Recent
hacking of medical records suggests a greater need for care by GPs. The Royal Australian College of General Practitioners recommend GPs
implement a set of "
RACGP Computer and Information Security Standards"
(CISS) for their practice computer systems. There is a workbook with a check-list provided. This covers Staff roles and responsibilities as well as technical matters.
Contents
Preface
- Introduction
- How to use this document
- Computer and information security checklist
- Organisational and technical issues
- Risk assessment
- Select security coordinator
- Articulate the operating parameters
- Record all user and technical support contact details
- Asset register
- Identify the threats and vulnerabilities, and suggested controls
- Identify appropriate controls
- Security management and reporting, including monitoring
- compliance and review planning
- Education and communication
- Breach reporting
- Staff roles and responsibilities
- Practice computer security coordinator
- Other staff roles and responsibilities
- Practice security policies and procedures
- Practice security policies and procedures description
- Sample confidentiality agreement
- Contractual agreements
- Access control and management
- Setting access levels
- Access policy
- Business continuity and disaster recovery plans
- Business continuity and disaster recovery
- Development process and procedures
- Staff internet and email usage
- Policies for the use of internet and email
- Procedures for the safe use of internet and email
- Backup
- Backup procedure
- Backup media cycling
- Documenting rotation of backup media
- Restoring data
- Malware, viruses and email threats
- Malware and virus protection
- Network perimeter controls
- Network perimeter control policy
- Intrusion detection system
- Firewall
- Other controls
- Portable devices and wireless networks
- Portable devices
- Remote access
- Physical, system and software protection
- Physical
- System maintenance
- Software maintenance
- Secure electronic communication
- Healthcare identifiers
- Message system record
- Conclusion
- Glossary of computer and information security terms
From: RACGP Computer and Information Security Standards, Royal Australian College of General Practitioners, 2011
RACGP cite these standards:
- AZ/NZS ISO 31000:2009 Risk management – principles and guidelines.
Sydney: Standards Australia International, 2009
- HB 292 – 2006 A practitioners guide to business continuity management.
Sydney: Standards Australia International, 2006
- HB 174 – 2003 Information security management – implementation guide for
the health sector. Sydney: Standards Australia International, 2003. Note: this
handbook is due for revision shortly
- HB 231 – 2004 Information security risk management guidelines.
Sydney: Standards Australia International, 2004
- HB 292 – 2006 A practitioners guide to business continuity management.
Sydney: Standards Australia International, 2006
- HB 293 – 2006 Executive guide to business continuity management.
Sydney: Standards Australia International, 2006
- Information Privacy Principles under the Privacy Act 198
- ISO/IEC 27002:2006 Information technology – Security techniques –
Code of practice for information security management
- ISO 27799:2008 Health Informatics – Information security management
in health using ISO/IEC 27002
- NIST (2008). Computer security incident handling guide. Special Publication
800–61. National Institute of Standards and Technology
- Office of the Australian Information Commissioner. (2006). National Privacy Principles
No comments:
Post a Comment