The growing adoption of IT solutions in the healthcare sector is leading to a steady increase in the number of cybersecurity incidents. As a result, organizations worldwide have introduced regulations, standards, and best practices to address cybersecurity and data protection issues in this sector. However, the application of this large corpus of documents presents operational difficulties, and operators continue to lag behind in resilience to cyber attacks. This paper contributes a systematization of the significant cybersecurity documents relevant to the healthcare sector. We collected the 49 most significant documents and used the NIST cybersecurity framework to categorize key information and support the implementation of cybersecurity measures.
翻译:随着信息技术解决方案在医疗领域日益普及,网络安全事件数量持续攀升。为此,全球各机构纷纷出台法规、标准及最佳实践,以应对该领域的网络安全与数据保护问题。然而,这些庞杂文件的实际应用仍存在操作层面的困难,医疗机构在抵御网络攻击方面的韧性仍然滞后。本文对医疗领域相关的重要网络安全文件进行了系统化梳理。我们收集了49份关键文件,并采用NIST网络安全框架对核心信息进行分类,以支持网络安全措施的实施。