医院信息系统安全风险规避管理策略研究

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

华中科技大学硕士学位论文医院信息系统安全风险规避管理策略研究姓名:祝敬萍申请学位级别:硕士专业:社会医学与卫生事业管理指导教师:方鹏骞2008050112===3===4StudyonRiskPreventionManagementStrategyforHospitalInformationSystemSecurityCandidate:JingpingZhuSupervisor:Prof.PengqianFangABSTRACTObjective:Onthebasisofunderstandingthestatusquoofinformationsystemsecurityriskathomeandabroad,tofurtherclarifyriskandproblemofhospitalinformationsystemsecuritythatalreadyexistedinourcountry,usingforreferenceoffeasiblefeatureinpreventionstrategyofinformationsystemsecurityriskthatalreadyexisted,puttingforwardpossiblemeasuresandstrategytopreventsecurityriskofhospitalinformationsystemfromangleofmanagement,providingreferencefordecision-makingandsystemsecurityadministratortocarryoutriskpreventionmanagementofinformationsystemsecuritybetter.Methods:1.DocumentRetrievalandinformationanalysis:Themethodisthroughcollection,identification,trimmingdocumentsandconductingresearchtoformascientificunderstandingoffacts.Inthispaper,onthebasisofconsultingrelevanttheoryandpracticalprogressaboutsystemsecurityandmanagementstrategyofriskprevention,summedupsomeofwhatcandrawon,ascertainedtarget,content,methods,questionnairesandinterviewoutlineofthisstudy.2.Statisticalanalysisofdescription:Themethodiscalculatedbystatisticalchartsanddatadistributionofsamplestounderstanddistributioncharacteristicsofobservations.Inthispaper,usedthismethodtosumupandanalyzebasicsituationofsurveyhospitalsandthecrowd,staffingandtrainingofsystemsecurityetc.Chi-squaretestwasusedonappraisementofabilitytoprotectsystemsafetyandsecurityproduct,perceivedifferencesofsufficientdegreeofinvestmentfundsfordifferentgroupsofthepersonnelofhospitalinformationbureau.3.Principalcomponentanalysis:Itisstatisticalmethodofmeltingmanyvariablesintoafewunrelatedcomprehensivevariables,fromrelationshipbetweenmanyvariables,usingthinkingofreducingdimension.Themethodwasusedonmanyriskfactorsimpactingsystemsecurityinthisstudy.4.Scenetypicalinvestigation:Itisamethodofsystematicsurveyselectingrepresentativeareasororganizationsaccordingtocontentandpurposeofthestudy.Inthispaper,thismethodwasused,conductinginvestigationonthepersonnelofhospitalinformationbureauandpersonnelthatusinghospitalinformationsubsystems.Atotalof5sevenhospitalsincitiesofWuhanandEzhou,threehundredsandthirtypeoplewereinvestigatedinthisstudy.5.Themethodofsociologyqualitativeresearch:Itisamethodcarryingthroughdeepleveldiscussionaboutindicatorswhichunabletoquantifyorinformationwhichunabletoaccessdirectlybyquestionnaire.Inthispaper,specialtopicgroupdiscussionwasused,invitingmanyfieldsofexpertsininformationmanagement,healthstatisticsetc.probingintoimplementationschemeanddataanalysismethodsofthisstudy.Personalsemi-structuredinterviewwasusedonkeypeople,probingintorelevantexperienceandproblemsaboutriskpreventionmanagementofhospitalinformationsystemsecurity.Resultsandanalysis:1.TheanalysisforpersonneldeployingandworkofdividinginthefieldofhospitalinformationsystemsecurityHospitalinformationsystemsecurityincludesmanyaspects,suchashardware,software,network,database,systemroomsandsoon.Systemsecurityiscarriedthroughundertheunifiedleadershipofmanagementdeaninthisfieldanddirectorofinformationbureau.Thereisonlyonepersonormoreresponsibleformanagementofsecurityincertainaspectinsomehospitals,butthereisonlyonepersonshouldberesponsibleforvariousaspectsofsecurityinotherhospitals.Whenserioussecurityincidentshappened,manyaspectsofpeoplewhoareresponsibleforsystemsecuritycooperatewitheachothertosolvethem.Insomehospitals,tasksofsystemsecuritymanagersaretooheavy,academicqualificationsareonthelowside,specialtiesarenotveryconsistentwithsystemsecuritymanagement,organizationalstructureofsystemsecuritymanagementisnotperfectenough,lackofcommunicationandharmonizationbetweenmulti-sectors2.TheanalysisforpersonneltrainingofhospitalinformationsystemsecurityTherearesomehospitalswhoarenotgivenenoughattentiontosecuritytrainingofsystem,thecontentandmethodsoftrainingarenotveryaffluentin,selectingoftrainingtimeandfrequencyisnotverysuitable,traininginvestmentisnotveryenough,theeffectoftrainingisnotverygood.3.TheanalysisforsecurityriskofhospitalinformationsystemThereareinternalandexternalsourcesofsystemsecurityrisk,whichmostlycomesfromfiveaspectsofdata,network,hardware,software,systemrooms.Thebetterwayofdetectingsecurityriskofsystemismonitoredbysystemadministratororsecurityproducts,buttherearestillsomehospitalswhichfinditbyanalysisafteraccidentorbysuddenness4.Theanalysisforselectingriskpreventionmeasuresofhospitalinformationsystemsecurityavailably.Thereareplaceswhichshouldbeimprovedoninselectingsecuritymeasuresavailablyinhospital,suchassystemarchitecture,thelevelofoperatingsystem,thelevelofsystem,data,network,managementandtechnology,andsoon.65.TheanalysisforappraisementofabilitytoprotectsystemsafetyandsecurityproductThemajorityofpeopleconsiderthatabilitytoprotectsystemsecurityintheirhospitalsisnotveryhigh.Inthepersonnelofhospitalinformationbureau,differentonesofagedistribution(?2=9.033,P=0.046),differentonesofacademiclevel(?2=10.189,P=0.023),onesofdifferentwor

1 / 97
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功