Your browser doesn't support javascript.
loading
A Risk Assessment Framework Proposal Based on Bow-Tie Analysis for Medical Image Diagnosis Sharing within Telemedicine.
Poleto, Thiago; Silva, Maisa Mendonça; Clemente, Thárcylla Rebecca Negreiros; de Gusmão, Ana Paula Henriques; Araújo, Ana Paula de Barros; Costa, Ana Paula Cabral Seixas.
Afiliação
  • Poleto T; Department of Business Administration, Federal University of Pará, Belém 66075-110, Brazil.
  • Silva MM; Department of Management Engineering, Universidade Federal de Pernambuco, Recife 50670-901, Brazil.
  • Clemente TRN; Department of Management Engineering CAA, Universidade Federal de Pernambuco, Caruaru 55002-970, Brazil.
  • de Gusmão APH; Department of Management Engineering, Universidade Federal de Sergipe, São Cristóvão 49100-000, Brazil.
  • Araújo APB; Department of Management Engineering, Universidade Federal de Pernambuco, Recife 50670-901, Brazil.
  • Costa APCS; Department of Management Engineering, Universidade Federal de Pernambuco, Recife 50670-901, Brazil.
Sensors (Basel) ; 21(7)2021 Apr 01.
Article em En | MEDLINE | ID: mdl-33915932
The purpose of this paper is to propose a framework for cybersecurity risk management in telemedicine. The framework, which uses a bow-tie approach for medical image diagnosis sharing, allows the identification, analysis, and assessment of risks, considering the ISO/TS 13131:2014 recommendations. The bow-tie method combines fault tree analysis (FTA) and event tree analysis (ETA). The literature review supported the identification of the main causes and forms of control associated with cybersecurity risks in telemedicine. The main finding of this paper is that it is possible, through a structured model, to manage risks and avoid losses for everyone involved in the process of exchanging medical image information through telemedicine services. Through the framework, those responsible for the telemedicine services can identify potential risks in cybersecurity and act preventively, recognizing the causes even as, in a mitigating way, identifying viable controls and prioritizing investments. Despite the existence of many studies on cybersecurity, the paper provides theoretical contributions to studies on cybersecurity risks and features a new methodological approach, which incorporates both causes and consequences of the incident scenario.
Assuntos
Palavras-chave

Texto completo: 1 Coleções: 01-internacional Base de dados: MEDLINE Assunto principal: Gestão de Riscos / Telemedicina Tipo de estudo: Diagnostic_studies / Etiology_studies / Guideline / Prognostic_studies / Risk_factors_studies Idioma: En Revista: Sensors (Basel) Ano de publicação: 2021 Tipo de documento: Article País de afiliação: Brasil País de publicação: Suíça

Texto completo: 1 Coleções: 01-internacional Base de dados: MEDLINE Assunto principal: Gestão de Riscos / Telemedicina Tipo de estudo: Diagnostic_studies / Etiology_studies / Guideline / Prognostic_studies / Risk_factors_studies Idioma: En Revista: Sensors (Basel) Ano de publicação: 2021 Tipo de documento: Article País de afiliação: Brasil País de publicação: Suíça