2014
DOI: 10.1007/978-3-662-43813-8_8
|View full text |Cite
|
Sign up to set email alerts
|

Improving the Exchange of Lessons Learned in Security Incident Reports: Case Studies in the Privacy of Electronic Patient Records

Abstract: The increasing use of Electronic Health Records has been mirrored by a similar rise in the number of security incidents where confidential information has inadvertently been disclosed to third parties. These problems have been compounded by an apparent inability to learn from previous violations; similar security incidents have been observed across Europe, North America and Asia. This has resulted in the loss of confidence and trust of the public towards the organisations' ability to protect the patients' priv… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
6
0

Year Published

2015
2015
2018
2018

Publication Types

Select...
3

Relationship

3
0

Authors

Journals

citations
Cited by 3 publications
(6 citation statements)
references
References 23 publications
0
6
0
Order By: Relevance
“…Previous research showed that GSTs can be used to represent and share lessons from previous security incidents [25,43,45]. In contrast, this paper has presented empirical studies that evaluate its acceptance in an industry setting.…”
Section: Discussionmentioning
confidence: 98%
See 2 more Smart Citations
“…Previous research showed that GSTs can be used to represent and share lessons from previous security incidents [25,43,45]. In contrast, this paper has presented empirical studies that evaluate its acceptance in an industry setting.…”
Section: Discussionmentioning
confidence: 98%
“…A previous study had already provided evidence that GSTs can improve the communication of security lessons compared to traditional text based approaches [45]. The next section, therefore, expands on Scenario II to find out how the GST can be used to redistribute security lessons into security management procedures.…”
Section: Scenarios For Applying Gstsmentioning
confidence: 96%
See 1 more Smart Citation
“…This finding was also share by Ahmad [24,25] and Tondel [31] This indicated poor communication between incident response teams and other stakeholders. Previous researches [53,54] argued text alone does not facilitate the communication of security lessons. There is a need for the conversion of post-incident reports into learning documents, which can be easily understood by people in the organisation.…”
Section: Information Disseminationmentioning
confidence: 97%
“…There a need of an effective way to present incident knowledge that can facilitate incident knowledge dissemination. Security assurance modelling framework can serve this purpose as it was found to be able to effectively communicate security incidents [37,54]. It can be applied to convert incident reports and represent lessons learned in a structured manner.…”
Section: Incident Dissemination and Assurance Modellingmentioning
confidence: 99%