Skip to main content
Erschienen in: Annals of Telecommunications 5-6/2017

15.02.2017

IT governance and risk mitigation approach for private cloud adoption: case study of provincial healthcare provider

verfasst von: Ayo Gbadeyan, Sergey Butakov, Shaun Aghili

Erschienen in: Annals of Telecommunications | Ausgabe 5-6/2017

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Cloud computing (CC) has the potential to provide significant benefits to healthcare organizations; however, its susceptibility to security and privacy apprehensions needs to be addressed before its adoption. It is important to evaluate the risks that arise from CC prior to its adoption in healthcare projects. Failure to evaluate security and privacy concerns could result in regulatory penalties, reputation loss, financial issues, and public loss of confidence in the healthcare provider. This paper uses Alberta’s Privacy Impact Assessment (PIA) requirement and COBIT 5 for Risk as guidance to highlight CC risk assessment areas and presents an IT governance and risk mitigation approach useful for CC adoption in the healthcare industry. In compliance with Alberta’s Health Information Act (HIA), the risk assessment areas are analyzed based on the security triad with emphasis on the confidentiality principle where privacy is the main focus. The proposed approach presented in this paper can be utilized by healthcare providers to mitigate and continuously evaluate CC risks from an IT governance perspective. Although the case study uses Canadian regulations, similar considerations can be taken into account in other jurisdictions.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Ahuja et al (2012) A survey of the state of cloud computing in healthcare. Netw Commun Technol 12–19 Ahuja et al (2012) A survey of the state of cloud computing in healthcare. Netw Commun Technol 12–19
6.
Zurück zum Zitat Becker JD, Bailey E (2014) A comparison of IT governance & control frameworks in cloud computing, Twentieth Americas Conference on Information Systems(AMCIS). Association for Information Systems (AIS), Savanah, pp 1825–1840 Becker JD, Bailey E (2014) A comparison of IT governance & control frameworks in cloud computing, Twentieth Americas Conference on Information Systems(AMCIS). Association for Information Systems (AIS), Savanah, pp 1825–1840
10.
Zurück zum Zitat Chaput SR, Ringwood K (2010) Cloud compliance: a framework for using cloud computing in a regulated world. In Cloud Computing, pp. 241–255 Chaput SR, Ringwood K (2010) Cloud compliance: a framework for using cloud computing in a regulated world. In Cloud Computing, pp. 241–255
17.
Zurück zum Zitat Gatewood V (2013) Aspirations to reality: filling the cloud computing performance gap. ISACA 2:6–9 Gatewood V (2013) Aspirations to reality: filling the cloud computing performance gap. ISACA 2:6–9
24.
26.
Zurück zum Zitat Kuo AM-H (2011) Opportunities and challenges of cloud computing to improve health care services. J Med Internet Res:1–21 Kuo AM-H (2011) Opportunities and challenges of cloud computing to improve health care services. J Med Internet Res:1–21
29.
Zurück zum Zitat Meis R, Heisel M (2016) Supporting privacy impact assessments using problem-based privacy analysis. In Software Technologies, pp 79–98 Meis R, Heisel M (2016) Supporting privacy impact assessments using problem-based privacy analysis. In Software Technologies, pp 79–98
34.
Zurück zum Zitat Rodrigues JJ, de la Torre I, Fernández G, López-Coronado M (2013) Analysis of the security and privacy requirements of cloud-based electronic health records systems. J Med Internet Res, 15(8) Rodrigues JJ, de la Torre I, Fernández G, López-Coronado M (2013) Analysis of the security and privacy requirements of cloud-based electronic health records systems. J Med Internet Res, 15(8)
38.
Zurück zum Zitat Tancock D, Pearson S, & Charlesworth A (2013) A privacy impact assessment tool. In Privacy and Security for Cloud Computing. Springer. Tancock D, Pearson S, & Charlesworth A (2013) A privacy impact assessment tool. In Privacy and Security for Cloud Computing. Springer.
39.
Zurück zum Zitat Theoharidou et al (2013) Privacy risks, security accountability in the cloud, 5th IEEE Conference on Cloud Computing Technology and Science. IEEE Press, United Kingdom, pp 177–184 Theoharidou et al (2013) Privacy risks, security accountability in the cloud, 5th IEEE Conference on Cloud Computing Technology and Science. IEEE Press, United Kingdom, pp 177–184
42.
Zurück zum Zitat Zhang R, Lui L (2010) Security models and requirements for healthcare application clouds, IEEE 3rd International Conference on Cloud Computing. IEEE, Miami, Florida, pp 268–275 Zhang R, Lui L (2010) Security models and requirements for healthcare application clouds, IEEE 3rd International Conference on Cloud Computing. IEEE, Miami, Florida, pp 268–275
Metadaten
Titel
IT governance and risk mitigation approach for private cloud adoption: case study of provincial healthcare provider
verfasst von
Ayo Gbadeyan
Sergey Butakov
Shaun Aghili
Publikationsdatum
15.02.2017
Verlag
Springer Paris
Erschienen in
Annals of Telecommunications / Ausgabe 5-6/2017
Print ISSN: 0003-4347
Elektronische ISSN: 1958-9395
DOI
https://doi.org/10.1007/s12243-017-0568-5

Weitere Artikel der Ausgabe 5-6/2017

Annals of Telecommunications 5-6/2017 Zur Ausgabe

Premium Partner