ISO 17090-3:2021 Health informatics — Public key infrastructure —Part 3: Policy management of certification authority
标准简介
Health informatics — Public key infrastructure —Part 3: Policy management of certification authority由国际标准化组织(International Organization for Standardization,简称ISO)于2021‑03‑09发布,适用于国际范围。标准截图

标准文档说明
标准文档类型为Health informatics — Public key infrastructure —Part 3: Policy management of certification authority高清PDF版本(文字版),标准文档内可进行搜索,可以复制原文,可粘贴。标准部分原文
INTERNATIONAL STANDARD ISO 17090-3:2021
Health informatics — Public key infrastructure —
Part 3: Policy management of certification authority
1 Scope
This document gives guidelines for certificate management issues involved in deploying digital certificates in healthcare. It specifies a structure and minimum requirements for certificate policies, as well as a structure for associated certification practice statements.
This document also identifies the principles needed in a healthcare security policy for cross-border communication and defines the minimum levels of security required, concentrating on aspects unique to healthcare.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes requirements of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies.
ISO 170901‑ :2021 , Health informatics — Public key infrastructure — Part 1: Overview of digital certificate services
ISO 170902‑ :2015 , Health informatics — Public key infrastructure — Part 2: Certificate profile
ISO/IEC 27002, Information technology — Security techniques — Code of practice for information security controls
IETF/RFC 3647, Internet X.509 Public Key Infrastructure Certificate Policy and Certification
Practices Framework
IETF/RFC 4211, Internet X.509 Public Key Infrastructure Certificate Request Message Format (CRMF)
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO 170901‑ apply.
ISO and IEC maintain terminological databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https://www.iso.org/obp
— IEC Electropedia: available at http://www.electropedia.org/
4 Abbreviations
AA attribute authority
CA certification authority
CP certificate policy
ISO 17090-3:2021
CPS certification practice statement
CRL certificate revocation list
OID object identifier
PKC public key certificate
PKI public key infrastructure
RA registration authority
TTP trusted third party
5 Requirements for digital certificate policy management in a healthcare context
5.1 General
Deployment of digital certificates in healthcare shall meet the following objectives in order to be effective in securing the communication of personal health information:
— the reliable and secure binding of unique and distinguished names to individuals, organizations, applications and devices that participate in the electronic exchange of personal health information;
— the reliable and secure binding of professional roles in healthcare to individuals, organizations and applications that participate in the electronic exchange of personal health information, insofar as those roles may be used as the basis of role-based access control to such health information;
— (optionally) the reliable and secure binding of attributes to individuals, organizations, applications and devices that participate in the electronic exchange of personal health information, insofar as those attributes may further the secure communication of health information.
The above objectives shall be accomplished in a manner that maintains the trust of all who rely upon the integrity and confidentiality of personal health information that is securely communicated by use of digital certificates.
To do this, each CA issuing digital certificates for use in healthcare shall operate according to an explicit set of publicly stated policies that promote the above objectives.
5.2 Need for a high level of assurance
The security services that are required for health applications are specified in Clause 6 of ISO 170901‑ :2021 . For each of these security services (authentication, integrity, confidentiality, digital signature, authorization, access control), a high level of assurance is required.
5.3 Need for a high level of infrastructure availability
Emergency healthcare is a round-the-clock endeavour and the ability to obtain certificates, revoke certificates and check revocation status is in no way bound by the normal working hours of most businesses. Unlike e-commerce, healthcare imposes high availability requirements on any deployment of digital certificates that will be relied upon to secure the communication of personal health information.
5.4 Need for a high level of trust
Unlike electronic commerce (where a vendor and a customer are often the only parties to an electronic transaction and are reliant upon its security and integrity), healthcare applications that store or transmit personal health information may implicitly require the trust of the patients whose information
网盘链接
百度网盘:https://pan.baidu.com/s/19DrXLMigAxYFke6mD8D9gQ
提取码:bfw4
【温馨提示】大资料ISO是提供信息发布的专业信息类网站,所有内容均由用户发布,不代表本站观点,本站亦不存储所涉及的文件及资料。如有【免费资料】以及【付费资料】,请用户根据自己的需求,自行判断是否需要获取。如有交易诈骗、内容侵权可发送邮件至kf@dzl100.com,我们审查后若发现情况属实,会立即对相关内容进行删除处理。
加载用时:71.4883 毫秒
相关评论
相关文章
-
ISO 17090-3:2021 Health informatics — Public key infrastructure —Part 3: Policy management of certification authority
Health informatics — Public key infrastructure —Part 3: Policy management of certification authority是国际标准化组织(International Organization for Standardization,简称ISO)于2021‑03‑09发布的ISO标准,适用于国际范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 10014:2021 Quality management systems — Managing an organization for quality results — Guidance for realizing financial and economic benefits
Quality management systems — Managing an organization for quality results — Guidance for realizing financial and economic benefits是国际标准化组织(International Organization for Standardization,简称ISO)于2021-04-20发布的ISO标准,适用于世界范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 19475:2021 Document management — Minimum requirements for the storage of documents
Document management — Minimum requirements for the storage of documents是国际标准化组织(International Organization for Standardization,简称ISO)于2021‑06‑10发布的ISO标准,适用于全球。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 19206-3:2021 Road vehicles — Test devices for target vehicles, vulnerable road users and other objects, for assessment of active safety functions —Part 3: Requirements for passenger vehicle 3D targets
Road vehicles — Test devices for target vehicles, vulnerable road users and other objects, for assessment of active safety functions —Part 3: Requirements for passenger vehicle 3D targets是ISO于2021‑05‑21发布的ISO标准,适用于全球范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 16355-1:2021 Application of statistical and related methods to new technology and product development process —Part 1: General principles and perspectives of quality function deployment (QFD)
Application of statistical and related methods to new technology and product development process —Part 1: General principles and perspectives of quality function deployment (QFD)是ISO于2021-05发布的ISO标准,适用于世界范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 17226-1:2021 INTERNATIONAL STANDARDIULTCS/IUC 19-1:2021(E)Leather — Chemical determination of formaldehyde content —Part 1: Method using high-performance liquid chromatography
INTERNATIONAL STANDARDIULTCS/IUC 19-1:2021(E)Leather — Chemical determination of formaldehyde content —Part 1: Method using high-performance liquid chromatography是国际标准化组织于2021-02发布的ISO标准,适用于国际范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 16140-3:2021 Microbiology of the food chain — Method validation —Part 3: Protocol for the verification of reference methods and validated alternative methods in a single laboratory
Microbiology of the food chain — Method validation —Part 3: Protocol for the verification of reference methods and validated alternative methods in a single laboratory是国际标准化组织于2021-01发布的ISO标准,适用于全球。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 16321-1:2021 Eye and face protection for occupational use —Part 1: General requirements
Eye and face protection for occupational use —Part 1: General requirements是ISO于2021-03发布的ISO标准,适用于全球。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
Petroleum and natural gas industries — Site-specific assessment of mobile offshore units —Part 3: Floating units
Petroleum and natural gas industries — Site-specific assessment of mobile offshore units —Part 3: Floating units是国际标准化组织(International Organization for Standardization,简称ISO)于2021-03发布的ISO标准,适用于国际,世界范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 10140-1:2021 Acoustics — Laboratory measurement of sound insulation of building elements —Part 1: Application rules for specific products
Acoustics — Laboratory measurement of sound insulation of building elements —Part 1: Application rules for specific products是国际标准化组织(International Organization for Standardization,简称ISO)于2021-05发布的ISO标准,适用于世界范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 19290:2021 Cigarettes — Determination of tobacco specific nitrosamines in mainstream cigarette smoke — Method using LC-MS/MS
Cigarettes — Determination of tobacco specific nitrosamines in mainstream cigarette smoke — Method using LC-MS/MS是国际标准化组织于2021-02发布的ISO标准,适用于国际范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 11737-1:2018/Amd.1:2021 Sterilization of health care products — Microbiological methods —Part 1: Determination of a population of microorganisms on products
Sterilization of health care products — Microbiological methods —Part 1: Determination of a population of microorganisms on products是ISO于2018-01发布的ISO标准,适用于全球范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 11665-4:2021 Measurement of radioactivity in the environment — Air: radon-222 —Part 4: Integrated measurement method for determining average activity concentration using passive sampling and delayed analysis
Measurement of radioactivity in the environment — Air: radon-222 —Part 4: Integrated measurement method for determining average activity concentration using passive sampling and delayed analysis是国际标准化组织于2021-03发布的ISO标准,适用于全球。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 14644-17:2021 Cleanrooms and associated controlled environments —Part 17: Particle deposition rate applications
Cleanrooms and associated controlled environments —Part 17: Particle deposition rate applications是国际标准化组织于2021-02发布的ISO标准,适用于全球范围。本次分享的标准文档为高清PDF(文字版),标准文档内可搜索,可复制,可粘贴。本文结尾附网盘链接。
-
ISO 10315:2021 Cigarettes — Determination of nicotine in total particulate matter from the mainstream smoke — Gas-chromatographic method
Cigarettes — Determination of nicotine in total particulate matter from the mainstream smoke — Gas-chromatographic methodWARNING — The use of this document can involve hazardous materials, operations and equipment. This document does not purport to address all the safety problems associated with its use. It is the responsibility of the user of this document to establish appropriate safety and health practices and determine the applicability of any other restrictions prior to use.是国际标准化组织(Interna