The Experts below are selected from a list of 246 Experts worldwide ranked by ideXlab platform

Eric T.t. Wong - One of the best experts on this subject based on the ideXlab platform.

  • Information Security Management in Picture Archiving and Communication Systems for the Healthcare Industry
    Encyclopedia of Multimedia Technology and Networking Second Edition, 2009
    Co-Authors: Carrison K.s. Tong, Eric T.t. Wong
    Abstract:

    Like other information systems in banking and commercial companies, information security is also an important issue in the health care industry. It is a common problem to have security incidences in an information system. Such security incidences include physical attacks, viruses, intrusions, and hacking. For instance, in the USA, more than 10 million security incidences occurred in the year 2003. The total loss was over $2 billion. In the health care industry, damages caused by security incidences could not be measured only by monetary cost. The trouble with inaccurate information in health care systems is that it is possible that someone might believe it and do something that might damage the patient. In a security event in which an unauthorized modification to the drug regime system at Arrowe Park Hospital proved to be a deliberate modification, the perpetrator received a jail sentence under the Computer Misuse Act of 1990. In another security event (The Institute of Physics and Engineering in Medicine, 2003), six patients received severe overdoses of radiation while being treated for cancer on a Computerized medical linear accelerator between June 1985 and January 1987. Owing to the Misuse of untested software in the control, the patients received radiation doses of about 25,000 rads while the normal therapeutic dose is 200 rads. Some of the patients reported immediate symptoms of burning and electric shock. Two died shortly afterward and others suffered scarring and permanent disability. BS7799 is an information security management standard developed by the British Standards Institution (BSI) for an information security management system (ISMS). The first part of BS7799, which is the code of prActice for information security, was later adopted by the International Organization for Standardization (ISO) as ISO17799. The ISO 27002 standard is the rename of the existing ISO 17799 standard. It basically outlines hundreds of potential controls and control mechanisms, which may be implemented. The second part of BS7799 states the specification for ISMS which was replaced by The ISO 27001 standard published in October 2005. The Picture Archiving and Communication System (PACS; Huang, 2004) is a clinical information system tailored for the management of radiological and other medical images for patient care in hospitals and clinics. It was the first time in the world to implement both standards to a clinical information system for the improvement of data security.

  • Information Security Management in Picture Archiving and Communication Systems for the Healthcare Industry
    Encyclopedia of Multimedia Technology and Networking, 1
    Co-Authors: Carrison K.s. Tong, Eric T.t. Wong
    Abstract:

    Like other information systems in banking and commercial companies, information security is also an important issue in the healthcare industry. It is a common problem to have security incidences in an information system. Such security incidences include physical attacks, viruses, intrusions, and hacking. For instance, in the U.S.A., more than 10 million security incidences occurred in the year of 2003. The total loss was over $2 billion. In the healthcare industry, damages caused by security incidences could not be measured only by monetary cost. The trouble with inaccurate information in healthcare systems is that it is possible that someone might believe it and do something that might damage the patient. In a security event in which an unauthorized modification to the drug regime system at Arrowe Park Hospital proved to be a deliberate modification, the perpetrator received a jail sentence under the Computer Misuse Act of 1990. In another security event (The Institute of Physics and Engineering in Medicine, 2003), six patients received severe overdoses of radiation while being treated for cancer on a Computerized medical linear accelerator between June 1985 and January 1987. Owing to the Misuse of untested software in the control, the patients received radiation doses of about 25,000 rads while the normal therapeutic dose is 200 rads. Some of the patients reported immediate symptoms of burning and electric shock. Two died shortly afterward and others suffered scarring and permanent disability.

  • Information Security Management in Picture Archiving and Communication Systems for the Healthcare Industry
    Medical Informatics, 1
    Co-Authors: Carrison K.s. Tong, Eric T.t. Wong
    Abstract:

    Like other information systems in banking and commercial companies, information security is also an important issue in the healthcare industry. It is a common problem to have security incidences in an information system. Such security incidences include physical attacks, viruses, intrusions, and hacking. For instance, in the U.S.A., more than 10 million security incidences occurred in the year of 2003. The total loss was over $2 billion. In the healthcare industry, damages caused by security incidences could not be measured only by monetary cost. The trouble with inaccurate information in healthcare systems is that it is possible that someone might believe it and do something that might damage the patient. In a security event in which an unauthorized modification to the drug regime system at Arrowe Park Hospital proved to be a deliberate modification, the perpetrator received a jail sentence under the Computer Misuse Act of 1990. In another security event (The Institute of Physics and Engineering in Medicine, 2003), six patients received severe overdoses of radiation while being treated for cancer on a Computerized medical linear accelerator between June 1985 and January 1987. Owing to the Misuse of untested software in the control, the patients received radiation doses of about 25,000 rads while the normal therapeutic dose is 200 rads. Some of the patients reported immediate symptoms of burning and electric shock. Two died shortly afterward and others suffered scarring and permanent disability. BS7799 is an information-security-management standard developed by the British Standards Institution (BSI) for an information-securitymanagement system (ISMS). The first part of BS7799, which is the code of prActice for information security, was later adopted by the International Organization for Standardization (ISO) as ISO17799. The second part of BS7799 states the specification for ISMS. The picture-archiving and -communication system (PACS; Huang, 2004) is a clinical information system tailored for the management of radiological and other medical images for patient care in hospitals and clinics. It was the first time in the world to implement both standards to a clinical information system for the improvement of data security.

Carrison K.s. Tong - One of the best experts on this subject based on the ideXlab platform.

  • Information Security Management in Picture Archiving and Communication Systems for the Healthcare Industry
    Encyclopedia of Multimedia Technology and Networking Second Edition, 2009
    Co-Authors: Carrison K.s. Tong, Eric T.t. Wong
    Abstract:

    Like other information systems in banking and commercial companies, information security is also an important issue in the health care industry. It is a common problem to have security incidences in an information system. Such security incidences include physical attacks, viruses, intrusions, and hacking. For instance, in the USA, more than 10 million security incidences occurred in the year 2003. The total loss was over $2 billion. In the health care industry, damages caused by security incidences could not be measured only by monetary cost. The trouble with inaccurate information in health care systems is that it is possible that someone might believe it and do something that might damage the patient. In a security event in which an unauthorized modification to the drug regime system at Arrowe Park Hospital proved to be a deliberate modification, the perpetrator received a jail sentence under the Computer Misuse Act of 1990. In another security event (The Institute of Physics and Engineering in Medicine, 2003), six patients received severe overdoses of radiation while being treated for cancer on a Computerized medical linear accelerator between June 1985 and January 1987. Owing to the Misuse of untested software in the control, the patients received radiation doses of about 25,000 rads while the normal therapeutic dose is 200 rads. Some of the patients reported immediate symptoms of burning and electric shock. Two died shortly afterward and others suffered scarring and permanent disability. BS7799 is an information security management standard developed by the British Standards Institution (BSI) for an information security management system (ISMS). The first part of BS7799, which is the code of prActice for information security, was later adopted by the International Organization for Standardization (ISO) as ISO17799. The ISO 27002 standard is the rename of the existing ISO 17799 standard. It basically outlines hundreds of potential controls and control mechanisms, which may be implemented. The second part of BS7799 states the specification for ISMS which was replaced by The ISO 27001 standard published in October 2005. The Picture Archiving and Communication System (PACS; Huang, 2004) is a clinical information system tailored for the management of radiological and other medical images for patient care in hospitals and clinics. It was the first time in the world to implement both standards to a clinical information system for the improvement of data security.

  • Information Security Management in Picture Archiving and Communication Systems for the Healthcare Industry
    Encyclopedia of Multimedia Technology and Networking, 1
    Co-Authors: Carrison K.s. Tong, Eric T.t. Wong
    Abstract:

    Like other information systems in banking and commercial companies, information security is also an important issue in the healthcare industry. It is a common problem to have security incidences in an information system. Such security incidences include physical attacks, viruses, intrusions, and hacking. For instance, in the U.S.A., more than 10 million security incidences occurred in the year of 2003. The total loss was over $2 billion. In the healthcare industry, damages caused by security incidences could not be measured only by monetary cost. The trouble with inaccurate information in healthcare systems is that it is possible that someone might believe it and do something that might damage the patient. In a security event in which an unauthorized modification to the drug regime system at Arrowe Park Hospital proved to be a deliberate modification, the perpetrator received a jail sentence under the Computer Misuse Act of 1990. In another security event (The Institute of Physics and Engineering in Medicine, 2003), six patients received severe overdoses of radiation while being treated for cancer on a Computerized medical linear accelerator between June 1985 and January 1987. Owing to the Misuse of untested software in the control, the patients received radiation doses of about 25,000 rads while the normal therapeutic dose is 200 rads. Some of the patients reported immediate symptoms of burning and electric shock. Two died shortly afterward and others suffered scarring and permanent disability.

  • Information Security Management in Picture Archiving and Communication Systems for the Healthcare Industry
    Medical Informatics, 1
    Co-Authors: Carrison K.s. Tong, Eric T.t. Wong
    Abstract:

    Like other information systems in banking and commercial companies, information security is also an important issue in the healthcare industry. It is a common problem to have security incidences in an information system. Such security incidences include physical attacks, viruses, intrusions, and hacking. For instance, in the U.S.A., more than 10 million security incidences occurred in the year of 2003. The total loss was over $2 billion. In the healthcare industry, damages caused by security incidences could not be measured only by monetary cost. The trouble with inaccurate information in healthcare systems is that it is possible that someone might believe it and do something that might damage the patient. In a security event in which an unauthorized modification to the drug regime system at Arrowe Park Hospital proved to be a deliberate modification, the perpetrator received a jail sentence under the Computer Misuse Act of 1990. In another security event (The Institute of Physics and Engineering in Medicine, 2003), six patients received severe overdoses of radiation while being treated for cancer on a Computerized medical linear accelerator between June 1985 and January 1987. Owing to the Misuse of untested software in the control, the patients received radiation doses of about 25,000 rads while the normal therapeutic dose is 200 rads. Some of the patients reported immediate symptoms of burning and electric shock. Two died shortly afterward and others suffered scarring and permanent disability. BS7799 is an information-security-management standard developed by the British Standards Institution (BSI) for an information-securitymanagement system (ISMS). The first part of BS7799, which is the code of prActice for information security, was later adopted by the International Organization for Standardization (ISO) as ISO17799. The second part of BS7799 states the specification for ISMS. The picture-archiving and -communication system (PACS; Huang, 2004) is a clinical information system tailored for the management of radiological and other medical images for patient care in hospitals and clinics. It was the first time in the world to implement both standards to a clinical information system for the improvement of data security.

Mt Mark Tucker - One of the best experts on this subject based on the ideXlab platform.

Stefan Fafinski - One of the best experts on this subject based on the ideXlab platform.

  • Computer Misuse: The Implications of the Police and Justice Act 2006
    The Journal of Criminal Law, 2008
    Co-Authors: Stefan Fafinski
    Abstract:

    While the Police and Justice Act 2006 is largely concerned with policing reform, there are also some long-overdue amendments to the Computer Misuse Act 1990 buried within it. These amendments attem...

  • Police and Justice Act: The security ramifications of the Police and Justice Act 2006
    Network Security, 2007
    Co-Authors: Stefan Fafinski
    Abstract:

    Like much legislation, the Computer Misuse Act 1990 was implemented to plug a hole in the law. It may have made it easier for prosecutors to punish those abusing Computer systems nearly 20 years ago, but conditions have changed dramatically since then. The Police and Justice Act 2006 was passed at the end of last year, and nestled among its non-Computer related measures is a raft of new rules designed to bring the terms and conditions relating to Computer crime into the 21^s^t century. IT criminology expert Stefan Fafinski examines the ramifications of the law, and wonders whether its scope might cause collateral damage for legitimate security prActitioners. During the 1980s, some of the potential problems resulting from the Misuse of Computer technology came to light on a widespread scale. The emergence of the Computer virus began with the relatively innocuous Elk Cloner (1981), via Brain (1986), the first global IBM-compatible boot sector virus, to viruses with more malicious payloads such as Suriv-3, or the Jerusalem virus (1988) and Datacrime and FuManchu, which was a Jerusalem variant (1989).

Vasileios Karagiannopoulos - One of the best experts on this subject based on the ideXlab platform.

  • insider unauthorised use of authorised access what are the alternatives to the Computer Misuse Act 1990
    International Journal of Law Crime and Justice, 2016
    Co-Authors: Vasileios Karagiannopoulos
    Abstract:

    Case-law developments in the United States have supported narrower interpretations of the Computer Fraud and Abuse Act 1986 (CFAA) in cases of unauthorised use of authorised access. This issue has been one that UK courts have also debated in the past and thus this renewed interest in the concept of insider unauthorised access offers an opportunity to bring this debate to the fore again. Starting from discussing the recent US case law, this paper further analyses relevant UK precedent and identifies legal provisions that are applicable when dealing with such incidents in addition to the Computer Misuse Act 1990. More particularly, it identifies provisions, mainly in the Data Protection Act 1998 and the Fraud Act 2006, which could substitute for the Computer Misuse Act 1990 in prosecuting insiders and thus clarifies the extent of the prosecutors’ legal arsenal and manoeuvring space when dealing with exceeding unauthorised access.

  • Insider unauthorised use of authorised access:what are the alternatives to the Computer Misuse Act 1990?
    International Journal of Law Crime and Justice, 2016
    Co-Authors: Vasileios Karagiannopoulos
    Abstract:

    Case-law developments in the United States have supported narrower interpretations of the Computer Fraud and Abuse Act 1986 (CFAA) in cases of unauthorised use of authorised access. This issue has been one that UK courts have also debated in the past and thus this renewed interest in the concept of insider unauthorised access offers an opportunity to bring this debate to the fore again. Starting from discussing the recent US case law, this paper further analyses relevant UK precedent and identifies legal provisions that are applicable when dealing with such incidents in addition to the Computer Misuse Act 1990. More particularly, it identifies provisions, mainly in the Data Protection Act 1998 and the Fraud Act 2006, which could substitute for the Computer Misuse Act 1990 in prosecuting insiders and thus clarifies the extent of the prosecutors’ legal arsenal and manoeuvring space when dealing with exceeding unauthorised access.