Article ID: | iaor20011399 |
Country: | South Korea |
Volume: | 17 |
Issue: | 1 |
Start Page Number: | 145 |
End Page Number: | 158 |
Publication Date: | May 2000 |
Journal: | Korean Management Science Review |
Authors: | Lee Sang-Jae, Han In-Goo, Moon Song-Chul |
Keywords: | information |
The medical records of diagnostic and testing information include sensitive personal information that reveals some of the most intimate aspects of an individual's life. The hospital information system (HIS) operates in a state of high risk which may lead to the possible loss to the IS resources caused by various threats. This research addresses twofold: (1) to perform asset identification and valuation, and (2) to recommend countermeasures for secure HIS network using case studies. This paper applied a risk management tool, CRAMM (Central Computer and Telecommunications Agency's Risk Analysis and Management Method), to assess asset values and suggest countermeasures for the security of computerized medical information of two large hospitals in Korea. CRAMM countermeasures are recommended at the reference sites from the network security requirements of systems utilized for the diagnosis and treatment of patients. The results of the study will enhance the awareness of IS risk management by IS managers.