ISO 22600-2:2014
Health informatics — Privilege management and access control — Part 2: Formal models
Health informatics — Privilege management and access control — Part 2: Formal models
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 26
- Дата публикации:
- 22 сентября 2014 г.
- Издание:
- ISO IS 22600 edition 1 version 1
- ICS:
- 35.240.80
ISO 22600 defines principles and specifies services needed for managing privileges and access control to data and/or functions. It focuses on communication and use of health information distributed across policy domain boundaries. This includes healthcare information sharing across unaffiliated providers of healthcare, healthcare organizations, health insurance companies, their patients, staff members, and trading partners by both individuals and application systems ranging from a local situation to a regional or even national situation. It specifies the necessary component-based concepts and is intended to support their technical implementation. It will not specify the use of these concepts in particular clinical process pathways. ISO 22600-2:2014 introduces the underlying paradigm of formal high-level models for architectural components. It is based on ISO/IEC 10746 (all parts) and introduces the domain model, the document model, the policy model, the role model, the authorization model, the delegation model, the control model, and the access control model.
Abstract
Overview
ISO 22600-2:2014 - Health informatics: Privilege management and access control - Part 2: Formal models defines high‑level, formal models for managing privileges and access control in distributed health information environments. It complements ISO 22600‑1 (overview/policy) and ISO 22600‑3 (implementations) and is intended to support technical implementation across policy domain boundaries - e.g., unaffiliated providers, insurers, patients, staff and trading partners. The standard introduces formal architectural components and meta‑models using UML and XML, and is based on ISO/IEC 10746. It references HL7 information models (ISO 21731) and aligns role semantics with ISO 21298.
Key topics and technical requirements
- Formal high‑level models: domain model, document model, policy model, role model, authorization model, delegation model, control model, and access control model.
- Component paradigm: component‑based concepts to support interoperable implementations across local, regional or national infrastructures.
- Policy representation: formal policy model to express rules for access to data and functions, supporting policy bridging across domains.
- Role and privilege assignment: role model and authorization model for mapping users to privileges and application functions.
- Delegation and control: delegation model and control model for temporary or delegated rights and accountability.
- Authentication and attribute handling: concepts for attribute authorities (AA), attribute certificates and certification authorities (CA) to support trustworthy identities and attributes.
- Specification languages: models specified with UML and XML; attributes referenced to HL7 data types and reference information model where appropriate.
- Interoperability focus: designed to enable secure sharing of health information while addressing privacy, legal and ethical implications.
Practical applications
- Designing secure, interoperable access control architectures for regional or national health information exchanges.
- Defining policy agreements and policy repositories to enable cross‑organizational data sharing.
- Implementing role‑based and attribute‑based access control services in electronic health record (EHR) systems.
- Creating authorization managers, directory services and local authorization servers that operate across policy boundaries.
- Supporting vendor integration when multiple applications with different authorization models must interoperate.
Who should use this standard
- Health IT architects and system integrators
- Security and privacy officers in healthcare organizations
- Software vendors building EHR, HIE, or access control components
- Policy makers, governance bodies and implementers responsible for cross‑domain information sharing
Related standards
- ISO 22600‑1 / ISO 22600‑3 (other parts of the series)
- ISO/IEC 10746 (reference architecture)
- ISO 21731 (HL7 reference information model)
- ISO 21298 (roles)
- Related ISO/TC 215 work: ISO 17090, ISO 22857, ISO 21091
Keywords: ISO 22600-2:2014, health informatics, privilege management, access control, formal models, policy model, role model, delegation, UML, XML, interoperability.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO 22600-2:2014
Похожие стандарты
Стандарты, упомянутые в описании
BS EN ISO 22600-1:2014
ДействующийHealth informatics. Privilege management and access control. Overview and policy management.
BS EN ISO 22600-3:2014
ДействующийHealth informatics. Privilege management and access control. Implementations.
BS ISO/IEC 10746-3:2009
ДействующийInformation technology. Open distributed processing. Reference model: Architecture.
BS EN ISO 21298:2017
ДействующийHealth informatics. Functional and structural roles.
BS ISO 17090-5:2017
ДействующийHealth informatics. Public key infrastructure. Authentication using Healthcare PKI credentials.
BS ISO 22857:2013
ДействующийHealth informatics. Guidelines on data protection to facilitate transborder flows of personal health data.
ISO 21091:2013
ДействующийHealth informatics — Directory services for healthcare providers, subjects of care and other entities
Overview ISO 21091:2013 - Health informatics - Directory services for healthcare providers, subjects of care and other entities - defines minimal, community-focused specifications for healthcare dire…