EN ISO 22600-2:2014 PDF
Health informatics - Privilege management and access control - Part 2: Formal models (ISO 22600-2:2014)
Health informatics - Privilege management and access control - Part 2: Formal models (ISO 22600-2:2014)
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 35
- Дата публикации:
- 15 октября 2014 г.
- Издание:
- CEN EN 22600 edition 1 version 1
- ICS:
- 35.240.80
ISO 22600 defines principles and specifies services needed for managing privileges and access control to data and/or functions. It focuses on communication and use of health information distributed across policy domain boundaries. This includes healthcare information sharing across unaffiliated providers of healthcare, healthcare organizations, health insurance companies, their patients, staff members, and trading partners by both individuals and application systems ranging from a local situation to a regional or even national situation. It specifies the necessary component-based concepts and is intended to support their technical implementation. It will not specify the use of these concepts in particular clinical process pathways. ISO 22600-2:2014 introduces the underlying paradigm of formal high-level models for architectural components. It is based on ISO/IEC 10746 (all parts) and introduces the domain model, the document model, the policy model, the role model, the authorization model, the delegation model, the control model, and the access control model.
Abstract
Overview
EN ISO 22600-2:2014 - Health informatics: Privilege management and access control, Part 2: Formal models defines formal, high‑level models that underpin privilege management and access control for distributed health information systems. Part 2 of the ISO 22600 series specifies component-based concepts to support technical implementation of cross‑domain healthcare information sharing and access control. It is based on ISO/IEC 10746 (all parts) and focuses on architecture and model definitions rather than clinical workflows or cryptographic protocols (these are out of scope).
Key topics and technical requirements
The standard introduces and formalizes multiple models used to express policies and enforce access control across policy domain boundaries:
- Component paradigm - a component‑based approach for building interoperable access control services.
- Domain model - structural representation of participating policy domains and actors.
- Document model - classification and sensitivity metadata for health information objects.
- Policy model - formal representation of access policies and policy agreements between parties.
- Role model - definition of functional and structural roles and role relationships.
- Authorization model - mechanisms for role-to-privilege assignment and authorization decisions.
- Delegation model - rules and constraints for delegation of privileges between actors.
- Control model & Access control model - formal control flows and access decision logic to evaluate requests across domains.
Other notable points:
- Emphasis on policy bridging and interoperability where local authorization servers and cross‑border policy repositories coordinate access decisions.
- Support for specifying purpose of use, requester identity, and target sensitivity in access decisions.
- References to broader standards and profiles (ISO, CEN and other industry specifications) for integration.
Practical applications and users
EN ISO 22600-2 is intended for organizations and professionals designing secure, interoperable health IT systems that exchange sensitive patient data across organizational or national boundaries. Typical users include:
- Health IT architects and solution designers implementing SOA or distributed EHR systems
- Security engineers and access control implementers (authorization servers, policy repositories, directories)
- System integrators and vendors building interoperable healthcare applications
- Policy makers, privacy officers and technical leads drafting cross‑organization policy agreements
- Healthcare organizations and insurers coordinating data sharing with unaffiliated providers
Implementing the formal models helps organizations manage complex role mappings, delegation, privacy constraints and legal/ethical considerations while improving interoperability and auditability.
Related standards
- ISO 22600-1: Overview and policy management
- ISO 22600-3: Implementations (examples/specifications)
- ISO/IEC 10746 (all parts) - reference architecture background
Keywords: EN ISO 22600-2:2014, health informatics, privilege management, access control, formal models, policy model, role model, authorization, delegation, interoperability, healthcare information sharing.
Технические детали
- Технический комитет
- CEN/TC 251 - Medical informatics
- SKU
- EN ISO 22600-2:2014
Похожие стандарты
Стандарты, упомянутые в описании
ISO 22600-2:2014
ДействующийHealth informatics — Privilege management and access control — Part 2: Formal models
Overview ISO 22600-2:2014 - Health informatics: Privilege management and access control - Part 2: Formal models defines high‑level, formal models for managing privileges and access control in distrib…
BS EN ISO 22600-2:2014
ДействующийHealth informatics. Privilege management and access control. Formal models.
ISO/IEC 10746-4:1998/Amd 1:2001
ДействующийInformation technology — Open Distributed Processing — Reference Model: Architectural semantics — Part 4: — A…
Overview ISO/IEC 10746-4:1998/Amd 1:2001 is an international amendment standard that enhances the Reference Model for Open Distributed Processing (RM-ODP) by introducing computational formalization.…
SIST EN ISO 22600-1:2015
ДействующийHealth informatics - Privilege management and access control - Part 1: Overview and policy management (ISO 22…
Overview EN ISO 22600-1:2014 (Health informatics - Privilege management and access control - Part 1: Overview and policy management) defines principles and services for managing privileges and access…
SIST EN ISO 22600-3:2015
ДействующийHealth informatics - Privilege management and access control - Part 3: Implementations (ISO/DIS 22600-3:2014)
Overview EN ISO 22600-3:2014 (Health informatics - Privilege management and access control - Part 3: Implementations) defines implementation-level guidance for managing privileges and access control…