标准编号:ISO 22600-3:2014
中文名称:保健信息学 特权管理和访问控制 第3部分:实施
英文名称:Health informatics — Privilege management and access control — Part 3: Implementations
发布日期:2014-10
标准范围
This multi-part International Standard defines principles and specifies services needed for managingprivileges and access control to data and/or functions.It focuses on communication and use of health information distributed across policy domain boundaries.This includes healthcare information sharing across unaffiliated providers of healthcare, healthcareorganizations, health insurance companies, their patients, staff members, and trading partners byboth individuals and application systems ranging from a local situation to a regional or even nationalsituation.It specifies the necessary component-based concepts and is intended to support their technicalimplementation. It will not specify the use of these concepts in particular clinical process pathways.This part of ISO 22600 instantiates requirements for repositories for access control policies andrequirements for privilege management infrastructures. It provides implementation examples of theformal models specified in ISO 22600-2.This part of ISO 22600 excludes platform-specific and implementation details. It does not specify technicalcommunication security services, authentication techniques, and protocols that have been established inother International Standards such as e.g. ISO 7498-2, ISO/IEC 10745 (ITU-T X.803), ISO/IEC/TR 13594(ITU-T X.802), ISO/IEC 10181-1 (ITU-T X.810), ISO/IEC 9594-8 (ITU-T X.509), ISO/IEC 9796 (all parts),ISO/IEC 9797 (all parts), and ISO/IEC 9798 (all parts).