| 
 
| 标准号:ISO/TS 22600-1-2006 实施状态:作废
 中文名称:医用信息.权限管理和入口控制.第1部分:综述和政策管理
 英文名称:Health informatics - Privilege management and access control - Part 1: Overview and policy management
 发布日期:2006-08
 被替代标准:ISO 22600-1-2014
 采用标准:BS DD ISO/TS 22600-1-2008,IDT;GOST R ISO/TC 22600-1-2009,IDT
 起草单位:ISO/TC 215
 标准简介:This part of ISO/TS 22600 is intended to support the needs of healthcare information sharing across
 unaffiliated providers of healthcare, healthcare organizations, health insurance companies, their patients, staff
 members and trading partners. It is also intended to support inquiries from both individuals and application
 systems.
 ISO/TS 22600 defines methods for managing authorization and access control to data and/or functions. It
 accommodates policy bridging. It is based on a conceptual model where local authorization servers and crossborder
 directory and policy repository services can assist access control in various applications (software
 components). The policy repository provides information on rules for access to various application functions
 based on roles and other attributes. The directory service enables identification of the individual user. The
 granted access will be based on four aspects:
 the authenticated identification of the user;
 the rules for access connected with a specific information object;
 the rules regarding authorization attributes linked to the user provided by the authorization manager;
 the functions of the specific application.
 This part of ISO/TS 22600 should be used in a perspective ranging from a local situation to a regional or
 national one. One of the key points in these perspectives is to have organizational criteria combined with
 authorization profiles agreed upon from both the requesting and delivering side in a written policy agreement.
 This part of ISO/TS 22600 supports collaboration between several authorization managers that may operate
 over organizational and policy borders.
 The collaboration is defined in a policy agreement, signed by all involved organizations, and constitutes the
 basic platform for the operation.
 A documentation format is proposed, as a platform for the policy agreement, which makes it possible to obtain
 comparable documentation from all parties involved in the information exchange of information.
 This part of ISO/TS 22600 excludes platform-specific and implementation details. It does not specify technical
 communication security services and protocols that have been established in other standards,
 e.g. ENV 13608. It also excludes authentication techniques.
 文件格式:PDF
 文件大小:693.93KB
 文件页数:36
 (以上信息更新时间为:2019-11-22)
 
 
  ISO_TS 22600-1-2006 医用信息.权限管理和入口控制.第1部分_综述和政策管理.pdf
(693.93 KB) | 
 |