|
Abstract: . . . alarms for critical events Monitored Internet usage System clock synchronization In Conclusion Our subjective overall grade is somewhere between a C and a B The standard is a useful tool Adds structure to existing business practice Highlights areas that need more attention Excellent metric for establishing trust between organizations A healthcare-specific code of practice and guidelines based on the Standard should be developed Discussion Click to add text . . . . . . all systems Documented backup procedures Routine testing of backup tapes Remote storage of backup media Database transaction backup procedures are understood and tested Some distributed content for fault tolerance Network Management: B Data transmitted over public networks is encrypted No encryption over leased segments (Telus) Redundant network connectivity Clear responsibility for network management Isolation of network traffic to required segments Overly complex network designs Exchanges of Information and Software: B Data access agreements Software escrow agreements Technical standards for information exchange Documented procedures for information exchange Security of E-mail: B No documented E-mail policy Well understood accepted use Reliable service – no down time Exceptional integrity of information . . . --1619,2,405,1423,8096
|