Propuesta de modelo de un Sistema de Gestión de la Seguridad de la Información aplicada a Hospitales Privados (IPS)
Fecha
Autor corporativo
Título de la revista
ISSN de la revista
Título del volumen
Editor
Compartir
Director
Altmetric
Resumen
In this final version of the document, it is proposed the recommended institutional structure that the information security model for private hospitals (IPS) should have. The document is divided into chapters as follows: Chapter 1 defines project planning. An approach is made to the problem that specifies the disadvantages that arise in the Health Service Provider Institutions that can be presented for lack of an information management system (ISMS). In addition, the objectives, the schedule of activities and the estimation of the resources necessary to determine the feasibility of the development of the project are defined. Chapter 2 describes the case study and the current situation of IPS Famisanar - Colsubsidio in charge of providing health services. Chapter 3 describes the importance of an ISMS within the institution, a prior analysis is performed, identifying opportunities, weaknesses, threats and / or strengths through the DOFA matrix. Chapter 4 identifies assets, threats and vulnerabilities to identify safeguards and controls to mitigate risks. Chapter 5 describes the security policies that must be followed to prevent threats and vulnerabilities from materializing. In chapter 6, the conclusions obtained during the development of the project are visualized. The approach of this case study is, therefore, to lay the foundations of an ISMS for the IPS, to ensure that the information of the patients and / or the people who entrust their data to the health entities remain safe, for this reason Document is based on the main activity of the entity, which is to provide a health service and therefore the assets must be identified and analyzed in order to study the threats to which they are exposed and identify the vulnerabilities and risks.
