host publication7th IET International Conference on System Safety, Incorporating the Cyber Security Conference 2012
Edition607 CP
DOIs
Publication statusPublished - 2012
Externally publishedYes
Event7th IET International Conference on System Safety, Incorporating the Cyber Security Conference 2012 - Edinburgh, United Kingdom
Duration: 15 Oct 201218 Oct 2012

Publication series

NameIET Conference Publications
Number607 CP
Volume2012

Conference

Conference7th IET International Conference on System Safety, Incorporating the Cyber Security Conference 2012
Country/TerritoryUnited Kingdom
CityEdinburgh
Period15/10/1218/10/12

Fingerprint

Dive into the research topics of 'Generic security cases for information system security in healthcare systems'. Together they form a unique fingerprint.

Cite this