النتائج (
الفرنسية) 1:
[نسخ]نسخ!
To mitigate the rigid nature of access control systems, EMRs often permit users to invoke “break the glass” when they lack sufficient access privileges. When a user opts to issue such an access, the system logs the event for follow up investigation.This type of approach to auditing works well when the number of exceptions is relatively small. However, there is evidence to suggest that the initial role specification in a healthcare domain do not lead to such scenarios. A study conducted by Røstad et al in the Central Norway Health Region provides a compelling illustration of this situation. After setting up an access control system, they monitored the system for one month.During this time, they observed that more than 50% of 100,000 patients' records were accessed via break the glass and that approximately 45% of users invoked this option. Overall, there over 290,000 exceptions issued, which is significantly more than can be followed up on by a human for investigation.
يجري ترجمتها، يرجى الانتظار ..