ISO 27799 - Information Security Management in Healthcare
Continuity, Resilience & Recovery
ISO 27799:2016 - Information Security Management in Healthcare (ISMH) gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization's information security risk environment(s).
ISO 27799:2016 provides implementation guidance for the controls described in ISO/IEC 27002 and supplements them where necessary, so that they can be effectively used for managing health information security. By implementing ISMH, healthcare organizations and other custodians of health information will be able to ensure a minimum requisite level of security that is appropriate to their organization's circumstances and that will maintain the confidentiality, integrity and availability of personal health information in their care.
It applies to health information in all its aspects, whatever form the information takes (words and numbers, sound recordings, drawings, video, and medical images), whatever means are used to store it (printing or writing on paper or storage electronically), and whatever means are used to transmit it (by hand, through fax, over computer networks, or by post), as the information is always be appropriately protected.
Benefits of ISO 27799:2016 Information Security Management in Healthcare (ISMH)
- Understood the implementation of Information Security Controls in healthcare organizations by adhering to the framework and principles of ISO 27799.
- Understood the relationship between the components of Information Security controls, including responsibility, strategy, acquisition, performance, conformance and human behavior.
- Gained the necessary skills to support a healthcare organization in implementing and managing the ongoing Information Security controls based on ISO 27799.
- Acquired the competences to perform periodic risk assessment in a healthcare organization.
- Enhanced your ability to help healthcare organizations to play an active and important role in the protection of personal health data of their patients.
- Gained the necessary knowledge to improve Information Security in healthcare organizations.