ISO 17090-3:2021
Health informatics — Public key infrastructure — Part 3: Policy management of certification authority
Health informatics — Public key infrastructure — Part 3: Policy management of certification authority
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 34
- Дата публикации:
- 9 марта 2021 г.
- Издание:
- ISO IS 17090 edition 2 version 1
- ICS:
- 35.240.80
This document gives guidelines for certificate management issues involved in deploying digital certificates in healthcare. It specifies a structure and minimum requirements for certificate policies, as well as a structure for associated certification practice statements. This document also identifies the principles needed in a healthcare security policy for cross-border communication and defines the minimum levels of security required, concentrating on aspects unique to healthcare.
Abstract
Overview
ISO 17090-3:2021 - Health informatics - Public key infrastructure - Part 3: Policy management of certification authority - provides guidelines for certificate management when deploying digital certificates in healthcare. It specifies a structure and minimum requirements for certificate policies (CPs) and a structure for associated certification practice statements (CPSs). The standard identifies principles for healthcare security policies that support cross‑border communication and defines minimum security levels focused on aspects unique to healthcare PKI deployments.
Key Topics and Requirements
The standard organizes policy management requirements around practical PKI operations commonly needed in healthcare:
- Governance and assurance
- Need for a high level of assurance, availability and trust for healthcare PKI.
- Internet compatibility and facilitation of CP evaluation and comparison.
- Structure of policy documents
- Required structure and content for CPs and CPSs and their relationship.
- Publication and repositories
- Rules for repositories, publication frequency and access controls for certificate information.
- Identification and authentication
- Procedures for initial registration, identity validation, re‑keying and revocation requests.
- Certificate lifecycle
- Controls for application, issuance, acceptance, renewal, re‑keying, modification, revocation/suspension, status services (CRL/OCSP), and end of subscription.
- Security controls
- Physical controls, personnel and procedural controls, record archives, compromise and disaster recovery, and CA termination.
- Technical controls such as key pair generation, private key protection, activation data, computer and network security, time stamping.
- Profiles and audits
- Certificate, CRL and OCSP profile requirements and compliance audit procedures (frequency, scope, auditor independence).
- Legal and business matters
- Fees, financial responsibility, confidentiality, privacy, IP, warranties, liability, dispute resolution and governing law.
- Model PKI disclosure statement
- Template guidance for communicating PKI properties to relying parties.
Applications
ISO 17090-3:2021 is designed to guide secure use of digital certificates across healthcare use cases, including:
- Secure exchange of electronic health records (EHRs) and cross‑border patient data flows
- Authentication and signing for e‑prescriptions, clinical messaging and telemedicine
- Securing health information systems, device communications and interoperability gateways
- Implementing trustworthy Certification Authorities (CAs) that serve hospitals, health networks and national health services
Who Uses This Standard
- Healthcare IT architects and CISOs
- Certification Authority operators servicing healthcare
- Health system integrators and software vendors
- Regulators, auditors and compliance officers
- National health bodies planning cross‑border identity and trust frameworks
Related standards
- Other parts of the ISO 17090 series (complementary PKI guidance for healthcare)
- General PKI and cryptographic standards (ISO/IEC and regional standards) relevant to implementation and interoperability
Keywords: ISO 17090-3:2021, health informatics, public key infrastructure, PKI, certificate policy, certification authority, digital certificates, healthcare security, cross‑border communication, certificate management.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 17090-3:2021
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO 17090-5:2017
ДействующийHealth informatics. Public key infrastructure. Authentication using Healthcare PKI credentials.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…
ISO 7574-3:1985
ДействующийAcoustics — Statistical methods for determining and verifying stated noise emission values of machinery and e…
Overview ISO 7574-3:1985 is part of the ISO 7574 series on acoustics and provides a simple (transition) statistical method for determining and verifying stated noise emission values for batches (lots…