Title
Cybersecurity and Privacy Capabilities Model for Data Management Against Cyber-Attacks in the Health Sector
Date Issued
01 January 2021
Access level
metadata only access
Resource Type
conference paper
Author(s)
Publisher(s)
Springer Science and Business Media Deutschland GmbH
Abstract
In this paper, we propose a model of capabilities that identify the reliability degree of Cybersecurity and Privacy elements applied to the Health Sector. The increasing interactions between technology and the health sector have brought a new set of risks to be confronted, such as data breaches and cyberattacks. However, in order to improve, a greater understanding of their current situation is needed. The proposal identifies the capability level for the organizations to know their maturity level comprehensively. This was achieved by selecting existing models, frameworks, and regulations, increasing their complexity, integrating their privacy and cybersecurity capabilities, and health data management. In this way, the proposal is supported by a tool prepared for outcome estimation and diagnosis. The model structure is organized into categories and subcategories, and the assessment is made according to the level of compliance with controls, for which five levels of maturity were defined: 1. Basic, 2. In Progress, 3. Defined, 4. Differentiated, 5. Continuous Improvement. The model was validated and proven in a private hospital in Lima, Peru. The preliminary results are related to the model application in the selected process. As a result, we found that the private hospital obtained a level of maturity of 2-In Progress. Based on this, we made some recommendations to improve the capacities of the assessed health provider. A comparison was made between the proposed model's results and the ones obtained through its root components. Said results were similar, thus proving that a coherent and comprehensive integration was achieved.
Start page
359
End page
367
Volume
233
Language
English
OCDE Knowledge area
Otras ciencias médicas
IngenierÃa de sistemas y comunicaciones
Subjects
Scopus EID
2-s2.0-85111363780
ISSN of the container
21903018
ISBN of the container
978-303075679-6
Conference
Smart Innovation, Systems and Technologies
Sources of information:
Directorio de Producción CientÃfica
Scopus