Purpose
IT is committed to safeguard the confidentiality, integrity and availability of all physical and electronic information assets of the organization to ensure that regulatory, operational and contractual requirements are fulfilled. The overall goals for information security at SSMC are the following:
- Ensure compliance with current national laws, regulations and guidelines.
- Implement policies and procedures to prevent, detect, contain, and correct information security violations.
- Implement technical policies and procedures for information systems that maintain protected health information to allow access only to those persons or software programs that have been granted access rights.
- Implement policies and procedures for authorizing access to protected health information. Access to information shall be based on need and defined by job title and function.
- Comply with requirements for confidentiality, integrity and availability.
- Motivate administrators and employees to maintain the responsibility for, ownership of and knowledge about information security, in order to minimize the risk of security incidents.
- Ensure that SSMC’s is capable of continuing their services even if major security incidents occur.
- Comply with methods from international standards for information security, e.g. ISO/IEC 27001, JCI.
- Ensure that external service providers comply with SSMC’s information security needs and requirements.
Description
legal documentation. In order to serve the above purposes, it is desirable to keep the medical record indefinitely. However there is always a serious problem with lack of storage space for the hard copy medical record. This Policy represents the SSMC’s policy regarding the retention and disposal of medical records and the retention and disposal of all other electronic documents.SSMC decided to keep the medical records for unlimited period of time. The primary purpose of the medical record is to serve as a communication tool for all health care providers to utilize when treating the patient
Policy
Organisation of Information Security
- Management shall actively support security within the organization through clear direction, demonstrated commitment, explicit assignment, and acknowledgment of information security responsibilities.
- It is also vital to have input from colleagues across the Group in order to benefit from their experience and assistance in disseminating best practice security information to SSMC as a whole and make them aware of the changes being discussed or implemented.
Responsibilities
- IT Director
The IT Director will be the final Authority for the Information security at SSMC and related policies and documentation.
- Infrastructure Team
The IT will delegate person/persons from the Infrastructure Team to act as the Security Incharge.
- Security Incharge
Providing leadership on methodologies and processes for information security. Identifying and implementing security controls required to enable service delivery and documenting those controls in the Information Security Policy, standards and guidelines;
- Application Owner
The Application owner, in consultation with the IT department, is responsible for purchasing requirements, development and maintenance of information and related information systems. The system owner must define which users or user groups are allowed access to the information and what authorized use of this information consists of.
- Representatives
The Representatives will have the responsibility of getting acquainted with the new changes and putting forth their views.
External Parties
- Assessment of risks from external party access to SSMC Information, information systems or information processing facilities shall be undertaken and appropriate security controls implemented.
- Identified security requirements must be addressed prior to granting external parties access to information, information systems or information processing facilities.
- Arrangements involving external party access to information, information systems or information processing facilities must be based on a formal contract containing necessary security requirements.
Asset Classification & Control
- To ensure all information in possession of SSMC is protected in an appropriate manner against misuse and harm, and is safeguarded against the risks associated with inappropriate distribution and mismanagement.
Responsibility for Assets
- An inventory of all important assets associated with information systems must be documented and maintained.
- Information Owners must be designated for all assets associated with information systems.
- Rules for the acceptable use of information systems must be identified, documented, and implemented.
- Information owner shall periodically review
- Who has the access to information asset.
- The information to which an individual has access.
Asset Classification
- Risk analysis should be carried out to classify Information Assets as per the criticality to operations.
- The Assets will be classified as RestrITed, Confidential, Internal or Public as referenced in the Data Classification Policy.
- Asset’s Information must be identified, labeled when appropriate and handled in accordance with the assigned Data classification.
Personnel Security
- To reduce the risks of human error, theft, fraud or misuse of computing and network facilities.
- A confidentiality agreement should be signed by employees, contractors or others who may gain access to sensitive and/or internal information.
- IT regulations should be accepted for all employment contracts and for system access for third parties.
- All staff should be made aware of their responsibilities with regards to information security.
- All employees and third party users should receive adequate training and updating regarding the Information security policy and procedures.
- Breaches of the Information security policy and accompanying guidelines will normally result in sanctions
- SSMC's information, information systems and other assets should only be utilized for their intended purpose. Private IT equipment in SSMC's infrastructure may only be connected where explicitly permitted. All other use must be approved in advance by the IT department.
- SSMC's assets should be handed in at the conclusion of the need for the use of these assets.
Physical and Environmental Security
- Secure areas must be protected by appropriate entry controls to ensure that only authorized personnel are allowed access.
- Physical security controls must be designed to protect against damage from natural or man-made disaster.
- Visitors are shall not be allowed to enter Secure areas. In case there is need, The Supervisor/Manager or responsible person shall keep vigilance during the visit.
- Equipment shall be protected to reduce the risks from unauthorized access, environmental and natural threats and hazards (temperature, humidity, flood, rain, earthquake etc.).Equipment shall be protected from power supply interruption and other disruptions caused by failures in supporting utilities.
- Equipment must be correctly maintained to enable continued availability and integrity.Equipment must be protected using documented security controls when off-site from SSMC premises.
- All data and software must be erased from equipment prior to disposal or re-deployment.
- Equipment, information or software belonging to SSMC must not be removed from SSMC premises without prior authorization.
Communications and Operations Management Operational Procedures and Responsibilities
- Operating procedures and responsibilities for information systems and information processing facilities must be authorized, documented, and maintained.
- Changes to information systems and information processing facilities must be controlled.
- Duties and areas of responsibility must be segregated to reduce opportunities for unauthorized modification or misuse of information systems.
- Development and test information systems must be separated from operational information systems.
Third Party Service Delivery Management
- Prior to using external information and technology services, security controls, service definitions and delivery levels must be identified and included in the agreement with the external party.
- ICT must regularly monitor and review services, reports and records provided by external parties and carry out regular audits.
- Change management processes for information system services delivered by external parties must take into account the criticality of the information systems, processes involved and assessment of risks.
System Planning and Acceptance
- The use of information system resources must be monitored, optimized and projections made of future capacity requirements.
- Acceptance criteria for new information systems, upgrades and new versions must be established and suitable tests of the system carried out prior to acceptance.
Protection Against Malicious Code
- Security awareness, prevention and detection controls must be utilized to protect information systems against malicious code.
- Mobile code must be restricted to the intended information system or environment.
Network Management
- A range of controls must be implemented to achieve and maintain security within the SSMC network.
- Security features, service levels and management requirements of all network services must be documented and included in the SLA Document.
Exchange of Information
- Information exchange policies, procedures and controls must be documented and implemented to protect the exchange of information through all types of electronic communication services.
- Information and software exchange agreements between the SSMC and other organizations must be documented.
- Media being physically transported must be appropriately protected.
- Information transmitted by electronic messaging must be appropriately protected.
- Security controls must be implemented to mitigate the business and security risks associated with the interconnection of business information systems.
Monitoring
- Audit logs recording user activities, exceptions and information security events must be produced and kept to assist in access control monitoring and future investigations.
- The use of information systems must be monitored and the result of the monitoring activities must be regularly reviewed.
- Information system logging facilities and log information must be protected against tampering and unauthorized access.
- Activities of privileged users must be logged, and the log must be subject to regular independent review.
- Faults must be logged, analyzed and appropriate action taken.
- Computer clocks shall be synchronized to GPS Network Time System for accurate reporting.
Access Control
- Access to information systems and services must be consistent with business needs and be based on security requirements.
User Access Management
- There must be a formal user registration and un-registration process for granting access to all information systems.
- The allocation and use of system privileges must be restricted and controlled.
- The issuance of authentication credentials must be controlled through a formal management process.
- Information Owners and Information Custodians must formally review user access rights at regular intervals.
User Responsibilities
- Users must follow good security practices in the selection and use of passwords as per the Password Policy.
- Users must ensure unattended equipment has appropriate protection.
- Users must ensure the safety of sensitive information from unauthorized access, loss or damage.
Network Access Control
- Users must only be provided access to the information systems they have been specifically authorized to use.
- Access by users must be subject to authentication.
- Groups of information services, users and information systems must be segregated on networks.
- The connection capability of users must be restricted in shared networks in accordance with the access control policy of the information system.
- Networks must have routing controls to ensure that computer connections and information flows do not breach the access control policy of the information system.
Operating System Access Control
- Access to information systems must use a secure logon process.
- All users must be issued a unique identifier for their use only, and an approved authentication technique must be used to substantiate the identity of the user.
- Use of system utility programs must be restricted and tightly controlled.
- Inactive sessions must be shut down after a defined period of inactivity.
- Restrictions on connection times must be used to provide additional security for high value applications.
Application and Information Access Control
- Access to information systems functions and information must be restricted in accordance with the access control policy.
- Information systems managing data of a sensitive nature must have an isolated dedicated computing environment.
Mobile Computing and Teleworking
- Appropriate controls must be implemented to mitigate security risks associated with the use of portable storage devices.
- Teleworking must employ security controls to ensure that information resources are not compromised.
Information Systems Acquisition, Development and Maintenance
Security Requirements of Information Systems
- Security controls must be identified as part of the business requirements for new information systems or enhancements to existing information systems.
Correct Processing in Applications
- Data input to an information system must be validated to ensure that it is correct and appropriate.
- Internal processing checks must be performed to minimize the risk of processing failures or deliberate acts leading to a loss of integrity.
- Message integrity controls must be used for information systems where there is a security requirement to protect the authenticity of the message content.
- Data output from an information system must be validated to ensure that the processing of stored information is correct and appropriate to the circumstances.
Cryptographic Controls
- The use of cryptographic controls must be based on the risk of unauthorized access and the classification of the information or information system that is to be protected.
Security of System Files
- The implementation of software on operational information systems must be controlled.
- Test data must be protected and controlled using the same procedures as for data from operational information systems.
- Access control must be maintained for program source libraries.
Security in Developmetn and Support Processes
- Changes to software must be controlled by the use of formal change control procedures.
- Information systems must be reviewed and tested when operating system changes occur.
- Modification of commercial-off-the-shelf software is limited to essential changes that are strictly controlled and documented.
- Controls must be applied to limit opportunities for information leakage.
- Controls must be applied to secure outsourced information system development.
Information Security Incident Management
Reporting Information Security Events and Weaknesses
- Information security events must be reported through appropriate management channels immediately.
- Personnel using information systems must note and report any observed or suspected security weaknesses in those systems.
Information Security Incidents Management
- Incident management responsibilities and procedures must be established to ensure a quick, effective and orderly response to information security incidents.
- The types, volumes and costs of information security incidents must be quantified and monitored.
- Investigations into information security incidents must ensure evidence is collected, retained and presented in conformance with the rules for collection of evidence.
Business Continuity Managmement
Information Security Aspects of Business Continuity Management
- A framework of business continuity plans must be maintained to ensure consistent handling of information security requirements.
- There must be a managed process to ensure that business continuity programs address information security requirements.
- A risk assessment must be conducted to identify information security events that may interrupt business processes.
- Business continuity plans must be developed to resume and maintain business operations to the required level following interruption to, or failure of, essential services.
- Business continuity plans must be regularly exercised and updated.
Compliance
Compliance with Legal Requirements
- The statutory, regulatory and contractual requirements for each information system must be explicitly defined, documented and maintained.
- Controls must be implemented to ensure compliance with legal, regulatory and contractual restrictions on the use of material with respect to intellectual property rights and proprietary software licensing.
- Client records must be protected from loss, destruction and falsification.
- Security controls must be applied to protect data and personal information in accordance with relevant legislation.
- Controls must be in place to deter misuse of information systems.
- Cryptographic controls must be used in conjunction with relevant agreements, laws and regulations.
Compliance with Security Policies and Standards
- Management must ensure security procedures are followed in their areas of responsibility and facilitate regular reviews to ensure compliance with security policies and standards.
- Information systems must be regularly checked for compliance with security policies and standards.
Information Systems Audit Considerations
- Audit requirements and activities involving checks on operational systems must be planned and approved to minimize disruption to business processes.
- Access to system audit tools must be controlled to prevent misuse or compromise.
Definitions
BCP: Business Continuity Plan. The procedures and information necessary for the timely recovery of essential services, programs and operations, within a predefined timeframe. The BCP includes the recovery following an emergency or a disaster that interrupts an operation or affects service or program delivery.
External Party: a person external to SSMC.
Mobile code: multiplatform computer code that can be downloaded or transmitted across a network that runs automatically on a computer with little or no user interaction.
Mobile code technology: software technologies that provide the mechanisms for the production and use of mobile code (e.g., Java, JavaScript, VBScript, ActiveX). Mobile devices: portable self-contained electronic devices, including portable computers (e.g., laptops), personal digital assistants (PDAs), cell phones, digital cameras, etc.
Network infrastructure: the equipment, information systems and cabling systems used to establish a communication network between Information Systems. Includes routers, switches, hubs, firewalls, transmitters, fibre optic cable and copper cable.
Third party: includes external party and includes a person outside the direct reporting structure of the Information Owner or Information Custodian. E.g., an individual, a business or organization, personnel from another branch.
Abbreviations
SSMC-DKP: SmartSalem Medical Centre Dubai Knowledge Park
SSMC-IMC: SmartSalem Medical Centre Index Mall
SSMC-CW: SmartSalem Medical Centre City Walk
SSMC-HQ: SmartSalem Head Quarters
